RFC 9106: Argon2 for password hashing
Summary
RFC 9106 describes Argon2 as a memory-hard password derivation function and gives recommendations for secure parameters. Every implementation compliant with RFC 9106 must support Argon2id; Argon2d and Argon2i are optional. For password hashing, the RFC recommends an individual salt 16 bytes long.
Ideas
- Argon2id combines protection against side channels and GPU attacks.
- The memory requirement makes parallel guessing more expensive.
- A salt prevents precomputed tables.
Insights
- Password protection depends more on cost parameters than on the name of the algorithm.
- Parameters have to keep pace with growing hardware performance.
Remarks
- RFC 9106 is an informational document and not an Internet Standard.
Recommendations
- Use Argon2id from a maintained library.
- Store parameters and salt together with each hash.
Facts
- The first recommended profile uses Argon2id with 2 GiB of memory, four lanes and one pass.
- The profile for memory-constrained systems uses 64 MiB of memory and three passes.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.