Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That reminds me of the sage advice Bruce Schneier wrote in Secret and Lies, "Anyone who creates his or her own cryptographic primitive is either a genius or a fool. Given the genius/fool ratio for our species, the odds aren't very good."


He's saying to build a custom function out of well established cryptographic primitives.

I don't think that's a good idea either. There's still a ton that can go wrong that won't be apparent at all to someone who knows how to analyze entropy flows through the internals of hash functions. There's a reason why we have a PBKDF2 that's favored over the original PBKDF.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: