In 1999, #bcrypt required using 6 or 8 “rounds” (really lg rounds) for reasonable #performance; nowadays 12 or more is probably necessary for #security.
on 02015-08-18#bcrypt in pure #node #JS has #performance of 108ms with rounds=9 (which really means 2⁹ rounds) on a 3GHz CPU; a C++ version takes 76ms. It would probably make sense to use 13 or 14 nowadays, as a result, unless you’re running bcrypt on your smartphone.
on 02015-08-18#bcrypt’s cost parameter is the log-base-2 of the number of rounds to use for #key-stretching.
on 02015-08-18