Why do we need a KDF for a cache key? Won't a normal cryptographic hash function (or its HMAC variant) suffice?
At least that's my immediate thought, could be wrong.
key = anyhash(uuid+username)
if (result := cache.get(uuid+username)):
if hash_and_equality(password, result.password_hash):
return result.the_other_stuff
# try login or else failOf course, if you have any validness of old sessions / passwords around a password change, you are doing something wrong.
My personal wondering is, considering KDF is meant to be expensive, why is IO more expensive to the point it needs a cache?
> why is IO more expensive to the point it needs a cache
The advisory mentions it's only exploitable if the upstream auth server is unresponsive. So it seems to be mainly for resilience.