Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 7 Dec 2017 18:52:31 -0600
From: Jeffrey Goldberg <>
 Jim Fenton <>
Subject: Re: Real world password policies

On Dec 7, 2017, at 4:54 PM, Jim Fenton <> wrote:
> On 11/8/17 2:32 PM, Jim Fenton wrote:

>> The recommendation to do an additional keyed hash with a key stored
>> separately is completely new in 800-63.

> To close the loop on this, I have published a simple utility for doing
> this. The code is at

Thanks. That is nice and to the point.

Is there any particularly reason you choose PBKDF2 instead of HMAC? There’s
nothing really wrong with using PBKDF2 here, but it is really just a round about
way of using HMAC. Furthermore HMAC is in the standard library.



Download attachment "smime.p7s" of type "application/pkcs7-signature" (3367 bytes)

Powered by blists - more mailing lists

Your e-mail address:

Powered by Openwall GNU/*/Linux - Powered by OpenVZ