Security stuff like this is exactly what you shouldn't be having this type of "genuine dialog" about unless you are an expert. Thats not a slight against antirez-I sure as hell am not a security expert either. The point is, this is an area where people shouldn't be trying to get clever. Even in this same thread, jgc has pointed out that PBKDF1 is deprecated, and that it's not designed to be slow (and thus not a good candidate for a password hashing function). Is he right? Maybe. I don't know. Do you? Does antirez?
Yes, the folks commenting on that pull request were being dicks, but that doesn't mean this is the appropriate response.
This is a well reasoned response, but I want to point out that there is nothing wrong with acknowledging that one is a non-expert and wanting to engage in discussion regardless.
Some participants in this thread and in the conversations with antirez seem to think that all developers who are not experts should always blindly obey the cryptography best practices handed down from on high without ever being interested in the details or questioning the whys or wherefores of those practices.
Comments
Security stuff like this is exactly what you shouldn't be having this type of "genuine dialog" about unless you are an expert. Thats not a slight against antirez-I sure as hell am not a security expert either. The point is, this is an area where people shouldn't be trying to get clever. Even in this same thread, jgc has pointed out that PBKDF1 is deprecated, and that it's not designed to be slow (and thus not a good candidate for a password hashing function). Is he right? Maybe. I don't know. Do you? Does antirez? Yes, the folks commenting on that pull request were being dicks, but that doesn't mean this is the appropriate response.
This is a well reasoned response, but I want to point out that there is nothing wrong with acknowledging that one is a non-expert and wanting to engage in discussion regardless.
Some participants in this thread and in the conversations with antirez seem to think that all developers who are not experts should always blindly obey the cryptography best practices handed down from on high without ever being interested in the details or questioning the whys or wherefores of those practices.