3 ms·
There was an article on HN earlier this week about PBKDF2 iterations[1]. The gist of the article was that adding iterations to the key derivation function doesn
by jxcl 4y ago
There was an article on HN earlier this week about PBKDF2 iterations[1]. The gist of the article was that adding iterations to the key derivation function doesn't actually increase the entropy of a password all that much. No matter how much education and encouragement they're given, some users will choose weak passwords, and those passwords will be crackable even with any reasonable number of DF iterations.
This was good support for 1PW's 2-key solution, since one of the keys is randomly generated with a true 128 bits of entropy, no matter what password the user chooses, a compromise of the service's data store alone will mean the user's vault encryption key is uncrackable.
[1]: https://neilmadden.blog/2023/01/09/on-pbkdf2-iterations/ https://neilmadden.blog/2023/01/09/on-pbkdf2-iterations/
Disclaimer: I'm an employee of 1Password.
- hn_throwaway_99 4y ago> The gist of the article was that adding iterations to the key derivation function doesn't actually increase the entropy of a password all that much. I know your linked article talks about it a bit like this, but I think it's wrong to think about PBKDF2 as "increasing the entropy" of a password. The number of PBKDF2 rounds just increases the cost of each guess an attacker makes, but doesn't fundamentally change the number of guesses an attacker needs to make. To me it's basically the constant multiplier term with respect to Big-O notation - that is, while some process make take 1000N time or 10N, it's all still just O(n). So, that said, I 100% agree that 1Password's approach of using a truly random 128 bit string as part of the key is fundamentally an uncrackable approach while LastPass's was not.