4 ms·
From that link: HMAC(K,m) = H((K ⊕ opad) ∥ H((K ⊕ ipad) ∥ m)).
by Xk 16y ago
From that link:
HMAC(K,m) = H((K ⊕ opad) ∥ H((K ⊕ ipad) ∥ m)).
- iwwr 16y agoWhy would HMAC be inappropriate in this case (of storing user credentials)? Is there a vulnerability? HMAC(key, password) instead of hash(password) or hash(salt+password)
- Xk 16y agoI don't know of any attack. However, my point is just that HMAC means using hashing for a message authentication code. Encrypting hashes makes more sense as to what's going on.