3 ms·
Usually encryption schemes use a key derivation function like PBKDF2 to "stretch" a user's password to generate 128/256 bits for the symmetric cipher. In this c
by moonboots 14y ago
Usually encryption schemes use a key derivation function like PBKDF2 to "stretch" a user's password to generate 128/256 bits for the symmetric cipher. In this case, the attacker cannot bruteforce aes directly because the generated key is "randomly" selected from the impossibly large 256 bit key space. The attacker now must feed his password guesses through the key derivation function, which hopefully will slow the attacker enough that even the smaller space of memorable user passwords is too large to bruteforce.
It doesn't seem so ludicrous if it works.
No key derivation function will protect from very short passwords, which is effectively the scenario here as the author is helping the attacker narrow number of possible passwords to 22472.
As a side note, my interpretation is that the author's password is longer than 6 characters, and he cannot remember 6 of the characters.