What are recommended / minimum parameters for hashlib.scrypt?

Viewed 640

The documentation of hashlib.scrypt is a bit short:

hashlib.scrypt(password, *, salt, n, r, p, maxmem=0, dklen=64)

The function provides scrypt password-based key derivation function as defined in RFC 7914.

password and salt must be bytes-like objects. Applications and libraries should limit password to a sensible length (e.g. 1024). salt should be about 16 or more bytes from a proper source, e.g. os.urandom().

n is the CPU/Memory cost factor, r the block size, p parallelization factor and maxmem limits memory (OpenSSL 1.1.0 defaults to 32 MiB). dklen is the length of the derived key.

I figured out that n must be a power of 2 and at least 2.

Besides that, I feel a bit left alone. Would hashlib.scrypt(b"foo", salt=b"bar", n=2, r=1, p=1) be considered safe today? How do I judge which parameters to take?

0 Answers
Related