Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You might want to add "with a high number of iterations or work factor," at least. PBKDF2-HMAC-SHA-256 is just as useless as 2xSHA-256 if you just do one iteration.


Yes - this is reasonable. I'd generalise this to:

"Use an accepted key derivation function, such as PBKDF2, bcrypt or scrypt, with accepted parameters".

What is "accepted" changes over time, of course.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: