Rekeying or just password change?
MSBsDkiUHF MSBsDkiUHF <[email protected]> Thu, 10 Dec 2009 13:20:32 +0100
| Newsgroups | gmane.comp.security.passwordsafe.user |
|---|---|
| Message-ID | <[email protected]> |
Hi, Let's say that - at some point of time a password repository is stolen and = the master password is either known or cracked.- to combat this, master pas= sword is changed Will the master password change the internal keying, e.g. future versions o= f the same repository aren't decrypted? I can think of a few ways this could be implemented, MASTER_KEY =3D hash(MASTER_PASSWORD).In this implementation, master key wil= l change if MASTER_PASSWORD change. MASTER_KEY =3D noise xor hash(MASTER_PASSWORD).In this implementation maste= r key could remain same upon password change (i.e. could be vulnerable) So, ... how is it? is rekeying implemented to combat "old version stolen an= d cracked" scenarios? = _________________________________________________________________ Hitta hetaste singlarna p=E5 MSN Dejting! http://dejting.se.msn.com/channel/index.aspx?trackingid=3D1002952 ---------------------------------------------------------------------------= --- Return on Information: Google Enterprise Search pays you back Get the facts. http://p.sf.net/sfu/google-dev2dev