Wed Jul 17 18:09:18 EDT 2013

For authentication of what/whom, with what credentials, to what
target(s)?  Ah, users with passwords to some node with a password

On Wed, Jul 17, 2013 at 4:54 PM, Krisztián Pintér <pinterkr at gmail.com> wrote:
Well, so in general we want PBKDFs to be slow and require lots of RAM
as a defense against off-line password attacks on stolen password
verifiers.  Once you have a session key you should want to use a KDF,
not a PBKDF, because you need the KDF to be fast.


