Saturday, 9 March 2019

Is it necessary to use key derivation when using Node's 'crypto' module?

I need to implement symmetric encryption using a user's passphrase in a NodeJS application. When using crypto.createCipheriv(), do I need to perform some sort of key derivation on the passphrase to obtain a value for the key parameter, or is it sufficient to just pass the user's passphrase as-is and this is taken care of by the implementation?



from Is it necessary to use key derivation when using Node's 'crypto' module?

No comments:

Post a Comment