browser-passworder icon indicating copy to clipboard operation
browser-passworder copied to clipboard

Store key derivation function used and iteration count in payload

Open federicobond opened this issue 8 years ago • 3 comments

The KDF used and iteration count should be included in the payload returned from encrypt to facilitate upgrades over time. This makes it possible to change the work factor or the algorithm used without breaking backward compatibility.

Library users should be encouraged to upgrade encrypted ciphertexts from time to time to take advantage of this too.

federicobond avatar Jun 29 '17 14:06 federicobond

I agree, and plan to do this eventually, maybe using pojo-migrator to allow users of the old format to experience no breaking changes.

In the meanwhile, I wouldn't object to a PR that does this, especially if it had a non-breaking migration process from the old format.

danfinlay avatar Jun 29 '17 16:06 danfinlay

We can always assume the current values if there aren't any defined, to preserve backwards compatibility.

federicobond avatar Jun 29 '17 16:06 federicobond

Exactly.

danfinlay avatar Jun 29 '17 16:06 danfinlay