bookmark

mjg59 | PSA: upgrade your LUKS key derivation function


Description

You want to be using argon2id. A KDF is a function that takes some input (in this case the user's password) and generates a key. Good KDFs reduce this risk by being what's technically referred to as "expensive". Rather than performing one simple calculation to turn a password into a key, they perform a lot of calculations. However, there's another axis of expense that can be considered - memory. If the KDF algorithm requires a significant amount of RAM, the degree to which it can be performed in parallel on a GPU is massively reduced.

Preview

Tags

Users

  • @jil

Comments and Reviews