Study. uk . com
  1. Home
  2. All questions
  3. Question 325

CISSP study material · question 325 of 500

A password hashing cost factor was chosen in 2018 and has never changed. What does NIST SP 800-63B recommend?

  1. Set it as high as practical without harming verifier performance, and raise it over time as computing power grows.
  2. Fix it at enrolment so that stored hashes remain comparable.
  3. Lower it as the user base grows, to preserve login latency.
  4. Replace the cost factor with a longer salt instead.
Show the answer

Answer: A. Set it as high as practical without harming verifier performance, and raise it over time as computing power grows.

Set the factor as high as the verifier can bear, and raise it over the years so that hardware improvements do not erode the defence.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 > 3.1.1.2 Password Verifiers

Challenge yourself on this topic → Study as cards