[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <alpine.DEB.2.10.1403101031540.13698@debian>
Date: Mon, 10 Mar 2014 10:38:16 +0100 (CET)
From: Stefan.Lucks@...-weimar.de
To: discussions@...sword-hashing.net
Subject: Re: [PHC] Upgrade HKDF to HKDF2?
On Sun, 9 Mar 2014, Bill Cox wrote:
> for(i = 0; i < passwordLength; i += 256) {
> for(j = 0; j < 256; j++) {
> buf[i] = password[(i + j) % passwordLength];
> }
> Hash_Update(hashCtx, buf, 256);
> }
Welcome password collisions!
Consider, e.g., passwords such as "abcd", "abcdabcd", "abcdabcdabcd" ...
Stefan
------ I love the taste of Cryptanalysis in the morning! ------
<http://www.uni-weimar.de/cms/medien/mediensicherheit/home.html>
--Stefan.Lucks (at) uni-weimar.de, Bauhaus-Universität Weimar, Germany--
Powered by blists - more mailing lists