Security notes / Key Derivation Functions
| Security related stuff.
Securing services
Unsorted - · Anonymization notes · website security notes · integrated security hardware · Glossary · unsorted |
pbkdf2
Password-Based Key Derivation Function 2 (1 is similar but could only generate up to 160-bit things)
Conceptually:
- taskes a value (probably a password)
- applies a given pseudorandom function,
- a given amount of times
The function is now often based on SHA-256 or SHA-512, others exist.
The amount of repeats is basically however many times it takes for the combination to take a while - maybe half a second.
Around the year 2000, 1000 iterations may have been enough,
As ASICs and GPUs have been optimized for this KDF, around the year 2025 you might want a few hundred thousand.
(bcrypt, scrypt, and argon2, all newer, were designed to be harder to optimize)