Salted scrypt is probably OK for this sort of thing, though I guess using javascript puts it at a speed disadvantage over optimised implementations. It's good enough, at least, that Peerio can honestly tell whoever enquires that they don't have any way to obtain somebodies key.
_______________________________________________ Messaging mailing list [email protected] https://moderncrypto.org/mailman/listinfo/messaging
