3 ms·
>> What does password complexity have to do with the strength of the algorithm used to generate passwords? It is not the algorithm only but if you can look a l
by marcusfrex 10y ago
>> What does password complexity have to do with the strength of the algorithm used to generate passwords?
It is not the algorithm only but if you can look a little bit more closely, it is iteration count too. It uses 1.000 times and 10.000 times more iterations respectively.
Plus, depending on complexity, character set range enlarges.
>> Why is this using PBKDF2?
We would like to use more industry-standart way of things rather than individual works.
>> Is the "commercial" version of this also Ruby code wrapping OpenSSL?
Commercial version is purely written C version of it and backed up with OpenSSL on some cases.
- tptacek 10y agoI don't think I asked the most important question clearly enough: Why do simpler passwords get a different construction? What does password complexity have to do with KDF hardness?
- marcusfrex 10y agoIt's probably because different understanding of same terms. With "complexity" word we mean hardness to generate. It doesnt adds up more algorithms but character sets and hashing algorithms for PBKDF2 respectively.
- tptacek 10y agoWhy, exactly, would a user ever want to generate a password with a weaker KDF? A password with lower levels of string complexity might make sense --- 1Password's strong passwords can sometimes be rejected by crappy websites. A password that sacrifices cryptographic strength in order to save a few tens of milliseconds of KDF, though, makes no sense at all. Also: really, you should not be using PBKDF2.
- Scaevolus 10y agoI want a password manager with Argon2 configured to take 10 seconds and 1GB of RAM, playing a gratuitous 3D animation of a vault slowly opening alongside CPU and bandwidth utilization graphs. Or if your attack model allows that reading protected files off a user's device is less likely than the cloud-synced database being compromised, you might derive the master encryption key as KDF_fast(KDF_slow(password)+password)), where KDF_slow takes 5 minutes and is stored on disk, but KDF_cheap takes 5 seconds.
- aparadja 10y agoHonest question: what's wrong with PBKDF2?
- gakada 10y agoIt's much weaker. Only reason for a password manager to use it is laziness or ignorance.