3 ms·
My mistake we are using PBKDF2 already on both iOS and Android. One of the developers added PBKDF2 while doing the implementation. I didn't know exactly how th
by danielpal 14y ago
My mistake we are using PBKDF2 already on both iOS and Android.
One of the developers added PBKDF2 while doing the implementation. I didn't know exactly how they had implemented the encryption - so I asked to clarify.
So to be completely clear:
1. We use a 256 bit key derived using a salt and PBKDF2.
2. AES is used in CBC mode with a different IV for each account.
3. The key is store on the cellphone only and is never transmitted