Back in April, there was an attack on 1Password that managed to exploit some flaws in its crypto scheme to achieve a sizable speedup. [1] To this day, they have not managed to rollout the new 1Password 4 Cloud Keychain that is supposed to fix these flaws. [2] Lots of smooth talk, but apparently security is not a blocker. 1: http://hashcat.net/forum/thread-2238.html 2: http://discussions.agilebits.com/discussion/14780…
The PBKDF2 speedup that hashcat achieved really was just 1 bit. This is because the other optimization is used by 1Password as well as by hashcat.
The particular flaw in PBKDF2 that hashcat was able to so brilliantly exploit not only gave it the 2x advantage, but also was connected to a clever AES speed up. (Only decrypting the last CBC block, with the penultimate block as the IV.
I presented a talk about this at PasswordsCon, the slides (PDF) discussing all of this.
Slides (PDF) : http://tooagile.wpengine.netdna-cdn.com/wp-content/uploads/2...
Video: http://youtu.be/oqFwQIOucwo
The 1Password 4 Cloud Keychain Format has been available in 1Password for iOS since December 2012, and it has been working well in the 1Password 4 Beta for Mac. But rolling it out everywhere will take time. Transitioning between formats in a world where data is synchronized between systems takes time. It will continue to take time.