[i7]
As hardware continues to advance with more powerful GPUs and specialized ASICs, does the work factor the cost parameter in bcrypt provide enough of a future-proof shield, or will we eventually reach a point where even the maximum slowness we can tolerate for a legitimate user login is no longer enough to deter a massive parallel attack?
What do you think? is there a limit to how much we can keep slowing things down before it breaks the user experience