4 ms·
This is correct. For v3, with P' the key derived from stretching the password: "2.6 B1 and B2 are two 128-bit blocks encrypted with Twofish [TWOFISH] using P'
by zwp 11y ago
This is correct. For v3, with P' the key derived from stretching the password:
"2.6 B1 and B2 are two 128-bit blocks encrypted with Twofish [TWOFISH] using P' as the key, in ECB mode. These blocks contain the 256 bit random key K that is used to encrypt the actual records. (This has the property that there is no known or guessable information on the plaintext encrypted with the passphrase-derived key that allows an attacker to mount an attack that bypasses the key stretching algorithm.)"