Skip to main content
PBKDF2

PBKDF2

Computer programWikipedia

Search complete. 12 mentions across 8 episodes found for "PBKDF2".

Oct 9, 2026

Adrian CulleyHOST
16:14
Look for accounts you don't recognize and check the password hash setting.
Adrian CulleyHOST
16:19
PBKDF2 for admin credentials and Fortinet says upgrade to 7.4, 7.6 or 8.0. Then review the REST API keys, which the advisory flags specifically.
Adrian CulleyHOST
16:32
Fortinet's guidance includes a setting login lockout upon weaker encryption.
Adrian CulleyHOST
16:37
to remove the old legacy password settings, so it's worth reading that thread properly.
speaker_0HOST
3:10
Investigate other edge devices sharing the same credentials and keep management interfaces off the internet.
speaker_0HOST
3:16
Enforce multi-factor authentication on every VPN and management login and enable PBKDF2 for administrator accounts.
speaker_0HOST
3:26
And finally, the secure by design lesson.
speaker_0HOST
3:30
Two design decisions did the damage.
speaker_0HOST
3:54
Applying it should cost little more than an afternoon per device.
speaker_0HOST
3:58
Restrict administration to an allow list.
speaker_0HOST
4:00
Switch on PBKDF2.
speaker_0HOST
4:02
Rotate every administrator password.
JoséeHOST
9:21
Exactly.
JoséeHOST
9:22
It hashes it again using a secure algorithm called PBKDF2.
Ernie PrescottHOST
9:26
PBKDF2, okay.
JoséeHOST
9:27
Yeah, specifically utilizing HMAC-SHA256.
JoséeHOST
9:32
And here's the kicker.

7 MINS LATER

JoséeHOST
16:21
Yes.
JoséeHOST
16:22
To an auditor enforcing that rule, a salted double hashed representation is still a representation of a password residing on a server they do not physically control.
Ernie PrescottHOST
16:32
They just don't care about the thousands of PBKDF2 iterations.
Nicolai ParlogHOST
31:56
attack.
Sean MullanGUEST
31:58
And it's better than the one we support now, which is called PBKDF2.
Sean MullanGUEST
32:04
That is not a memory-hard algorithm.
Sean MullanGUEST
32:06
So we're bringing in this new one.
Lee NeelyPANELIST
20:21
key artifact or something they were deriving from the configuration in the Fortinet OS.
Lee NeelyPANELIST
20:28
And the fix was to implement the new, what is it, the PKDF something? PBKDF2? Did I say that right? What Paul said.
Lee NeelyPANELIST
20:35
Yeah.
Lee NeelyPANELIST
20:37
Yeah.
Nicolai ParlogHOST
31:56
attack.
Sean MullanGUEST
31:58
And it's better than the one we support now, which is called PBKDF2.
Sean MullanGUEST
32:04
That is not a memory-hard algorithm.
Sean MullanGUEST
32:06
So we're bringing in this new one.
Lee NeelyPANELIST
20:21
key artifact or something they were deriving from the configuration in the Fortinet OS.
Lee NeelyPANELIST
20:28
And the fix was to implement the new, what is it, the PKDF something? PBKDF2? Did I say that right? What Paul said.
Lee NeelyPANELIST
20:35
Yeah.
Lee NeelyPANELIST
20:37
Yeah.
Ernie PrescottHOST
25:43
Never.
Ernie PrescottHOST
25:44
The local agent intercepts the hash, applies unique salt, and runs it through 1,000 iterations of the PBKDF2 key derivation function.
JoséeHOST
25:53
1,000 iterations.
JoséeHOST
25:54
That's heavy.
JoséeHOST
25:54
Very
Ernie PrescottHOST
25:55
heavy.
Ernie PrescottHOST
25:55
The computational expense of 1,000 PBKDF2 iterations provides massive cryptographic resistance against brute force attacks, even if the TLS tunnel were somehow compromised.
JoséeHOST
26:05
So the plaintext password never leaves the on-premises network.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.