4 ms·
My guess is they're using the standard approach for deriving an encryption key from a password: http://en.wikipedia.org/wiki/PBKDF2 http://en.wikipedia.org/wiki
by arantius 12y ago
My guess is they're using the standard approach for deriving an encryption key from a password: http://en.wikipedia.org/wiki/PBKDF2 http://en.wikipedia.org/wiki/PBKDF2
- gabriel34 12y agoThanks for the clarification (and thanks to throwaway above as well), seems this is standard. Is there a salt in this implementation? Is it bruteforced the first time I open the database on a new device?
- throwaway41597 12y agoIt says the encryption is done client-side so a salt would be public. edit: they may be salting with the username or email address.