
PBKDF2
Computer programWikipedia
12
MENTIONS
8
EPISODES
7
PODCASTS
Search complete. 12 mentions across 8 episodes found for "PBKDF2".
Oct 9, 2026
Ep. 85 - FortiBleed: The Campaign With No CVE That Locks You Out of Your Own Firewall
A
16:14Adrian CulleyHOST
Look for accounts you don't recognize and check the password hash setting.
A
16:19Adrian CulleyHOST
PBKDF2 for admin credentials and Fortinet says upgrade to 7.4, 7.6 or 8.0. Then review the REST API keys, which the advisory flags specifically.
A
16:32Adrian CulleyHOST
Fortinet's guidance includes a setting login lockout upon weaker encryption.
A
16:37Adrian CulleyHOST
to remove the old legacy password settings, so it's worth reading that thread properly.
FortiBleed is still locking admins out of their own firewalls, and the NCSC saw it coming
S
3:10speaker_0HOST
Investigate other edge devices sharing the same credentials and keep management interfaces off the internet.
S
3:16speaker_0HOST
Enforce multi-factor authentication on every VPN and management login and enable PBKDF2 for administrator accounts.
S
3:26speaker_0HOST
And finally, the secure by design lesson.
S
3:30speaker_0HOST
Two design decisions did the damage.
S
3:54speaker_0HOST
Applying it should cost little more than an afternoon per device.
S
3:58speaker_0HOST
Restrict administration to an allow list.
S
4:00speaker_0HOST
Switch on PBKDF2.
S
4:02speaker_0HOST
Rotate every administrator password.
The Silent Killer of Active Directory Removal
J
9:21JoséeHOST
Exactly.
J
9:22JoséeHOST
It hashes it again using a secure algorithm called PBKDF2.
E
9:26Ernie PrescottHOST
PBKDF2, okay.
J
9:27JoséeHOST
Yeah, specifically utilizing HMAC-SHA256.
J
9:32JoséeHOST
And here's the kicker.
7 MINS LATER
J
16:21JoséeHOST
Yes.
J
16:22JoséeHOST
To an auditor enforcing that rule, a salted double hashed representation is still a representation of a password residing on a server they do not physically control.
E
16:32Ernie PrescottHOST
They just don't care about the thousands of PBKDF2 iterations.
"Security in Java" [AtA]
N
31:56Nicolai ParlogHOST
attack.
S
31:58Sean MullanGUEST
And it's better than the one we support now, which is called PBKDF2.
S
32:04Sean MullanGUEST
That is not a memory-hard algorithm.
S
32:06Sean MullanGUEST
So we're bringing in this new one.
AI Will Save Us, or Not? - PSW #945
L
20:21Lee NeelyPANELIST
key artifact or something they were deriving from the configuration in the Fortinet OS.
L
20:28Lee NeelyPANELIST
And the fix was to implement the new, what is it, the PKDF something? PBKDF2? Did I say that right? What Paul said.
L
20:35Lee NeelyPANELIST
Yeah.
L
20:37Lee NeelyPANELIST
Yeah.
"Security in Java" [AtA]
N
31:56Nicolai ParlogHOST
attack.
S
31:58Sean MullanGUEST
And it's better than the one we support now, which is called PBKDF2.
S
32:04Sean MullanGUEST
That is not a memory-hard algorithm.
S
32:06Sean MullanGUEST
So we're bringing in this new one.
AI Will Save Us, or Not? - PSW #945
L
20:21Lee NeelyPANELIST
key artifact or something they were deriving from the configuration in the Fortinet OS.
L
20:28Lee NeelyPANELIST
And the fix was to implement the new, what is it, the PKDF something? PBKDF2? Did I say that right? What Paul said.
L
20:35Lee NeelyPANELIST
Yeah.
L
20:37Lee NeelyPANELIST
Yeah.
How to Govern 40 Isolated OT Tenants Centrally
E
25:43Ernie PrescottHOST
Never.
E
25:44Ernie PrescottHOST
The local agent intercepts the hash, applies unique salt, and runs it through 1,000 iterations of the PBKDF2 key derivation function.
J
25:53JoséeHOST
1,000 iterations.
J
25:54JoséeHOST
That's heavy.
J
25:54JoséeHOST
Very
E
25:55Ernie PrescottHOST
heavy.
E
25:55Ernie PrescottHOST
The computational expense of 1,000 PBKDF2 iterations provides massive cryptographic resistance against brute force attacks, even if the TLS tunnel were somehow compromised.
J
26:05JoséeHOST
So the plaintext password never leaves the on-premises network.