Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Argon2id is a strong default for a new password-storage system because it makes each password guess costly in both computation and memory. That expense affects legitimate logins too, so the right setting is not simply “as high as possible”: it must fit the service’s latency, memory budget, and expected login concurrency.

What “faster” means for password hashing

A password-storage function is used to verify a submitted password against a stored hash. A fast function may reduce the work for a legitimate login, but it can also let an attacker who has obtained password hashes test more guesses in a given amount of time. The relevant comparison is therefore not just how quickly a server verifies one password; it is how the chosen parameters affect both defender capacity and an attacker’s cost per guess.

Passwords should be stored with an adaptive password-hashing function and a unique salt—not as plaintext and not as a fast general-purpose hash such as SHA-256 used alone. A salt makes identical passwords produce different stored results; it is not a secret key. A password hash is not encrypted data and cannot simply be decrypted to recover the password. OWASP explains the rationale for password-specific hashing in its Password Storage Cheat Sheet.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why Argon2id is a defensible choice

Argon2id is a memory-hard password-hashing function: its parameters let an implementation require memory as well as computation. This matters because the design aims to make large-scale guessing more resource-intensive, rather than relying only on repeated calculations. OWASP recommends Argon2id for password storage and describes it as balancing resistance to side-channel and GPU-based attacks.

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

RFC 9106 specifies Argon2 as a memory-hard function for password hashing and proof-of-work applications. It was published by the RFC Editor in September 2021. The specification includes its own recommended parameter profiles, which are distinct from OWASP’s operational minimum guidance; they should not be blended into a single purported universal default. See RFC 9106.

Choose parameters for the system that will run them

Argon2id exposes memory, time, and parallelism costs. Increasing the costs raises the resources needed for verification and for each offline guess, but also affects login latency and how many verifications the service can handle at once. A setting that is reasonable for one server or workload may be unsuitable for another.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

OWASP’s minimum guidance

OWASP’s current Password Storage Cheat Sheet guidance, accessed in 2026, specifies a minimum Argon2id configuration of 19 MiB of memory, two iterations, and parallelism one. This is a minimum recommendation, not a measured speed result or a claim that the setting fits every production environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Benchmark under expected load

Benchmark the selected configuration on the actual target system and under expected load. Consider the latency target for a login, the memory available to authentication work, and the number of verifications that may run concurrently. If memory-intensive verification is allowed to run without regard to concurrency, aggregate resource use can become a capacity problem even when a single verification performs acceptably. The cited guidance does not establish timings for a particular machine, so there is no sound universal claim that one option is “fastest.”

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

When another password-hashing option fits better

Argon2id is not automatically the right answer when platform support, legacy data, or compliance requirements constrain a system. OWASP’s recommendations distinguish several cases:

Option When it may fit Important qualification
Argon2id OWASP’s recommended choice for password storage when it is available. Tune its cost and benchmark locally; memory use and latency affect authentication capacity.
scrypt OWASP’s fallback when Argon2id is unavailable. It also has configurable CPU and memory costs, block size, and parallelization.
bcrypt A legacy system where migration or support constraints make continued use necessary. OWASP specifies a work factor of 10 or more and notes a 72-byte password limit.
PBKDF2 The OWASP choice in the stated FIPS-140 compliance scenario. OWASP specifies HMAC-SHA-256 with a work factor of 600,000 or more for this guidance. Confirm the requirements that apply to the deployment; this guidance does not certify a particular product or cryptographic module.
Fast general-purpose hash, such as SHA-256 alone Not suitable as a password-storage function. Its speed can enable many guesses; use a password-hashing function with appropriate cost instead.

These figures are guidance for the stated algorithms and circumstances, not a head-to-head performance ranking. In particular, the PBKDF2 work factor is not an Argon2id setting, and OWASP’s bcrypt work factor and password-length caveat do not establish comparable timing.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Make the choice without assuming a speed winner

  • For a new system: start with Argon2id if your libraries and deployment support it, then tune its parameters for the real service.
  • If Argon2id is unavailable: OWASP identifies scrypt as a fallback; evaluate its configurable costs against the same capacity constraints.
  • If you must retain bcrypt: account for its 72-byte password limit and plan around the system’s legacy or compatibility requirements.
  • If FIPS-140 compliance is required: review the applicable requirements and OWASP’s PBKDF2 guidance rather than treating Argon2id as a universal compliance answer.
  • Do not choose a hash because it wins an unqualified speed claim: a meaningful comparison requires a named system, parameter settings, workload, and a clear distinction between verifier latency and attacker cost per guess.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the choice does—and does not—establish

Choosing Argon2id expresses a security and operational trade-off: increase the resources required per guess while keeping legitimate verification manageable for the service. OWASP’s recommendation supports that choice for password storage, but it does not establish a universal parameter setting, a particular deployment’s performance, or that every faster alternative is insecure. The appropriate option depends on available implementations and the system’s constraints.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.