Tuesday, 2024-10-29

JayFhttps://review.opendev.org/c/openstack/keystone-specs/+/915482 security-interested folks might wanna take a gander at this15:49
fungilooking it over, it seems reasonably well thought-out16:22
fungiusing a kdf and severely truncating the result should be safe enough for logging purposes anyway16:23
JayFoh, the use case just clicked16:41
JayFdifferentiating between "I changed a password and have my old one in 1000 places" and "someone is trying to brute force"16:42
fungiyeah, "someone is trying lots of different passwords for the same account" in which case the truncated hash would vary wildly16:44

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!