Pra quem é noob em criptografia,no geral, chave simétrica é ruim.
Mas essa história de um metodo ser pior do que o outro tem que ser analisada melhor.
O que me assustou:
http://www.net-security.org/vuln.php?id=5625"openSUSE is prone to an insecure password-hash weakness.
This issue stems from a design error when 'libxcrypt' is used to calculate password hashes. This weakness can result in the creation of weak passwords and can lead to a false sense of security.
Note that the default installation of openSUSE uses 'blowfish', which isn't affected by the hash issue."