4 ms·
I'm new to infosec and I'm having a bit of trouble understanding how PasswordSafe is able to modify the master password without re-encrypting the entire databas
by iraphael 11y ago
I'm new to infosec and I'm having a bit of trouble understanding how PasswordSafe is able to modify the master password without re-encrypting the entire database with the new salt.
The only scenario I see this happening is if, upon the creation of a new master password, PasswordSafe encrypts the header (with the old password). This way, when the user enters their new password, PS uses it to decrypt the header, and then uses the old password (stored in the header) to decrypt the database. This would make it easy for someone with access to the old password and the database to simply decrypt it.
Is this how it works? I can't think of any other way it would be able to not re-encrypt the database with the new password. Plus the lingo/acronyms in the paper are going a bit over my head.
- ryan-c 11y agoGenerally these things work by creating a master key to encrypt the data. The master key is then encrypted with a key derived from the password. To change the password the master key just needs to be reencrypted.
- zwp 11y agoThis is correct. For v3, with P' the key derived from stretching the password: "2.6 B1 and B2 are two 128-bit blocks encrypted with Twofish [TWOFISH] using P' as the key, in ECB mode. These blocks contain the 256 bit random key K that is used to encrypt the actual records. (This has the property that there is no known or guessable information on the plaintext encrypted with the passphrase-derived key that allows an attacker to mount an attack that bypasses the key stretching algorithm.)"