3 ms·
right, that's what I labeled the password-derived encryption use case. Great to do the XKCD mechanism, and if you follow the link in that article you'll see tha
by benadida 14y ago
right, that's what I labeled the password-derived encryption use case. Great to do the XKCD mechanism, and if you follow the link in that article you'll see that we're working on maximizing the key stretching we can do based on passwords:
https://wiki.mozilla.org/Identity/CryptoIdeas/01-PBKDF-scrypt https://wiki.mozilla.org/Identity/CryptoIdeas/01-PBKDF-scryp...
But unless you have a crazy long passphrase, you're not going to get 128 bits, let alone 256.
- kragen 14y agoYeah, I did read Warner's proposal. It's full of awesome, as his ideas usually are. Were you around that time that he showed Memento at his house, but with the scenes in chronological order? As I explained in a late edit to my comment, this is distinct from your "password-derived key" case because it eliminates the major drawback of that case: "This is not as secure as the previous setting, since most user passwords are not nearly as strong as full-strength crypto keys." If you generate high-entropy passphrases, that problem goes away. 128 bits is overkill for defense against brute force. You can do maybe 2³⁰ crypto operations per second in a custom crypto-cracking processor, pack maybe 2²⁰ of them onto a custom chip, use maybe 2²⁰ custom chips in your Crypto Cracking Center in your evil genius volcano base, and let it run for maybe a year, 2²⁵ seconds, before you get bored. That's still only enough to search 2⁹⁵ keys, so you should be pretty safe with keys that need 2¹⁰⁰ operations to crack, at least for a few years. Or, if you don't have a supervillain or major intelligence agency devoting their full computational resources to reading your browser bookmarks, 2⁸⁰. I do think it's actually feasible for someone to memorize an 11-word phrase encoding a 128-bit key, but it would take several minutes and careful practice over the next few weeks to be sure they didn't forget it, and using a decent PBKDF with a 7- or 8-word passphrase is probably a better option.