4 ms·
I'm no expert but I see no harm here. In order to use symmetric encryption, you need a certain key size (e.g. 128-bit key for AES-128). How do you transform a p
by throwaway41597 12y ago
I'm no expert but I see no harm here. In order to use symmetric encryption, you need a certain key size (e.g. 128-bit key for AES-128). How do you transform a password of, say, 15 characters to 128 bits? You guessed it, with a hash (well a key derivation function to slow down brute force). What they do is I think standard practice.
> but not increase the number of possible keys
So yes, if your password is weak, then it won't make it strong.
> while actually lowering security (since hash collisions can occur)
But I think you're wrong here. On a human password of 30 bits of entropy, there is very little chance of collision. If one collision was to happen, you'd still have a key space of (30^2) - 1, which is very much the same number.