Should have used the WebCrypto API instead of the crypto-js npm package.
https://developer.mozilla.org/en-US/docs/Web/API/Web_Crypto_...
Also sorry for the long link. Is there any accepted way to post a shorted URL?
Edit: added a corrected version [2]
[1]: https://www.typescriptlang.org/play?#code/DYUwLgBAbiDGYHsBOE...
[2]: https://www.typescriptlang.org/play?#code/FAiGGcE8DsGMAIBmBX...
Would "salting" the key safely tackle the problem?
Put explicitly;
send <- nonce || salt || ciphertext
recv -> decrypt(ciphertext, nonce, pbkdf(pass) || salt)
[edit: apply salt outside of the kdf]Here I thought GCM was some modern foolproof/footgunless design.
1: https://csrc.nist.gov/csrc/media/Projects/crypto-publication...
Web Crypto is faster and has many more devs working in the different implementations between all the companies and doesn't require any includes.
Just levels of trust. I'd happily use the former if the latter didn't exist.