From c7d5012803e6636c11621f320ad522a25616ceb5 Mon Sep 17 00:00:00 2001 From: Tony Arcieri Date: Sat, 4 Mar 2023 18:30:45 -0700 Subject: [PATCH] scrypt: adopt OWASP recommendations Adopts the recommended settings from: https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html > use scrypt with a minimum CPU/memory cost parameter of (2^17), > a minimum block size of 8 (1024 bytes), and a parallelization > parameter of 1. --- scrypt/src/params.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scrypt/src/params.rs b/scrypt/src/params.rs index df6b1bc0..231d6132 100644 --- a/scrypt/src/params.rs +++ b/scrypt/src/params.rs @@ -17,7 +17,7 @@ pub struct Params { impl Params { /// Recommended logâ‚‚ of the Scrypt parameter `N`: CPU/memory cost. - pub const RECOMMENDED_LOG_N: u8 = 15; + pub const RECOMMENDED_LOG_N: u8 = 17; /// Recommended Scrypt parameter `r`: block size. pub const RECOMMENDED_R: u32 = 8;