Hashing passwords in 2026

Back to list2026-02-03
You

bcrypt, scrypt or argon2 for a new project?

ChatGPT

Argon2id with the current OWASP parameters, and bcrypt only when a library constraint forces it. What matters more than the choice is that the cost parameter is revisited: a setting tuned five years ago is now cheap to attack.

You

What is a sane rate limit design for a public API?

ChatGPT

Token bucket per key and per IP, with the limit expressed in the response headers so clients can behave. The subtle part is what you do on limit: a 429 with Retry-After is cooperative, silently dropping is what turns one misbehaving client into a retry storm.

You

Do I need CSRF protection if I use bearer tokens?

ChatGPT

Not if the token lives in memory and is sent in a header, because the browser will not attach it automatically. The moment it moves into a cookie for convenience, CSRF is back, and SameSite=Lax becomes load-bearing.