3 ms·
Amusing to see a comment mention 14 work factor and the code is 12 rounds. Code and comments get out of sync so quickly. Out of interest, why the static salt
by throwawayReply 10y ago
Amusing to see a comment mention 14 work factor and the code is 12 rounds.
Code and comments get out of sync so quickly.
Out of interest, why the static salt in addition to bcrypt?
- arkadiyt 10y agoNot the author but if I had to take a guess I'd say they might have been trying to pepper the hash: https://en.wikipedia.org/wiki/Pepper_(cryptography) https://en.wikipedia.org/wiki/Pepper_(cryptography). It's not particularly useful here since if someone got access to your remote encrypted file and knew it was made with sdees, the pepper is public. However if the value was configurable by the user then it could provide an extra layer of protection against someone brute forcing the hash and getting your password. A better approach would be to not store a hash of the password at all. The author uses it to check that the user supplied the correct password when attempting decryption - instead you can decrypt the file using whatever password the user provides (getting either correct or garbage output back), and check for a magic value in the output.
- qrv3w 10y agoThanks! I will do that.