[Cryptography] Recommendations for short AES passphrases

Kent Borg kentborg at borg.org
Sun Sep 18 14:04:48 EDT 2016


On 09/17/2016 08:01 AM, ıuoʎ wrote:
> If I assumed a medium adversary can try a Million keys a second

I finally saw Citizenfour, and the voiceover at the beginning said to 
assume that a they can try a trillion keys a second. That would be the 
US government, ~3-years ago, in a case where they are really pissed. 
Other cases would be slower.

Looking at hashcat speeds 
(https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a270c40) on an 
8-GPU system (pretty affordable for many values of "medium"), is a lot 
slower, but dang impressive. The comments say the PBKDF2 numbers are all 
1,000-rounds, I don't know which matches your proposal.

-kb



More information about the cryptography mailing list