แฮช/การเข้ารหัส
Argon2 Hash + Verify
แฮชรหัสผ่านด้วย Argon2 (ผู้ชนะ Password Hashing Competition, RFC 9106) — รองรับ d/i/id พร้อมตรวจสอบกับแฮชที่มีอยู่
Argon2 is the Password Hashing Competition winner and the algorithm recommended in RFC 9106 for hashing passwords. Unlike bcrypt, it deliberately demands a lot of memory, not just CPU time, which makes attacks on specialized hardware (GPUs, ASICs) much harder.
How to use it
- Hash: enter a password, pick a variant (Argon2d, Argon2i, or Argon2id), and set the parameters (memory, iterations, parallelism) to get a hash.
- Verify: paste a password and an existing Argon2 hash to check whether they match, without hashing manually yourself.
- Argon2id is the recommended default for most applications — it combines the strengths of Argon2i and Argon2d.
Common uses
- Checking that a backend generates correct Argon2 hashes with the expected parameters before a release.
- Tuning memory and iteration parameters to fit within a server's response-time budget (typically 250-500ms).
- Comparing Argon2 against bcrypt or PBKDF2 when choosing an algorithm for a new project.
Things to keep in mind
The memory parameter is Argon2's main defense: the more memory hashing requires, the more expensive it is for an attacker to parallelize an attack on a GPU with limited fast memory per chip.
Argon2id is recommended for most cases: Argon2i resists side-channel attacks better, Argon2d resists GPU attacks better, and id combines both approaches.
บทความเกี่ยวกับเครื่องมือนี้: Argon2: เหตุใดอัลกอริทึมนี้จึงชนะการแข่งขันแฮชรหัสผ่าน
คำถามที่พบบ่อย
ทำไม Argon2 ถึงได้รับการแนะนำมากกว่าแฮชรุ่นเก่าอย่าง MD5 หรือ SHA-256 สำหรับรหัสผ่าน?
Argon2 ถูกออกแบบให้ช้าและใช้หน่วยความจำมากโดยตั้งใจ ทำให้การบรูทฟอร์สและการเจาะด้วย GPU/ASIC มีต้นทุนสูงขึ้นมาก ต่างจากแฮชอเนกประสงค์ที่เร็วอย่าง MD5 หรือ SHA-256 ซึ่งไม่เหมาะกับการเก็บรหัสผ่าน
พารามิเตอร์หน่วยความจำ จำนวนรอบ และความขนานควบคุมอะไร?
ต้นทุนหน่วยความจำกำหนดว่าแต่ละครั้งที่ลองแฮชต้องใช้ RAM เท่าไร จำนวนรอบกำหนดว่าจะรันกี่รอบ และความขนานกำหนดจำนวนเธรด การเพิ่มค่าใดค่าหนึ่งจะเพิ่มต้นทุนการเจาะแต่ทำให้แฮชช้าลง
ควรใช้ Argon2 แบบไหน — d, i หรือ id?
Argon2id เป็นค่าเริ่มต้นที่แนะนำสำหรับแฮชรหัสผ่าน เพราะรวมความทนทานต่อการโจมตีแบบ side-channel ของ Argon2i เข้ากับความทนทานต่อการเจาะด้วย GPU ของ Argon2d
Argon2 กลายเป็นมาตรฐานได้อย่างไร?
Argon2 ชนะการแข่งขัน Password Hashing Competition ในปี 2015 ซึ่งเป็นการแข่งขันเปิดของนักวิทยาการรหัสลับที่มีเป้าหมายเพื่อค้นหาอัลกอริทึมที่ดีที่สุดสำหรับการแฮชรหัสผ่าน นับแต่นั้นมา OWASP จึงแนะนำให้เป็นตัวเลือกอันดับแรกเหนือ bcrypt
พารามิเตอร์ความขนานเร่งเฉพาะการแฮชเท่านั้นหรือไม่?
ไม่ใช่ พารามิเตอร์เดียวกันนี้ก็เร่งการไล่เดารหัสให้ผู้โจมตีที่มีฮาร์ดแวร์หลายคอร์ได้เช่นกัน ดังนั้นควรกำหนดค่าความขนานให้สอดคล้องกับจำนวนคอร์จริงของเซิร์ฟเวอร์ ไม่ใช่เพิ่มโดยไม่จำเป็น