Dev Overflow Logo

Dev Overflow

Global search

Search across questions, answers, users and tags.

Loading...
save

How should I hash passwords in 2026 — bcrypt, scrypt, or argon2?

clock icon

asked 3 months ago

message icon

2

eye icon

1.7K

Existing code uses bcrypt with 10 rounds. Is that still acceptable, or should I be migrating to argon2?

2 Answers

All three are acceptable; none of them are the weak link in a typical breach. In preference order for new code: argon2id, then scrypt, then bcrypt.

Argon2id resists GPU and side-channel attacks better and lets you tune memory cost, which is what actually hurts an attacker with a rack of GPUs.

bcrypt at 10 rounds is not broken, but bump it — 12 is the common floor now, and it costs you a few hundred milliseconds per login. Two things people forget about bcrypt:

  • It silently truncates input at 72 bytes. Pre-hash with SHA-256 if you accept long passphrases.
  • The cost factor should be re-evaluated periodically; a value chosen in 2016 is doing much less work relative to today's hardware.

Migrate opportunistically: on successful login, if the stored hash uses the old scheme, re-hash with the new one. No mass reset required.

And rate-limit the login endpoint. A slow hash protects the database dump; it does nothing about someone trying ten thousand passwords against one account over the network.

1

of 1

Write your answer here

Introduce the problem and expand on what you've put in the title.

Top Questions