3 ms·
You had me until "backups are encrypted with PBKDF2". PBKDF2 is not encryption, it is a Key Derivation Function (it says so right in the name - KDF). Given that
by cdman 13y ago
You had me until "backups are encrypted with PBKDF2". PBKDF2 is not encryption, it is a Key Derivation Function (it says so right in the name - KDF). Given that one of the developers is claiming that they are "encrypting" using PBKDF2 (which is in the same category as claiming that they are encrypting using MD5!), dissuades me from ever using it or recommending it.
- kibibu 13y agoI may be totally wrong, but isn't PBKDF2 useful exactly as a way to generate an encryption key from a password?
- ketralnis 13y agoSure, in the same way that MD5 is (although you'd want to use PBKDF2 instead of MD5). But you can't actually encrypt with PBKDF2 itself, much like you can't with MD5
- kibibu 13y agoFrom the linked discussion ([3] above): > 1. We use a 256 bit key derived using a salt and PBKDF2. > 2. AES is used in CBC mode with a different IV for each account. > 3. The key is store on the cellphone only and is never transmitted
- kylequest 13y ago> 2. AES is used in CBC mode with a different IV for each account. Depending on the actual implementation (if everything is just one encrypted blob or if individual records are encrypted separately) using the same IV for all data in one account can be pretty bad.
- phlo 13y agoYou're perfectly right. PBKDF2 (Password-based Key Derivation Function 2) takes your password as an input, derives a key from it and outputs that. This key is then fed into an encryption algorithm like AES in order to actually encrypt anything.