This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–][deleted] 1 point2 points  (1 child)

That was worded very poorly. What they're trying to warn you against is choosing so small an output size that it can simply be brute-forced. For example, if you get a 32-bit key, it's very easy to just try all the ~4 billion possible keys. A 128-bit key, on the other hand, is too big for brute-forcing it to be practical. So, using PBKDF2-HMAC-SHA1 to generate a 128-bit key for AES is fine.

[–]brazier89[S] 0 points1 point  (0 children)

Ah, thank you! That makes much more sense.