DEV Community

Discussion on: Q Vault: An open source secret manager

 
tarialfaro profile image
Tari R. Alfaro

Okay. It makes sense. Why do you want AES-256 in GCM mode? And why Scrypt?

Thread Thread
 
wagslane profile image
Lane Wagner

From a high level GCM is considered more secure than CBC. Especially at lower resolutions. Good link: crypto.stackexchange.com/questions...

I like scrypt for our use case because we are simply trying to make it hard to brute force access. Scrypt requires high powered computation AND memory in order to continue guessing keys.