Thus, you can parallelize an attack using lots of specialized ASICs...
More to the point, you can parallelize attacks on most KDFs by building an ASIC with many copies of a password-cracking circuit. With scrypt, the vast majority of the IC area (and thus cost) is RAM.
Comments
Thus, you can parallelize an attack using lots of specialized ASICs...
More to the point, you can parallelize attacks on most KDFs by building an ASIC with many copies of a password-cracking circuit. With scrypt, the vast majority of the IC area (and thus cost) is RAM.