RFC 2898 defines PBKDF2 as a password-based key-derivation function built around a pseudorandom function, with HMAC-SHA-1 specified as its default. PBKDF2 derives keys from a password, salt, iteration count, and requested output length; the salt and sufficiently high iteration count remain essential protections against precomputation and password-guessing attacks.
PBKDF2-HMAC can produce equivalent derived keys for distinct password inputs because HMAC normalizes keys longer than its hash block size by hashing them first. For an overlong password, using its HMAC hash digest as a shorter password can yield the same PBKDF2 result when the same salt, iteration count, PRF, and output length are used. Implementations should recognize this as an HMAC key-normalization property rather than a break in PBKDF2, avoid relying on raw password uniqueness for security decisions, and use modern password-hashing schemes and robust password-handling controls where possible.

See affected versions and whether adversaries are exploiting it.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.