Hacker News new | ask | show | jobs
by blueskin_ 4278 days ago
Very interesting. I've always been wary of PBKDF2 for these applications simply because most people will have a 4 digit PIN (although I don't), which is essentially useless against an offline brute force attack, and possibly worse than useless if it gives people a false sense of security.

At least CM11 allows a dedicated FDE password though - Google is really doing its users a disservice by not implementing this in stock Android.