Right what I'm confused about is that first bit, my understanding from the RFC is that the implementation should have look something like
return pbkdf2.derive(password, email, PBKDF2_ROUNDS, STRETCHED_PASS_LENGTH_BYTES)
.then((quickStretchedPW) => {
result.quickStretchedPW = quickStretchedPW;
// stretch to twice the length necessary
return hkdf(quickStretchedPW, kw('generated'), HKDF_SALT, HKDF_LENGTH * 2)
.then((generated) => {
// split output into two cryptographically strong keys
result.unwrapBkey = generated.slice(0, HKDF_LENGTH);
result.authPW = generated.slice(HKDF_LENGTH);
}
);
}
)
but my read in pseudo code of what they end up doing is closer to this:
hashed_password = hash(password, 'salt1')
hashed_auth_tok = hash(hashed_password, 'salt2')
hashed_unwrap_key = hash(hashed_password, 'salt3')
which seems secure because the server can't reverse hashed_unwrap_key to find hashed_password and thus shouldn't be able to calculate hashed_auth_tok. However the point of HKDF is to make multiple cryptographic keys while it looks like in practice we are just using it as a one way funciton.