[{"data":1,"prerenderedAt":318},["ShallowReactive",2],{"navigation_docs":3,"-algorithms-evp-bytestokey":156,"-algorithms-evp-bytestokey-surround":315},[4,40],{"title":5,"path":6,"stem":7,"children":8,"icon":39},"Guide","\u002Fguide","1.guide\u002F01.index",[9,11,15,19,23,27,31,35],{"title":10,"path":6,"stem":7},"Getting Started",{"title":12,"path":13,"stem":14},"Hashing","\u002Fguide\u002Fhashing","1.guide\u002F02.hashing",{"title":16,"path":17,"stem":18},"HMAC and verify","\u002Fguide\u002Fverify","1.guide\u002F03.verify",{"title":20,"path":21,"stem":22},"Salted KDFs","\u002Fguide\u002Fkdf","1.guide\u002F04.kdf",{"title":24,"path":25,"stem":26},"CLI","\u002Fguide\u002Fcli","1.guide\u002F05.cli",{"title":28,"path":29,"stem":30},"Agents","\u002Fguide\u002Fagents","1.guide\u002F06.agents",{"title":32,"path":33,"stem":34},"Custom algorithms","\u002Fguide\u002Fcustom","1.guide\u002F07.custom",{"title":36,"path":37,"stem":38},"Playground","\u002Fguide\u002Fplayground","1.guide\u002F08.playground","i-lucide-book-open",{"title":41,"path":42,"stem":43,"children":44,"icon":155},"Algorithms","\u002Falgorithms","2.algorithms\u002F00.index",[45,47,51,55,59,63,67,71,75,79,83,87,91,95,99,103,107,111,115,119,123,127,131,135,139,143,147,151],{"title":46,"path":42,"stem":43},"Every algorithm",{"title":48,"path":49,"stem":50},"SHA-256","\u002Falgorithms\u002Fsha256","2.algorithms\u002F01.sha256",{"title":52,"path":53,"stem":54},"SHA-384","\u002Falgorithms\u002Fsha384","2.algorithms\u002F02.sha384",{"title":56,"path":57,"stem":58},"SHA-512","\u002Falgorithms\u002Fsha512","2.algorithms\u002F03.sha512",{"title":60,"path":61,"stem":62},"SHA-512Half","\u002Falgorithms\u002Fsha512-half","2.algorithms\u002F04.sha512-half",{"title":64,"path":65,"stem":66},"SHA3-256","\u002Falgorithms\u002Fsha3-256","2.algorithms\u002F05.sha3-256",{"title":68,"path":69,"stem":70},"SHA3-512","\u002Falgorithms\u002Fsha3-512","2.algorithms\u002F06.sha3-512",{"title":72,"path":73,"stem":74},"Keccak-256","\u002Falgorithms\u002Fkeccak256","2.algorithms\u002F07.keccak256",{"title":76,"path":77,"stem":78},"BLAKE2b","\u002Falgorithms\u002Fblake2b","2.algorithms\u002F08.blake2b",{"title":80,"path":81,"stem":82},"BLAKE2b-256","\u002Falgorithms\u002Fblake2b-256","2.algorithms\u002F09.blake2b-256",{"title":84,"path":85,"stem":86},"BLAKE2b-224","\u002Falgorithms\u002Fblake2b-224","2.algorithms\u002F10.blake2b-224",{"title":88,"path":89,"stem":90},"BLAKE2s","\u002Falgorithms\u002Fblake2s","2.algorithms\u002F11.blake2s",{"title":92,"path":93,"stem":94},"BLAKE3","\u002Falgorithms\u002Fblake3","2.algorithms\u002F12.blake3",{"title":96,"path":97,"stem":98},"BLAKE-256","\u002Falgorithms\u002Fblake256","2.algorithms\u002F13.blake256",{"title":100,"path":101,"stem":102},"RIPEMD-160","\u002Falgorithms\u002Fripemd160","2.algorithms\u002F14.ripemd160",{"title":104,"path":105,"stem":106},"HASH160","\u002Falgorithms\u002Fhash160","2.algorithms\u002F15.hash160",{"title":108,"path":109,"stem":110},"HASH256","\u002Falgorithms\u002Fhash256","2.algorithms\u002F16.hash256",{"title":112,"path":113,"stem":114},"MD5","\u002Falgorithms\u002Fmd5","2.algorithms\u002F17.md5",{"title":116,"path":117,"stem":118},"SHA-1","\u002Falgorithms\u002Fsha1","2.algorithms\u002F18.sha1",{"title":120,"path":121,"stem":122},"SHA-0","\u002Falgorithms\u002Fsha0","2.algorithms\u002F19.sha0",{"title":124,"path":125,"stem":126},"CRC-32","\u002Falgorithms\u002Fcrc32","2.algorithms\u002F20.crc32",{"title":128,"path":129,"stem":130},"CRC-16\u002FXMODEM","\u002Falgorithms\u002Fcrc16-xmodem","2.algorithms\u002F21.crc16-xmodem",{"title":132,"path":133,"stem":134},"xxHash (XXH64)","\u002Falgorithms\u002Fxxhash","2.algorithms\u002F22.xxhash",{"title":136,"path":137,"stem":138},"FNV-1a (64-bit)","\u002Falgorithms\u002Ffnv1a","2.algorithms\u002F23.fnv1a",{"title":140,"path":141,"stem":142},"scrypt","\u002Falgorithms\u002Fscrypt","2.algorithms\u002F24.scrypt",{"title":144,"path":145,"stem":146},"PBKDF2","\u002Falgorithms\u002Fpbkdf2","2.algorithms\u002F25.pbkdf2",{"title":148,"path":149,"stem":150},"HKDF","\u002Falgorithms\u002Fhkdf","2.algorithms\u002F26.hkdf",{"title":152,"path":153,"stem":154},"EVP_BytesToKey","\u002Falgorithms\u002Fevp-bytestokey","2.algorithms\u002F27.evp-bytestokey","i-lucide-library",{"id":157,"title":152,"body":158,"description":308,"extension":309,"links":310,"meta":311,"navigation":312,"path":153,"seo":313,"stem":154,"__hash__":314},"docs\u002F2.algorithms\u002F27.evp-bytestokey.md",{"type":159,"value":160,"toc":306},"minimark",[161,165,186,193,246,261,295,302],[162,163],"algorithm-facts",{"name":164},"evp-bytestokey",[166,167,168,169,173,174,177,178,181,182,185],"p",{},"Ever seen base64 that starts with ",[170,171,172],"code",{},"U2FsdGVkX1","? That's ",[170,175,176],{},"Salted__",", and somebody ran ",[170,179,180],{},"openssl enc"," or ",[170,183,184],{},"CryptoJS.AES.encrypt(message, passphrase)",". Both get the key and the IV from the passphrase with EVP_BytesToKey. CryptoJS calls it EvpKDF. Same recipe, two names.",[166,187,188,189,192],{},"And the recipe is short. Hash the password and the salt. Hash that block again with the password and the salt behind it. Repeat until the key and the IV fit. Set ",[170,190,191],{},"iterations"," and each block goes through the hash that many times before the next one starts.",[194,195,200],"pre",{"className":196,"code":197,"language":198,"meta":199,"style":199},"language-ts shiki shiki-themes hashes hashes hashes","create(\"evp-bytestokey\").hash(\"password\", { salt: \"0102030405060708\" }).digest;\n\u002F\u002F \"e7b0971e52ca5cc8d0539fb3412f6316f7ba2e6ee293d9f3457b99436b51ce028d450e2ed75a84a923d4eac9fe49226b\"\n","ts","",[170,201,202,239],{"__ignoreMap":199},[203,204,207,211,215,219,222,225,227,230,233,236],"span",{"class":205,"line":206},"line",1,[203,208,210],{"class":209},"sK71F","create",[203,212,214],{"class":213},"s38Sx","(",[203,216,218],{"class":217},"shU9J","\"evp-bytestokey\"",[203,220,221],{"class":213},").",[203,223,224],{"class":209},"hash",[203,226,214],{"class":213},[203,228,229],{"class":217},"\"password\"",[203,231,232],{"class":213},", { salt: ",[203,234,235],{"class":217},"\"0102030405060708\"",[203,237,238],{"class":213}," }).digest;\n",[203,240,242],{"class":205,"line":241},2,[203,243,245],{"class":244},"scIB-","\u002F\u002F \"e7b0971e52ca5cc8d0539fb3412f6316f7ba2e6ee293d9f3457b99436b51ce028d450e2ed75a84a923d4eac9fe49226b\"\n",[166,247,248,249,252,253,256,257,260],{},"That's ",[170,250,251],{},"openssl enc -aes-256-cbc -P -md md5 -pass pass:password -S 0102030405060708",", byte for byte. The first 32 bytes are the key and the last 16 the IV. Where's the split? ",[170,254,255],{},"keyLength"," and ",[170,258,259],{},"ivLength"," set it, and the result names both.",[166,262,263,266,267,270,271,273,274,277,278,281,282,284,285,288,289,291,292,294],{},[170,264,265],{},"digest"," is ",[170,268,269],{},"md5"," by default. CryptoJS uses it, and so did OpenSSL before 1.1.0. Newer ",[170,272,180],{}," takes ",[170,275,276],{},"sha256",", and ",[170,279,280],{},"sha1"," is there too. The salt is the 8 bytes after ",[170,283,176],{},", in hex. Leave it out and there's no salt, like ",[170,286,287],{},"-nosalt",". Not a random one, because the format keeps its salt next to the ciphertext anyway. CryptoJS lets a page ask for any key size, so ",[170,290,255],{}," goes way past 32. A cipher without an IV takes ",[170,293,259],{}," 0.",[166,296,297,298,301],{},"Encrypt something new with it? Please don't. One MD5 per block is nothing for a GPU. It's here to open what somebody already locked. Your own keys want ",[299,300,140],"a",{"href":141},".",[303,304,305],"style",{},"html pre.shiki code .sK71F, html code.shiki .sK71F{--shiki-light:var(--shiki-token-function);--shiki-default:var(--shiki-token-function);--shiki-dark:var(--shiki-token-function)}html pre.shiki code .s38Sx, html code.shiki .s38Sx{--shiki-light:var(--ui-text-highlighted);--shiki-default:var(--ui-text-highlighted);--shiki-dark:var(--ui-text-highlighted)}html pre.shiki code .shU9J, html code.shiki .shU9J{--shiki-light:var(--shiki-token-string);--shiki-default:var(--shiki-token-string);--shiki-dark:var(--shiki-token-string)}html pre.shiki code .scIB-, html code.shiki .scIB-{--shiki-light:var(--shiki-token-comment);--shiki-default:var(--shiki-token-comment);--shiki-dark:var(--shiki-token-comment)}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":199,"searchDepth":241,"depth":241,"links":307},[],"The key and IV behind openssl enc without -pbkdf2 and behind CryptoJS with a passphrase. Old and weak and still everywhere","md",null,{},true,{"title":152,"description":308},"bEmBUb679AGqVDcEkMaheG6638ZsqyLUXS8FZY9meVA",[316,310],{"title":148,"path":149,"stem":150,"description":317,"children":-1},"Extract then expand. One strong secret in and the separate keys a protocol needs out. No cost and no random salt",1790830342387]