5 ms·
Are DMG passwords really going through 250,000 rounds of PBKDF2-HMAC-SHA1? I've been using the Python PBKDF2 module with fewer iterations as it takes over 18 s
by thomas-st 14y ago
Are DMG passwords really going through 250,000 rounds of PBKDF2-HMAC-SHA1?
I've been using the Python PBKDF2 module with fewer iterations as it takes over 18 seconds to hash a password with 250,000 iterations on my 2.7 GHz Core i5:
In [1]: import pbkdf2
In [2]: %time pbkdf2.PBKDF2('mypassword', open('/dev/urandom').read(16), 250000).read(32)
CPU times: user 18.36 s, sys: 0.07 s, total: 18.43 s
Wall time: 18.45 s
Out[2]: '<>\x17\x03q+\x1d\x1c+\x94^\xa2\xc9&\xa9\xa56\xc2\xfa\x97A\xd7\xfb\xc8\x93r\x9d\xa0\xd67|\x1e'
Also, everyone else seems to be using way fewer iterations, e.g. 5000 for LastPass (http://helpdesk.lastpass.com/security-options/password-iterations-pbkdf2/ http://helpdesk.lastpass.com/security-options/password-itera...)
I wonder if the C implementation is much faster, or if Apple uses some special hardware acceleration (GPU or special CPU instructions), as I'd love to increase the number of iterations in my Python application.
- oakenshield 14y ago> I wonder if the C implementation is much faster Very likely -- Run this on your machine and see if it improves things http://stackoverflow.com/a/9781943 http://stackoverflow.com/a/9781943. I got about 18.6s for your python code while this one with a 16 byte salt and 250k iterations runs in 0.6s. OWASP recommends over 100k iterations too: https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet#Rule_3:_Iterate_the_hash https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet...
- thomas-st 14y agoTrue, looks like it's important to use a C module if available: In [13]: from M2Crypto.EVP import pbkdf2 In [14]: %time pbkdf2('mypassword', open('/dev/urandom').read(16), 250000, 32) CPU times: user 1.16 s, sys: 0.02 s, total: 1.18 s Wall time: 1.18 s
- oakenshield 14y agoI may not understand the whole context, but if you're using PBKDF2 for key derivation, you don't want to use something that works "fast". You want whatever algorithm/iteration combination that is as slow as possible [1], but not too slow that it annoys the user. [1] on modern hardware, that is.
- moonboots 14y agoThe kdf should be as slow as possible for an attacker but fast enough for you. If you're using python and the attacker is using C, you can increase security with no usability loss by switching to C and raising the iteration count.
- jgeralnik 14y agoUsing a slow implementation of PBKDF2 is not going to slow down attackers who use a fast implementation.
- oakenshield 14y agoCorrect. I didn't mean slow implementation, I meant slow enough on modern hardware using the fastest implementaiton.