Re: Re: hash_hkdf() signature and return value

From: Date: Fri, 08 Sep 2017 09:38:40 +0000
Subject: Re: Re: hash_hkdf() signature and return value
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-100465@lists.php.net to get a copy of this message
> > I finally find out what's wrong. > No, you didn't. You still want to use user-supplied passwords as IKM. HKDF is not suited for that purpose. > RFC 5689 - https://tools.ietf.org/html/rfc5869#section-3.3 > -------- > In some applications, the input key material IKM may already be > present as a cryptographically strong key. In this case, one can skip the > extract part and use IKM directly to key HMAC in the expand step. > --------- > > Therefore, you are debating "IKM should be strong always" and > "salt is pure optional parameter". > Yes, HKDF might be used for lower-entropy IKM, but not for short inputs like passwords. The extract part requires a large low-entropy input to concentrate the entropy into a smaller output. HKDF doesn't add / amplify entropy, but it can concentrate a larger low-entropy input to a smaller output with entropy. Further reading material: https://eprint.iacr.org/2010/264.pdf Regards, Niklas

« previous php.internals (#100465) next »