scrypt time-memory tradeoff

Colin, all -

This is probably nothing new to you, but here's some analysis Anthony
Ferrara (ircmaxell) posted regarding an attacker making scrypt run in a
lot less memory, by trading CPU/GPU time for that:


For some settings and some types of attacker's equipment (not ASICs, but
GPUs with their constraints) the trade-off might be worthwhile, although
I think that it is not for the settings given by ircmaxell and for
present GPUs, and it would not provide impressive performance anyway
(potentially just slightly better than the straightforward approach).