Security notes / Key Derivation Functions

From Helpful
Jump to navigation Jump to search

Security related stuff.


Linux - PAM notes · SELinux

Securing services


A little more practical


More techincal waffling

Hashing notes · Message signing notes · Key Derivation Functions
Auth - Kinds of auth setup · identity and auth notes ·· OAuth notes · OpenID notes Kerberos notes · · SASL notes
Encryption - Encryption notes · public key encryption notes · data-at-rest encryption · encrypted connections
pre-boot authentication

Unsorted - · Anonymization notes · website security notes · integrated security hardware · Glossary · unsorted


pbkdf2

This article/section is a stub — some half-sorted notes, not necessarily checked, not necessarily correct. Feel free to ignore, or tell me about it.

Password-Based Key Derivation Function 2 (1 is similar but could only generate up to 160-bit things)

Conceptually:

taskes a value (probably a password)
applies a given pseudorandom function,
probably a HMAC so that it involves salt,
a given amount of times


The function is now often based on SHA-256 or SHA-512, others exist.

The amount of repeats is basically however many times it takes for the combination to take a while - maybe half a second.

Around the year 2000, 1000 iterations may have been enough,

As ASICs and GPUs have been optimized for this KDF, around the year 2025 you might want a few hundred thousand.

(bcrypt, scrypt, and argon2, all newer, were designed to be harder to optimize)


https://en.wikipedia.org/wiki/PBKDF2