3 ms·
PBKDF2 is a key strengthening algorithm, used to generate a key from a shared secret. AES is a block cipher. I'm not a security expert, but simply padding out t
by beala 14y ago
PBKDF2 is a key strengthening algorithm, used to generate a key from a shared secret. AES is a block cipher. I'm not a security expert, but simply padding out the password to the right number of bits seems like a huge no-no. Instead, you should be generating a key of the correct length using something like PBKDF2.
Everything I've learned about encryption, I've learned from cperciva. This presentation in particular might be worth your time: http://www.bsdcan.org/2010/schedule/attachments/135_crypto1hr.pdf http://www.bsdcan.org/2010/schedule/attachments/135_crypto1h...
Recording: http://blip.tv/fosslc/everything-you-need-to-know-about-cryptography-in-1-hour-3646795 http://blip.tv/fosslc/everything-you-need-to-know-about-cryp...
This in particular: "DO: Avoid using passwords whenever possible.
DO: Use a key derivation function to convert passwords into
keys as soon as possible.
DO: Use PBKDF2 if you want to be buzzword-compliant.
DO: Use scrypt if you want to be ≈ 2^8 times more secure against serious attackers."