<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>23501</bug_id>
          
          <creation_ts>2013-10-14 19:54:22 +0000</creation_ts>
          <short_desc>PBKDF2 Parameter Warning?</short_desc>
          <delta_ts>2014-09-26 15:03:58 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Web Cryptography</product>
          <component>Web Cryptography API Document</component>
          <version>unspecified</version>
          <rep_platform>PC</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>DUPLICATE</resolution>
          <dup_id>25607</dup_id>
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Harry Halpin">hhalpin</reporter>
          <assigned_to name="Ryan Sleevi">sleevi</assigned_to>
          <cc>ttaubert</cc>
    
    <cc>watsonm</cc>
          
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>94691</commentid>
    <comment_count>0</comment_count>
    <who name="Harry Halpin">hhalpin</who>
    <bug_when>2013-10-14 19:54:22 +0000</bug_when>
    <thetext>(6) For PBKDF2, should some guidance be given as to how to choose the
    number of iterations? If developers set it too high it may be too slow
    on slow user agents. If they set it too low to accommodate all user
    agents it will hurt security.

    (Dan Boneh)

    ---
    Problem with precise numbers recognized, currently between 20,000-&gt;200,000

    http://lists.w3.org/Archives/Public/public-webcrypto/2013Sep/0055.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>111939</commentid>
    <comment_count>1</comment_count>
    <who name="Mark Watson">watsonm</who>
    <bug_when>2014-09-22 17:36:37 +0000</bug_when>
    <thetext>This seems to be covered by the more general considerations in 25607. Resolve dup ?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>112250</commentid>
    <comment_count>2</comment_count>
    <who name="Mark Watson">watsonm</who>
    <bug_when>2014-09-26 15:03:37 +0000</bug_when>
    <thetext>I&apos;m marking this as a dup of 25607, since it should be addressed there. It&apos;s more of a subset than I dup, but we don&apos;t have a specific way of saying that in Bugzilla (that I&apos;m aware of).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>112251</commentid>
    <comment_count>3</comment_count>
    <who name="Mark Watson">watsonm</who>
    <bug_when>2014-09-26 15:03:58 +0000</bug_when>
    <thetext>

*** This bug has been marked as a duplicate of bug 25607 ***</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>