Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If they said SHA-256 with salt, excuse us to think it is just that, with no iteration. If it's iterated SHA-256 it becomes a lot closer to PBKDF and one wonder why they would not use it.

Given Adobe history wrt security, let us assume the worst.



That is the standard in the password libraries really. passlib uses thousands of rounds of sha-256, so does glibc, etc.

Unless they implemented the whole thing from scratch, they wouldn't be using a single run of sha-256. It's not impossible, but I'd say at this point it's unlikely they're doing something silly - it would be a job terminating mistake for whoever implemented the new system after the last fiasco.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: