Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think those schemes are pretty silly, but as long as you're using a well-tested implementation of a real KDF and not some goofy scheme you hacked up yourself so you could add the second secret nonce, I don't care.


Alright, it's true that it feels silly to add negligible protections when your security here is reduced to the KDF and its implementation.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: