Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"making the unhinged argument that a poor KDF is a feature because it encourages users to select better passwords."

Where does it say that? It says a better kdf would improve the security of shorter passwords. I don't see anything that suggests a poor kdf is a feature.

The kdf used for "gpg -c" also seems better than "openssh enc". And we've still not heard what the reasonable alternative is for symmetric/password file encryption is. So, I'm sticking with gpg for that use case.



I think you're right, and that I misread the comment. I fixed my vote. Thanks! See! The system works!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: