Hacker News new | past | comments | ask | show | jobs | submit login

Using the passphrase as both the salt and password for the PBKDF2 step strikes me as suspicious, but as I don't do crypto for my day job I'm not sure how bad this is (or isn't).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: