Dwolla’s Password Hashing Requirements
Dwolla’s Password Hashing Requirements
- Jul 22, 2025
- Knowledge
Information
Title
Dwolla’s Password Hashing Requirements
Summary
When handling or storing passwords, all passwords need to be hashed.
Hashing is a function that takes a string (a sequence of characters such as a password) and transforms it into a fixed-length string of letters and numbers. This operation cannot be reversed. Some common password-based hashing algorithms to use are argon2, scrypt, bcrypt, and PBKDF2.
Not all hashing algorithms are created equal. Many algorithms are designed to be fast. This is often desirable in cases where they're used for "on the fly" integrity checking or other performance-sensitive purposes.
However, in the case of authentication, this is the opposite of what we want! If you use a fast hashing algorithm (like SHA256 by itself), an adversary with the right hardware eventually can guess the original password by trying tens of billions of keys per second.
For one password, we suggest aiming for a speed between one-tenth of a second to one second. This is tricky because hardware is constantly getting faster, so the required parameters to achieve this change over time. Additionally, these schemes typically only make sense for interactive logins. The slow-downs introduced here may be too impactful for API-based traffic that requires low latency and high throughput.
You can find more information on password hashing in our related blog posts.
URL Name
Dwolla-s-Password-Hashing-Requirements