3 ms·
Keepass' security measures, described here: http://keepass.info/help/base/security.html http://keepass.info/help/base/security.html A question: does anyone ha
by disconnected 9y ago
Keepass' security measures, described here:
http://keepass.info/help/base/security.html http://keepass.info/help/base/security.html
A question: does anyone have any idea why is it so much slower to crack Rar5 and Office 2016 than these password databases? What sort of magic sauce are they using to reduce the amount of guesses/second?
- 21 9y agoNo magic, just a bigger number of hash iterations. I have setup my KeePass to use around 100 mil iterations. It takes 1 second to validate the password on the CPU, on a GPU it will be maybe 100-1000 tries per second.
- annabellish 9y agoThe idea you can put a number on how many guesses/second you can make on a keepass database at least is silly - that number is _configurable_! There's even a button in the UI which tunes that value to an estimated amount of time on the user's current hardware, so it's hardly an esoteric option. MS word, by comparison, does not offer this option, and so they simply default to something sanely high.
- disconnected 9y ago> The idea you can put a number on how many guesses/second you can make on a keepass database at least is silly - that number is _configurable_! I understand this. I was asking because the article says "[lastpass and 1password] are still nearly an order of magnitude less secure than, say, Microsoft Office 2016 documents, but even this level of security is much better than nothing.". That, to me, implied that Office (and Rar5) were using some different - and much better! - algorithm that made guesses more expensive. If indeed it is just a matter of more hashing rounds, then that sentence and the graph are very misleading and borderline FUD.