You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I'm also confused about this. 4MiB seems unreasonably low for Argon2 and could easily confuse people or even lead them to make insecure decisions. OWASP’s Password Storage Cheat Sheet recommends 19MiB (at least), so making that the default seems like a better idea.
The actual default options for argon2 hash produces
Indicating
memoryCost = 19 * 2 ** 10
,timeCost = 2
, instead of what are suggested in docs:The text was updated successfully, but these errors were encountered: