[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAOLP8p5bRbEXWsqRbTJ2pPLLK01fJe9ThQW2qX9A6Rgd92eXvA@mail.gmail.com>
Date: Thu, 3 Apr 2014 14:00:14 -0400
From: Bill Cox <waywardgeek@...il.com>
To: discussions@...sword-hashing.net
Subject: Re: [PHC] babbling about trends
On Thu, Apr 3, 2014 at 1:48 PM, Thomas Pornin <pornin@...et.org> wrote:
> (Self-promotion: in that model, an algorithm which allows delegation of
> work to untrusted third parties can be quite handy.)
>
>
> --Thomas Pornin
Is it fair to say that the most interesting aspect of your entry is
the delegation capability? I find that fascinating. IIRC, there's no
arbitrary hash function called during delegation. Is it possible to
add a memory-hard hash function call to the delegated password
hashing? Maybe it's already there... after reading 23 papers, my head
is mush.
Another thing I get confused about is the entries that have server
specific short-cuts in computing the hashes. Yours seems quite
ingenious to me in that respect, and I know the PHC site called for
such innovations specifically. However, I get confused as to why this
is better than just having a server master password used to decrypt
password/user specific secret secondary keys?
Bill
Powered by blists - more mailing lists