A security engineer is selecting a hash function to protect stored user passwords in a new application. The threat model assumes an attacker who steals the password database and has substantial GPU resources for offline cracking. Which choice best addresses this threat?
Argon2id is purpose-built for password storage and its memory-hard design sharply limits GPU parallelism, because each guess requires substantial memory that GPUs cannot multiply cheaply. Tuned time and memory costs plus unique per-user salts make offline cracking of a stolen database far more expensive than with fast general-purpose hashes.
Why this answer
Password storage needs a deliberately slow, memory-hard function so each offline guess is expensive and GPU parallelism is blunted. Argon2id with tuned parameters and unique per-user salts achieves this, whereas fast hashes, reversible encryption, and a single global secret all fail against an attacker with stolen data and strong cracking hardware.
Exam trap
The trap here is assuming that salting or iterating a fast general-purpose hash like SHA-256 is sufficient, when only a memory-hard function meaningfully raises the cost of GPU-accelerated offline cracking.