Hacker News new | ask | show | jobs
by mpyne 4480 days ago
Using the passphrase as both the salt and password for the PBKDF2 step strikes me as suspicious, but as I don't do crypto for my day job I'm not sure how bad this is (or isn't).