Algorithms

Argon2d

Argon2 with memory reads that follow the data. The fastest to hurt a GPU and the wrong pick when someone shares the machine
IDargon2d38 / 38Argon2 · variable
Hash / Password

Argon2d

Argon2 whose reads follow the data, fit for proof of work.

Digest
keyLength you pick
HMAC
no key mode
Security
Its reads follow the data and can leak through a side channel
Family
3 in Argon2
8 options, 0 required

Sample

hex
74e24cdeacbfa81c92481ed3f8f43accb71957504c94e2679daa7f88cde8f99d
base64
dOJM3qy/qBySSB7T+PQ6zLcZV1BMlOJnnap/iM3o+Z0=

Options

encodingstring
default hex
Output encoding: hex, base64, base64url, binary
saltstring
optional
Salt in hex; 32 random bytes when omitted
memorynumber
default 65536
Memory in KiB, at least 8 per lane
iterationsnumber
default 3
Passes over the memory
parallelismnumber
default 4
Lanes
keyLengthnumber
default 32
Output key length in bytes, at least 4
secretstring
optional
Secret key in hex, a pepper
associatedDatastring
optional
Associated data in hex

Access

Createcreate("argon2d")
CLIhashes argon2d 'hello world' --salt 73616c7473616c74 --memory 1024 --iterations 2 --parallelism 1
Tryplayground with the sample above
Kinargon2id, argon2i

argon2d lets the data pick the next block to read. A cracker can't guess the order, so dropping memory gets expensive fast. The catch? Timing. Those reads follow the password, and a process next to yours can watch them. RFC 9106 points it at cryptocurrencies and proof of work. Nobody sneaks onto that box.

ts
create("argon2d").hash("password", {
  salt: "73616c7473616c74",
  memory: 1024,
  iterations: 2,
  parallelism: 1,
}).digest;
// "32d03e4754ab2c9369e56f14f9ac2f496ea2b15b75be1d7882b44783f09c5281"

A puzzle that says "Argon2" and nothing else? Try all three. The variant is one number in the first hash, and it changes every byte after.

Options, defaults and the byte function argon2d from @agntn/hashes/argon2 work exactly like on the argon2id page.