3 ms·
Adding extra random characters to the end of the passphrase requires effort from the user, key derivation only requires them to wait. Ideally, one should use a
by ryan-c 3y ago
Adding extra random characters to the end of the passphrase requires effort from the user, key derivation only requires them to wait.
Ideally, one should use a strong passphrase with strong key derivation parameters.
You're free to make whatever security trade-offs you like, but don't presume they make sense for everyone.
- deleted 3y ago[deleted]