Hacker News new | ask | show | jobs
by tptacek 3199 days ago
While there is some weird design in Login.gov, this particular report is mostly generating giggles among crypto engineers I know.
1 comments

You mean to say that the outdated requirements of FIPS-140-2 aren't the best practices for designing a crypto system? That the lack of TMTO attack resistance in PBKDF2 makes it a sub-optimal choice for storing passwords? Surely not! NIST would never recommend anything but the strongest cryptography!