lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <877gk1v77w.fsf@latte.josefsson.org> Date: Wed, 17 Apr 2013 11:26:11 +0200 From: Simon Josefsson <simon@...efsson.org> To: Jeffrey Goldberg <jeffrey@...dmark.org> Cc: "discussions\@password-hashing.net" <discussions@...sword-hashing.net> Subject: Re: [PHC] Let's not degenerate when if the PRF is too narrow for desired output Jeffrey Goldberg <jeffrey@...dmark.org> writes: > This is mostly me whining. I just got bitten by the fact that PBKDF2 > does weird stuff if you ask for more derived data than is natural for > the PRF you give it. Perhaps this can be converted into a requirement for a nicer KDF: the cost to compute one bit of the output should be as high as computing the entire output? /Simon