Rekeying or just password change?

MSBsDkiUHF MSBsDkiUHF <[email protected]> Thu, 10 Dec 2009 13:20:32 +0100
Newsgroups gmane.comp.security.passwordsafe.user
Message-ID <[email protected]>

Hi,
Let's say that - at some point of time a password repository is stolen and =
the master password is either known or cracked.- to combat this, master pas=
sword is changed

Will the master password change the internal keying, e.g. future versions o=
f the same repository aren't decrypted?

I can think of a few ways this could be implemented,
MASTER_KEY =3D hash(MASTER_PASSWORD).In this implementation, master key wil=
l change if MASTER_PASSWORD change.

MASTER_KEY =3D noise xor hash(MASTER_PASSWORD).In this implementation maste=
r key could remain same upon password change (i.e. could be vulnerable)

So, ... how is it? is rekeying implemented to combat "old version stolen an=
d cracked" scenarios?
 		 	   		  =

_________________________________________________________________
Hitta hetaste singlarna p=E5 MSN Dejting!
http://dejting.se.msn.com/channel/index.aspx?trackingid=3D1002952
---------------------------------------------------------------------------=
---
Return on Information:
Google Enterprise Search pays you back
Get the facts.
http://p.sf.net/sfu/google-dev2dev