When you call deriveKey multiple times every time a new hashed password should be generated in the current implementation this is not the case. The problem is the use of the sjcl library is wrong and the salt is empty every time, creating the same hash every time.
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira