3 ms·
I like this idea to reduce dependence on trusting any given algorithm. If I'm a global passive adversary, I would try to attack your blobs in these ways: 1) w
by blake8086 13y ago
I like this idea to reduce dependence on trusting any given algorithm.
If I'm a global passive adversary, I would try to attack your blobs in these ways:
1) weaken your random number generators
2) guess your password by running massive dumps of passwords and passwords mutated with rules against pbkdf2 (why didn't you use scrypt?)
3) try to convince you or your system to decrypt a blob and reveal the plaintext to me surreptitiously (not so passive)
4) try to get your password from security flaws in wherever you store it
5) conduct traffic analysis on who is storing blobs where and when, and how long their blobs are
My bet is that the password is the weak point. Can you do anything to address that?
- rorrr2 13y ago1) How do you do that? His random generator is not even controlled by him, it's a bunch of open source browsers. 2) That's basically bruteforcing. Considering he is running pbkdf2 thousands of times, good luck with that. You might get lucky with 5-6 character passwords and a bunch of servers. 3) How? 4) Passwords are usually stored either nowhere (inside user's head) or a program like KeePass. Good luck breaking either. 5) What would that give you? It's still triple-encrypted.
- bankIsSketch 13y agoPasswords have always been a weak point. This has been widely discussed for the last two decades of security research. Solving the password dilemma is not his or her intention.
- maxtaco 13y agoPasswords are bound to be weak, you are right. Running PBKDF2 only gives some protection against password-cracking, but a well-funded adversary can overcome that protection if the original password doesn't have enough entropy. For passwords, I recommend using a sequence of 4-5 random words chosen from a ~20k word dictionary. This gives you about 58 to 72 bits of entropy. I also recommend https://oneshallpass.com https://oneshallpass.com for giving random PWs to different Web sites, but that's a slightly different problem.