bk99.de entertain the web since 1997

RFC 9106: Argon2 for password hashing

Summary

RFC 9106 describes Argon2 as a memory-hard password derivation function and gives recommendations for secure parameters. Every implementation compliant with RFC 9106 must support Argon2id; Argon2d and Argon2i are optional. For password hashing, the RFC recommends an individual salt 16 bytes long.

Ideas

  • Argon2id combines protection against side channels and GPU attacks.
  • The memory requirement makes parallel guessing more expensive.
  • A salt prevents precomputed tables.

Insights

  • Password protection depends more on cost parameters than on the name of the algorithm.
  • Parameters have to keep pace with growing hardware performance.

Remarks

  • RFC 9106 is an informational document and not an Internet Standard.

Recommendations

  • Use Argon2id from a maintained library.
  • Store parameters and salt together with each hash.

Facts

  • The first recommended profile uses Argon2id with 2 GiB of memory, four lanes and one pass.
  • The profile for memory-constrained systems uses 64 MiB of memory and three passes.

References

Read the RFC at the RFC Editor

Search the Web Archive