4 ms·
Deriving from passphrase is optional. Mainly, for development and testing, and also for users who are ok with passphrases. Having a passphrase + server-saved s
by michwill 11y ago
Deriving from passphrase is optional. Mainly, for development and testing, and also for users who are ok with passphrases.
Having a passphrase + server-saved salt makes it better than a passphrase with no salt (for brute-force by dictionary).
If you think about it, security of passphrase approach is tested all the time with Bitcoin brain wallets. Over there, private keys are derived using SHA256 (which is fast to compute!) with no salt. It's hard for humans to generate good passphrases, so these wallets do that for them (usually 12 words).
But yeah, in most production usecases it would be some certificate, or KMS
- swordswinger12 11y agoYeah, this approach has been tested and has failed miserably: http://eprint.iacr.org/2016/103.pdf http://eprint.iacr.org/2016/103.pdf