4 ms·
This is a bad idea because if you can generate your key from a passphrase, everyone else in the world can do so also. This tool "helpfully" tags all keys it gen
by ryan-c 7y ago
This is a bad idea because if you can generate your key from a passphrase, everyone else in the world can do so also. This tool "helpfully" tags all keys it generates (via timestamp = 0) to announce the potential vulnerability.
Yes, this implementation uses the user id as a salt to prevent lookup tables from being built.
Yes, this implementation uses aggressive KDF settings to deter this sort of attack.
People are still really bad at choosing passwords and passphrases. They often pick phrases from obscure, but public, sources, thinking they're clever.
When the "let's derive asymmetric keys from a passphrase" idea was applied to cryptocurrencies the results were catastrophically bad. I gave a talk at DEFCON about this four years ago:
https://www.youtube.com/watch?v=foil0hzl4Pg https://www.youtube.com/watch?v=foil0hzl4Pg
There are some marginally valid use cases for keys that can be memorized, but for those cases, tools should offer opinionated passphrase generation tools that make it impractical to pick a bad passphrase. A simple way to do this would be to require that e.g. the first x bits (10 to 16 probably?) of sha256(passphrase) are zero, and bundle a tool that takes in a wordlist, an output passphrase strength, and user provided entropy (to be combined with system entropy for users who don't trust the system csprng), and spit out a compliant diceware-style passphrase.