Hacker News new | past | comments | ask | show | jobs | submit login

Eh? PBKDF2 has configurable complexity and has found many more applications than bycrpt, from WPA2 to disk encryption. The crypto research behind PBKDF2 is much more rigorous.



Please cite one academic cryptography paper that presents an analysis of PBKDF2, other than Colin's paper which damns it.

There is virtually no "rigorous" research into KDFs of any sort, let alone password KDFs. Most academic crypto research simply presumes passwords are taken from cryptographically secure random number generators and stored securely.

And with that said I want to remind you that I just cited a source, accepted at Usenix, that measured PBKDF2, bcrypt, and scrypt and found PBKDF2 inferior to bcrypt. You seem to want to pretend otherwise.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: