Repository navigation
"async" argon2 freezes the main event loop #62861
Copy link
Copy link
Closed
Labels
cryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.experimentalIssues and PRs related to experimental features.Issues and PRs related to experimental features.performanceIssues and PRs related to the performance of Node.js.Issues and PRs related to the performance of Node.js.securityIssues and PRs related to security.Issues and PRs related to security.
Description
Activity
- changed the title
[-]async argon2 freezes the event loop[/-][+]async argon2 freezes the main event loop[/+]on Apr 21, 2026 - changed the title
[-]async argon2 freezes the main event loop[/-][+]"async" argon2 freezes the main event loop[/+]on Apr 21, 2026 - addedcryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.
on Apr 21, 2026 - addedsecurityIssues and PRs related to security.Issues and PRs related to security.
on Apr 21, 2026 FYI the API is still in
Yes, I'm aware, and that's precisely why this is public!
Yes, I'm aware, and that's precisely why this is public!
I'm aware that you're aware :) Just calling it out for clarity.
Reacted by Nikita Skovoroda@ChALkeR what about the scrypt or PBKDF2 jobs?
I'm aware that you're aware :) Just calling it out for clarity.
It had "FYI" so I replied 😄
@ChALkeR what about the scrypt or PBKDF2 jobs?
@panva scrypt is fine:
console.time('ASync') console.time('Sync') scrypt('password', 'salt', 64, { N: 2**18, maxmem: 2**30 }, () => console.timeEnd('ASync')) console.timeEnd('Sync')
Sync: 0.4ms ASync: 416.924mspbkdf2 is fine too:
console.time('ASync') console.time('Sync') pbkdf2('secret', 'salt', 1e6, 64, 'sha512', () => console.timeEnd('ASync')) console.timeEnd('Sync')
Sync: 0.117ms ASync: 201.389ms
compare to argon2:
console.time('ASync') console.time('Sync') argon2('argon2id', parameters, () => console.timeEnd('ASync')) console.timeEnd('Sync')
passes=10 (parameters from doc example):
Sync: 117.201ms ASync: 217.662mspasses=100:
Sync: 974.533ms ASync: 2.034spasses=1000:
Sync: 8.570s ASync: 16.860sIt literally is just computed twice: once in sync, once in async, per every async call (at least judging from the numbers)
- addedperformanceIssues and PRs related to the performance of Node.js.Issues and PRs related to the performance of Node.js.
on Apr 21, 2026 - addedexperimentalIssues and PRs related to experimental features.Issues and PRs related to experimental features.
on Apr 21, 2026 - added a commit that references this issue
on Apr 21, 2026 - added a commit that references this issue
on Apr 25, 2026 - added 3 commits that reference this issue
on May 5, 2026 - added a commit that references this issue
on Aug 12, 2026
Metadata
Metadata
Assignees
Labels
cryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.experimentalIssues and PRs related to experimental features.Issues and PRs related to experimental features.performanceIssues and PRs related to the performance of Node.js.Issues and PRs related to the performance of Node.js.securityIssues and PRs related to security.Issues and PRs related to security.
Original detect from @deepview-autofix:
To validate:
cc @panva perhaps?
Likely too complex for an autofix.
Also does not qualify to be a security bug, hence public.