ended3월 27일· 1 sources
The End of bcrypt: GPU Attacks Force Password Security Standards Shift
bcrypt의 시대는 끝났다: GPU 공격이 바꾼 Node.js 보안 표준
Why it matters
bcrypt, designed for 1999-era CPUs, is no longer sufficient against modern GPU-based attacks that can process 400,000 password attempts per second. Argon2id, winner of the 2015 Password Hashing Competition, makes large-scale attacks economically impractical by requiring 64MB of RAM per attempt. OWASP's 2025 recommendation update signals a critical shift in password security standards that developers must adopt to protect user credentials in today's threat landscape.
1
Sources
+0
24h
—
Growth
167d
Active
Argon2idnodearmorbcryptmemory-hardpassword hashingGPU attacks