#pbkdf2
February 5, 2026 at 1:35 AM
Oh bordel... ta derivation key qui derive pas trop...
Marrez-vous, mais 'déjà vu cela dans une autre implémentation sur du matériel crypto où la passphrase "secrète" était >24 octets et qu'en desassemblant le code, tu vois que le code n'utilise que le [0]. Allez, zou, une rainbow-table facile.
April 8, 2026 at 11:09 AM
March 13, 2024 at 2:51 AM
i keep hearing disingenuous morons breathlessly repeating the lie that tcrf stores passwords in plain text.

so, just because i can: here's my password, straight from the database. looks pretty plain text to me; see, there's letters and stuff.

(this is, in fact, mediawiki's standard pw encryption.)
June 11, 2025 at 5:35 PM
Yes, all live in one local SQLite file. The app supports export/import: a JSON dump, optionally AES-256-GCM encrypted (PBKDF2-HMAC-SHA256, 600k iterations). So you can easily share it between your devices via OneDrive, Google Drive, or whatever you choose.
September 26, 2026 at 5:24 PM
Bravo @jtdowney.com for adding password hashing algorithms Erlang's crypto module!

So many NIFs can be removed from so many web applications when this is released, hype!

github.com/erlang/otp/p...
crypto: add crypto:kdf/4 by jtdowney · Pull Request #11301 · erlang/otp
Add a crypto:kdf/4 NIF backed by OpenSSL's EVP_KDF, supporting argon2, hkdf, scrypt, sskdf, and pbkdf2 with option maps. This was something I had proposed on Erlang Forums and also discovered i...
github.com
August 18, 2026 at 11:52 AM
New blog post:
In which I explore the impact of SQL Server 2025’s PBKDF2 hashing algorithm on password cracking and compare it with SQL Server 2022.
#sqlserver #sqldba #microsoftsqlserver #mssqlserver #mssql #mssqldba #sql #security #pbkdf2
Looking into SQL Server 2025's new PBKDF2 hashing algorithm
In this post I explore the impact of SQL Server 2025's PBKDF2 hashing algorithm on password cracking and compare it with SQL Server 2022.
vladdba.com
June 23, 2025 at 5:29 PM
extremely niche peeve: people calling it pbkdf2-sha256 instead of pbkdf2-hmac-sha256. pbkdf2 is parameterised by an arbitrary pseudo random function, it is not specified to only use hmac
May 23, 2025 at 11:27 PM
Benditos clientes. Recuerdo uno que almacenaba las contraseñas de usuarios en md5. Le propuse un sistema para migrar a pbkdf2 y nunca se hizo.
March 21, 2025 at 10:10 AM
📦 erikwang2013/encryption v1.3.1

A pluggable cryptography component library: under a unified contract it provides symmetric encryption, asymmetric encryption, hashing, and key derivation (HKDF / PBKDF2), with implementations inclu...

🔗 https://github.com/erikwang2013/encryption
September 25, 2026 at 4:00 PM
📦 erikwang2013/encryption v1.3.0

A pluggable cryptography component library: under a unified contract it provides symmetric encryption, asymmetric encryption, hashing, and key derivation (HKDF / PBKDF2), with implementations inclu...

🔗 https://github.com/erikwang2013/encryption
September 25, 2026 at 4:00 PM
AES/TwoFish, RSA, SHA2/SHA3, HMAC, PBKDF2...
Xojo’s Crypto module covers the essentials. Start with the docs + examples.
#Xojo #Security https://documentation.xojo.com/api/cryptography/crypto.html
September 19, 2025 at 2:13 PM
encrypted json dump over a drive folder is a clean middle path. what forced aes-gcm + 600k pbkdf2 instead of just trusting the cloud folder and calling it done — a sober-streak privacy case, or you just don't want markd depending on anyone's backend?
September 27, 2026 at 12:37 PM
New blog post:
In which I demo a pure T-SQL implementation of SQL Server 2025's new PBKDF2 hashing algorithm

#sqlserver #sqldba #microsoftsqlserver #mssqlserver #mssql #mssqldba #sql #security
Replicating SQL Server 2025's PBKDF2 hashing algorithm using T-SQL
In this post I talk some more about SQL Server 2025's new PBKDF2 and demo a method to replicate it using T-SQL
vladdba.com
November 3, 2025 at 4:37 PM
Може комусь треба: github.com/roalyr/Passw...

Бо я користуюсь github.com/SecUSo/priva..., а він все-таки вимагає ОС Андроїд.
Скрипт все робить так само, але нічого не зберігає і трохи простіший функціонал.

Якщо запустити без введення даних - буде пароль як на скріншоті.
GitHub - roalyr/PasswordGeneraor: A secure, deterministic, and flexible password generator written in Python. It uses PBKDF2 for key stretching, supports customizable password options (e.g., length, s...
A secure, deterministic, and flexible password generator written in Python. It uses PBKDF2 for key stretching, supports customizable password options (e.g., length, special characters, uppercase, n...
github.com
December 22, 2024 at 4:27 AM
New breach: Canadian Tire had 38M unique email addresses breached in October. Data also included name, phone, physical address, PBKDF2 password and partial credit card data. 86% were already in @haveibeenpwned.com . Read more: haveibeenpwned.com/Breach/Canad...
Have I Been Pwned: Canadian Tire Data Breach
In October 2025, retailer Canadian Tire was the victim of a data breach that exposed almost 42M records. The data contained 38M unique email addresses along with names, phone numbers and physical addr...
haveibeenpwned.com
February 25, 2026 at 6:57 AM
How does end-to-end encryption actually work in Nextcloud? 🔐 Our whitepaper breaks it down for you:

• Client-side encryption
• Key management across devices
• Secure sharing
• Proven crypto (AES, RSA, PBKDF2)
And more!

Discover the full guide:
End-to-end encryption - Nextcloud
Learn how Nextcloud secures data with end-to-end encryption. Explore architecture, security principles, and implementation in this detailed whitepaper.
nextcloud.com
June 3, 2026 at 5:25 PM
Quick Linux Tip #83

Q: How do I create an encrypted compressed backup in Linux?

Try: `tar -czf - /home/linuxteck/documents | openssl enc -aes-256-cbc -pbkdf2 -out backup.tar.gz.enc`

Info: tar -czf - streams archive to stdout for openssl to encrypt in-memory

Follow @linuxteck.bsky.social
September 27, 2026 at 11:40 PM
How does end-to-end encryption actually work? 🔐 Our new whitepaper breaks down Nextcloud #E2EE:

• Client-side encryption
• Key management across devices
• Secure sharing
• Proven crypto (AES, RSA, PBKDF2)
And more!

Discover the full guide:
End-to-end encryption - Nextcloud
Learn how Nextcloud secures data with end-to-end encryption. Explore architecture, security principles, and implementation in this detailed whitepaper.
nextcloud.com
April 24, 2026 at 7:25 AM
New breach: Fanlore suffered a breach earlier this month exposing 145k unique email addresses. Data also included usernames and passwords stored as either MD5 or PBKDF2 hashes. 23% were already in @haveibeenpwned.com. Read more: haveibeenpwned.com/Breach/Fanlore
Have I Been Pwned: Fanlore Data Breach
In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along...
haveibeenpwned.com
August 19, 2026 at 2:14 AM
Cracking Gitea's PBKDF2 Password Hashes
www.unix-ninja.com
February 18, 2025 at 12:53 PM
We got our first responsible disclosure report yesterday!

On 32bit builds, it was possible to bypass the client-side PBKDF2 iteration count check by overflowing the parameter.

We patched the issue and shipped an update within a few hours.

Thank you to the researcher for reporting responsibly!
August 14, 2026 at 9:18 AM
🚨 FortiGate admins:
Stop and check 2 things TODAY:

1️⃣ Unexpected admin logins, config exports & config changes
2️⃣ Are ALL admin accounts using PBKDF2—not legacy SHA-256 hashes?

That second one is a much bigger deal than most #FortiBleed coverage suggests.

Details 👇
www.linkedin.com/feed/update/...
#fortigate #fortibleed #firewalls #cybersecurity #sha256 #pbkdf2 #cryptography #securityuncorked | Jennifer Jabbusch
FORTIGAGTE ADMINS, PLEASE CHECK THESE 2 THINGS If you're responsible for FortiGate firewalls, I'd recommend taking 10 minutes today to check these two things. After digging through the FortiBleed r...
www.linkedin.com
June 29, 2026 at 6:20 PM
by "hashed" i meant pbkdf2 lol
July 9, 2024 at 8:51 PM
Wine 10.6 brings a new lexer for the Command Processor, PBKDF2 in Bcrypt, enhanced image metadata support, and fixes for 27 bugs.
linuxiac.com/wine-10-6-ne...

#linux #opensource
Wine 10.6: New Lexer, Bcrypt Enhancements, and 27 Bug Fixes
Wine 10.6 brings a new lexer for the Command Processor, PBKDF2 in Bcrypt, enhanced image metadata support, and fixes for 27 bugs.
linuxiac.com
April 21, 2025 at 12:18 PM