6 ms·
I also wonder if a weak link could pose a threat. Say, Attacker knows User is a member of Site X, but Site X fails to implement checks and/or rate limits prope
by kosinus 9y ago
I also wonder if a weak link could pose a threat.
Say, Attacker knows User is a member of Site X, but Site X fails to implement checks and/or rate limits properly. Attacker brute forces master password by spamming the login endpoints.
Extrapolating: a database leak of any site means the attacked can locally brute force master passwords of all users?
Currently, such a leak means a subset of users who reuse passwords are in trouble. Widespread deployment of this kind of scheme would take away choice, and put everyone in trouble. (Unless you start using different master passwords to create bubbles, which means we're back to square one.)
- zwily 9y agoI don't know if brute forcing is that much of a thread. Your password is taken through a key derivation function that takes about 20s to generate the real master key. (From what I understand).
- ezfe 9y agoI just checked and on my laptop the app download takes about 5 seconds (timed manually) to process a new master password account.
- homakov 9y agoThere is no need for rate limiting against pubkey crypto, and bruteforce is simply too expensive for current derivation.