Uploaded image for project: 'MusicBrainz Server'
  1. MusicBrainz Server
  2. MBS-9208

Increase bcrypt cost parameter

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Fixed
    • Icon: Normal Normal
    • 2018-11-01
    • None
    • Accounts
    • None
    • House

      User passwords are stored encrypted via bcrypt (Blowfish). The cost parameter is still 10, as it was when introduced in 2013. Since computing power is ever increasing, we should use a higher cost parameter of at least 12 (four times the work); see an answer on Security.SE for more background.

      This will only affect new passwords (new account or changed password).

            yvanzo yvanzo
            chirlu Ulrich Klauer
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved:

                Version Package
                2018-11-01