in reply to Replacing crypt() for password login via a digest - looking for stronger alternative

+1 for Authen::Passphrase::BlowfishCrypt, we use it in our main product at $work. It creates salted hashes, and it has an adjustable cost parameter to decrease efficiency of brute-force attacks on faster hardware in the future.

It's compatible with pgcrypto, which we've used in the past.

  • Comment on Re: Replacing crypt() for password login via a digest - looking for stronger alternative