drive-web
drive-web copied to clipboard
[PB-2666]: Feat/add argon2 and kyber
Update
- Switching to Argon2. The idea is to re-compute all hashes in the database to Argon2 of the current PBKDF2 value and modify the login accordingly, then bit by bit change all users to just Argon2.
- Add a post-quantum layer. The idea is always to send two encrypted values - 'secret' and 'secret XORed with the mnemonic'. The 'secret' is encrypted with KyberKEM (post-quantum) and 'secret XORed with mnemonic' with ECC from openpgp. This way, to get a mnemonic one must break both ECC and Kyber.
Related to PB-2666
The latest updates on your projects. Learn more about Vercel for Git ↗︎
| Name | Status | Preview | Comments | Updated (UTC) |
|---|---|---|---|---|
| drive-web | ✅ Ready (Inspect) | Visit Preview | 💬 Add feedback | Nov 27, 2024 9:24am |
@TamaraFinogina Please provide a description
Hey @xabg2 @CandelR, We should review each line more carefully than a typical Pull Request as this could be a breaking change in the way we are modifying the involved cryptography for every customer
Let's aim to increase the testing coverage to 80% @TamaraFinogina
