3 ms·
This is pretty wild. When you rotate your master password and it re-encrypts everything, that's a perfect opportunity to use a new iteration count. If they didn
by brianshaler 4y ago
This is pretty wild. When you rotate your master password and it re-encrypts everything, that's a perfect opportunity to use a new iteration count. If they didn't want change the value for user's who were at an old default value, they at least could have nagged "your account is using an old/low value for an encryption setting, click here to use the latest recommended default"
Of course, changing it now won't do any good with regard to previous leaks.
- insanitybit 4y agoThey could have changed the setting any time the user logged in. I pointed out that they used too few rounds over a decade ago, I believe. To their credit, they increased the limit to 256K in response (it was much lower before).