> Unless the article means that the key itself is a derivation (a hash?) of the password
Why is this an issue? Other people call this 'issue' PKCS5.
Why is this an issue? Other people call this 'issue' PKCS5.
That's why I suggested that a more appropriate application would be to derive a key from the password (using a PBKDF, which PKCS5 is (PBKDF2)) and use that one to encrypt the file encryption key.
This way, you can always change the password (provided you still have it) and encrypt the encryption key again, while not needing to encrypt each file.