Using an inefficient cipher slows the attacker down by a constant factor, and this is in fact done in the UNIX crypt() implementation. This technique, however, can only yield a limited benefit because of the range of platforms that the client may be running. Javascript implementations in some browsers, for example, are extremely slow. To improve password security and concluded that the only technique offering a substantial long term improvement is for users to increase the entropy of the passwords they generate.











