Ask HN: Best way to derive an AES256 key from a password/passphrase?
My current approach to generate the aes key is to ask for a password/passphrase, bcrypt it, then do a SHA256 on the bcrypt hash to generate the key, and store the bcrypt salt. The purpose of the SHA256 is because the bcrypt hash wouldn't be 256 bits.
Are there any weaknesses in this scenario? If so, can anyone suggest a better approach?
Please be polite.