Hacker News new | ask | show | jobs
by sdevlin 4038 days ago
There's no a priori need for password-derived key material in a library like this. To require it unilaterally is to introduce a security risk, since people have proven to be poor sources of entropy.

I don't really understand the self-driving car analogy. A better analogy would probably be three cars hitched together.