4 ms·
Correction: Scrypt actually uses PBKDF2 internally. (Previously said "scrypt is based on PBKDF2" but that's a loaded statment.) PBKDF2 is an improvement over P
by sarciszewski 11y ago
Correction: Scrypt actually uses PBKDF2 internally. (Previously said "scrypt is based on PBKDF2" but that's a loaded statment.)
PBKDF2 is an improvement over PBKDF1 (and other naive iterated hash constructions), but attacks got better and better defenses are called for.
- cperciva 11y agoScrypt is based on PBKDF2. No, it really isn't.
- sarciszewski 11y agoI could have sworn it used PBKDF2-SHA256 and Salsa20/8 internally, which is what I meant by "based on".
- cperciva 11y agoIt also uses xor internally, but I wouldn't say that scrypt is based on xor. scrypt does not use PBKDF2 for any PBKDF properties; it's just a convenient arbitrary-length-output hash function. I would have used a sponge if they had been widely available when I created scrypt.
- sarciszewski 11y agoOkay, thanks for the clarification.