Skip to content

Comment on “YOLO” is not a valid hash constructionparent

Comments

I have a really hard time taking the attack research on password KDFs all that seriously. I don't think there are many common threat models where "weaknesses" in password hashes are more than marginal issues.

Not using a real password KDF is a big issue. Using the wrong one, not so much.

I don't disagree at all. My comment is about paperwork and selling to the government ("operating in the FIPS world", as the post has it, where NIST enters the conversation). I'm sure you can get away with tacking PBKDF2 onto Argon2 here, but those are hoops you don't need to jump through.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.