Is it secure to derive multiple keys from one password?
c#, encryption, hash, security
Solution
For easy reference, I'm compiling the advice I was given into one answer.
Iteration Count
Although this wasn't part of my question erickson pointed out that 5,000 iterations for Rfc2898DeriveBytes (a PBKDF2 method for C#) is far too few and recommended at least 50,000.
After looking elsewhere for more information, it seems that between 50,000 and 1,000,000 is a good number of iterations, but keep in mind there is an inverse relation between speed and security here: As the number of iterations increases so does security, and the amount of time it takes to derive the key (which is why it's more secure).
Solutions
Although according to erickson the first key could not be used to determine the second, it does make a brute-force attack easier. Therefore, any of the following solutions could be used to address the issue:
- Generate a double-length key, and use the first half of the derived key for authentication, and the second half for encryption. (erickson)
- Use a separate salt for each key.
- Appending a unique but hard coded salt (like "website" and "encryption" respectively) to each before deriving the key. A unique salt should be used in addition.(Damien_the_Unbeliever)
Rejected Solutions
- SHA_512 is too fast to be secure for my purposes (and for most purposes in which hashes are used). Using multiple iterations can help, but it is far more secure to use a PBKDF2 method such as Rfc2898DeriveBytes.
Conclusion
Thank you everyone for your help, if you have any further insight please comment and I'll do my best to add it.
Problem
Problem My application (which I will be writing in C#) uses a key derivation method (Rfc2898DeriveBytes, 4000 iterations) along with a salt to generate a "hash" of a password. This hash is then sent to a database so that the user can use that password in the future to authenticate to their account. So far that should be secure, but after that, I want to use Rfc2898DeriveBytes on the same password to generate a key which can then be used for encryption. Now the way I was going to do that was to use 5000 iterations of the same method to get a different key, but I am concerned that if the hash stored in the database was compromised (or I was forced to reveal it) it would be possible to derive the second key somehow. Is that possible? Potential Solutions - Ideally I would like to use the same salt, but would using a different one fix the problem? - What about using SHA for the database hash and Rfc for the encryption key? - Appending a unique but hard coded string (like "website" and "encryption" respectively) to each before deriving the key. (Damien_the_Unbeliever) - Generate a double-length key, and use the first half of the derived key for authentication, and the second half for encryption. (erickson) I would appreciate any advice on how best to improve this process. I would post code but I haven't written it yet.