Re: internals Digest 3 Feb 2017 23:56:52 -0000 Issue 4435
| From: | Tom Worster | Date: | Sat, 04 Feb 2017 16:20:47 +0000 |
| Subject: | Re: internals Digest 3 Feb 2017 23:56:52 -0000 Issue 4435 | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-98185@lists.php.net to get a copy of this message | ||
On 3 Feb 2017, at 18:56, internals-digest-help@lists.php.net wrote:
HKDF w/o salt is OK, but with salt, it's much stronger than w/o it.That's not correct. The salt defends against certain attacks on predictable input key material, i.e. weak passwords. But HKDF should not normally be used for passwords because it is unsuitable. There is something like a weird pattern to your attempts to help PHP programmers use the wrong function for the job -- HKDF for passwords, uniqid and mt_rand for unpredictable randoms. Tom