Algorithms

PBKDF2

HMAC run a few hundred thousand times. The NIST password KDF with a salt and iterations and a choice of hash
IDpbkdf224 / 24password · variable
Hash / Password

PBKDF2

HMAC a few hundred thousand times.

Digest
keyLength you pick
HMAC
no key mode
Security
OWASP Password Storage Cheat Sheet: >=600000 iterations with HMAC-SHA256
Family
2 in password
5 options, 0 required

Sample

hex
883f5fb301ff684a2e92fdfc1754241bb2dd3eb6af53e5bd7e6c9eb2df7ccb7783f40872b5d3dd5c2915a519f008a92c4c2093e8a589e59962cf1e33c8706ca9
base64
iD9fswH/aEoukv38F1QkG7LdPravU+W9fmyest98y3eD9AhytdPdXCkVpRnwCKksTCCT6KWJ5Zlizx4zyHBsqQ==

Options

encodingstring
default hex
Output encoding: hex, base64, base64url, binary
saltstring
optional
Salt in hex; 32 random bytes when omitted
iterationsnumber
default 600000
Iteration count (OWASP: >=600000 with sha256, >=220000 with sha512)
digeststring
default sha512
Underlying hash: sha256, sha384, sha512, sha3-256, sha3-512
keyLengthnumber
default 64
Output key length in bytes

Access

Createcreate("pbkdf2")
CLIhashes pbkdf2 'hello world' --salt 73616c74 --iterations 1000
Tryplayground with the sample above
Kinscrypt

PBKDF2 runs HMAC over the password and salt, then again over the result, iterations times, and XORs the rounds together. It's slow by counting, not by memory, so GPUs love it more than scrypt. Still everywhere: WPA2, BIP39 seeds (2048 rounds of HMAC-SHA512), most password stores from before 2015.

ts
create("pbkdf2").hash("password", {
  salt: "73616c74",
  iterations: 4096,
  digest: "sha256",
  keyLength: 32,
}).digest;
// "c5e478d59288c841aa530db6845c4c8d962893a001ce4e11a4963873aa98134a"

73616c74 is salt in hex. digest picks the HMAC underneath: sha256, sha384, sha512 (the default), sha3-256 or sha3-512. The default 600000 iterations is OWASP's number for HMAC-SHA256. With SHA-512 OWASP asks for 220000, so the default errs slow, which is the right way to err. The page above uses 1000 for its sample, so it renders in a blink instead of a second.