Alex Rivera | Logout

Bcrypt - How many iterations/cost?

Asked 2011-10-01T20:16:15.953
11

I've read some articles saying you should set the cost to be at least 16 (216), yet others say 8 or so is fine.

Is there any official standard for how high the cost should be set to?

Edit
Report

1 Answer

10

You must set the number of iterations at the maximum value which is still "tolerable" depending on the hardware you use and the patience of the users. Higher is better.

The whole point of the iteration count is to make the password processing slow -- that is, to make it slow for the attacker who "tries" potential passwords. The slower the better. Unfortunately, raising the iteration count makes it slow for you too...

As a rule of thumb, consider that an attacker will break passwords by trying, on average, about 10 millions (107) of potential passwords. If you set the iteration count so that password hashing takes 1 second for you, and you consider that the attacker can muster ten times more computing power than you, then it will take him 107*1/10 seconds, i.e. about 12 days. If you set the iteration count so that password hashing takes only 0.01 second on your PC, then the attacker is done in three hours.

answered 2011-10-02T14:09:57.643

Your Answer