Variable Key Stretching for v3
"Frank Pilhofer" <[email protected]>
| Newsgroups | gmane.comp.security.passwordsafe.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi,
the v3 database format uses key stretching to make brute force attacks
against the password harder. The current proposal stretches the key
using 2048 iterations of SHA-256.
The other day, I was reading Linux Weekly News article on OpenBSD's
crypt_blowfish module, see http://lwn.net/Articles/170248/
The major point of the article is,
"[I]n order to have a future-proof password hashing algorithm,
one must be able to dial up the computational cost of that
algorithm over time. If the cost can be provided as a parameter
- and stored with the hashed password - then password hashing
can be made more expensive [...] while maintaining compatibility
with currently-hashed passwords."
So I was wondering if we wanted to apply the same idea to Password
Safe.
We could easily add the number of iterations for the key stretching
algorithm to the file header, instead of using the constant 2048.
Even if that value is not exposed to the user, future versions of
Password Safe could crank up the iterations in a both forward and
backward compatible manner.
Frank
--
Frank Pilhofer, [email protected]
-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems? Stop! Download the new AJAX search engine that makes
searching your log files as easy as surfing the web. DOWNLOAD SPLUNK!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642