Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20110701003900.GA20891@openwall.com>
Date: Fri, 1 Jul 2011 04:39:00 +0400
From: Solar Designer <solar@...nwall.com>
To: scrypt@...snap.com, crypt-dev@...ts.openwall.com
Subject: scrypt time-memory tradeoff

Colin, all -

This is probably nothing new to you, but here's some analysis Anthony
Ferrara (ircmaxell) posted regarding an attacker making scrypt run in a
lot less memory, by trading CPU/GPU time for that:

http://drupal.org/node/1201444#comment-4675994

For some settings and some types of attacker's equipment (not ASICs, but
GPUs with their constraints) the trade-off might be worthwhile, although
I think that it is not for the settings given by ircmaxell and for
present GPUs, and it would not provide impressive performance anyway
(potentially just slightly better than the straightforward approach).

Alexander

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.