LastPass breach: The significance of these password iterations
1–10 of 17 posts
Re: LastPass breach: The significance of these password iterations
#2Re: LastPass breach: The significance of these password iterations
#3Re: LastPass breach: The significance of these password iterations
#4I don't suppose it being a non-obvious value makes it any more secure? Is an attacker brute forcing the thing likely to try obvious default values first and then give up if they don't work? Or will they simply +1 the iteration count until they hit paydirt?
Re: LastPass breach: The significance of these password iterations
#5As I feared, I changed the iterations myself at some point, and they never "migrated" it to the new value. So it's above the old default, but well below the recommended number of iterations. I don't suppose it being a non-obvious value makes it any more secure? Is an attacker brute forcing the thing likely to try obvious default values first and then give up if they don't work? Or will they simply +1 the iteration co…
Re: LastPass breach: The significance of these password iterations
#6Re: LastPass breach: The significance of these password iterations
#7Re: LastPass breach: The significance of these password iterations
#8>GeForce RTX 4090 graphics card could test more than 88,000 guesses per second!
Guessing we're missing a zero there?
Re: LastPass breach: The significance of these password iterations
#9The writer of the article needs to retract.
https://support.lastpass.com/help/about-password-iterations-...
Re: LastPass breach: The significance of these password iterations
#10As I feared, I changed the iterations myself at some point, and they never "migrated" it to the new value. So it's above the old default, but well below the recommended number of iterations. I don't suppose it being a non-obvious value makes it any more secure? Is an attacker brute forcing the thing likely to try obvious default values first and then give up if they don't work? Or will they simply +1 the iteration co…
No, the iteration count is no secret. It’s even exposed via a public API, anyone can query it if they know the email address.