Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Microsoft uses PBKDF2 for newer domain cached credentials (DCC2). These password hashes are stored in the registry of Windows clients (laptops and desktops) and allow users to logon when the domain is unavailable. They use 10240 iterations. It's very compute intensive to crack... roughly 330 guesses per second. Great article BTW!

Edit: I only post this to add to the examples of who uses PBKDF2 in addition to what the article lists.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: