yescrypt Catena-like features Current: Client-side computation of almost final yescrypt hashes (server relief) in a way allowing for a straightforward extension of SCRAM (RFC 5802) Planned: Hash upgrades to higher cost settings without knowledge of passwords Can be defined and implemented without breaking compatibility with current yescrypt Will support over 60% area-time efficiency, as opposed to Catena's over 33% Optional full or partial cache timing side-channel resistance This is a trade-off since it weakens TMTO resistance and removes dependency on memory latency (but yescrypt's multiplication latency hardening will help)