5 ms·
Oof, my Bitwarden account was created a while ago and was set to only 5,000 iterations. You can see and change the number of iterations here: https://vault.bitw
by ywain 4y ago
Oof, my Bitwarden account was created a while ago and was set to only 5,000 iterations. You can see and change the number of iterations here: https://vault.bitwarden.com/#/settings/security/security-keys https://vault.bitwarden.com/#/settings/security/security-key... (or if you don't trust links for something like your password manager: log into your web vault, click on the top-right dropdown menu, then Account settings > Security > Keys).
I've updated it to 600,000 iterations and so far don't see any noticeable impact on performance, both on desktop (using the Firefox extension) and on mobile (iOS).
- ajorgensen 4y agooof me too thanks for the nudge to check!
- mkasberg 4y agoI had bumped mine up once before (to 200K) and I just bumped it up again to 600K. But my wife (registered several years ago, like me) was still at 5K, I just bumped hers up too. Wish Bitwarden would force this for anyone still on an old default - particularly given the LastPass compromise we just saw.
- philliphaydon 4y agoThank you! Mine was also set to 5000, updated to 600k.
- rstuart4133 4y agoA way to think about the difference you just made is, you increased the difficulty of cracking your password by 600000 / 5000 = 120. Making your attacker guess 7 extra bits (well, slightly under) would have the same effect, so that translates to a slightly under 7 bits of entropy. Appending two randomly chosen digits to your password would have about the same effect. Those first 5000 iterations added over 12 bits of entropy. The article is complaining about not adding an extra 100,000 iterations which would double the difficulty, so he's effectively berating them over 1 bit of entropy.
- zeven7 4y agoAs of now, your link is fine (though the comment is probably still editable), and I believe you have the best of intetions but Note: It's not a great idea to click a link to something like Bitwarden, since a phishing domain could be used.
- ywain 4y agoFair enough, I added navigation instructions.
- sircastor 4y agoI upped mine to more than 1M and haven’t seen any degradation of performance.
- vena 4y agodid you fully log out/in or just lock/unlock? iirc locking with BW doesn’t do what one might expect wrt encryption state.
- ywain 4y agoChanging the number of iterations should automatically log you out on all devices. At least it did for me.
- vena 4y agooh good, didn’t know if it would do that/force a cache invalidation for clients
- sircastor 4y agoIt forced me out of all my logged in instances. I had to login to everything. With my master password and my 2nd factor.
- orra 4y agoThat's important to realise, in case your (normal) second factor is a different Bitwarden device!
- sircastor 4y agoI didn't even think about this. My 2nd factor is through a different app, but if I'd been using BitWarden's TOTP I wonder if I would've been stuck. A good reminder to also have printed (or something) OTPs accessible in a safe place in case you need them.
- runnerup 4y ago
- realitysballs 4y agoCan someone Eli5 iterations in this context?
- ywain 4y agoIterations refer to the number of times the password goes through the hash function. The higher the number, the longer it takes, so you want it low enough that it doesn't impact your day-to-day use but high enough that it will hinder an attacker in case the hashed password is leaked.
- eyelidlessness 4y agoMaybe overly pedantic to expand on this, but since we’re in an ELI5 context: the attack vector is brute forcing hash collisions. Making it computationally slow for attackers is a hindrance because the relative value of a collision diminishes over time (depending on the value of their target).
- rcxdude 4y agoIt's not really hash collisions: SHA256 is still too secure for that, you're unlikely to find a value which isn't the password used to generate it. It's just brute forcing the password
- sircastor 4y agoYour master password is put in a box that’s very hard to break into. But because someone might be really determined to get in, we put that box in another box that’s just as hard to break into. And because someone might be really really determined, we keep putting those boxes in new boxes so it’s really really difficult to get to the password. But sometimes we also need to get to the password, so we use enough boxes that it’s difficult for them, but not so many that it’s annoying for us. That might be a little too much “like I’m 5”, but that’s the general idea. Hashing is easy one way but it still requires compute cycles to do each iteration. We don’t want to make it excessively expensive for us.
- aidenn0 4y agoI updated my master password in 2022, but my account was still set to 5000 iterations. Not increasing it on master key changes seems beyond careless.
- devwastaken 4y agoI checked a two year old account and it's at 100k, might have been changed though.
- bjoli 4y ago600.000 was a bit too much for my 3 year old low-end android phone. 400k workes OK. when I sorted everything into folders I could bump it up to 600k probably due to time saved rendering.
- jve 4y agoSome warning to users: Changing iterations MAY corrupt your data: > Making changes in a session with a “stale” encryption key will cause data corruption that will make your data unrecoverable. https://community.bitwarden.com/t/increasing-kdf-interations/48059/8 https://community.bitwarden.com/t/increasing-kdf-interations... https://news.ycombinator.com/item?id=34152181 https://news.ycombinator.com/item?id=34152181 EDIT: Look below, this actually applies to changing master password.
- kadoban 4y ago> Some warning to users: Changing iterations MAY corrupt your data This is incorrect. https://bitwarden.com/help/what-encryption-is-used/#changing-kdf-iterations https://bitwarden.com/help/what-encryption-is-used/#changing... > When you change the iteration count, you'll be logged out of all clients. Though the risk involved in rotating your encryption key does not exist when changing KDF iteration count, we still recommend exporting your vault beforehand.
- EspadaV9 4y agoThat is when you change your master password, or rotate your encryption keys, not changing the number of iterations (as far as I can tell). From what I read, changing the number of iterations is safe to do.
- adament 4y agoI am not a cryptographer but to my understanding, the number of PBKDF iterations is really only of concern for weak (low-entropy) passwords. If you know that your password has high entropy (>128 bit), for example because you generated it randomly uniformly from at least 2^128 possible outcomes[1], you are safe even if you used only 1 iteration. PBKDF is all about password strengthening, so if you are making changes for yourself the most effective change is just to use a secure password and stop worrying about key derivation functions. [1] 28 characters in a single case, 23 characters if both upper and lower case are used, 22 characters if you include numbers, 12 words if you use a word list of 2000 words and sample uniformly
- e12e 4y ago> If you know that your password has high entropy (>128 bit) I don't think that is practical for most users - 12 words (or 10 taken from a 10k list) - or 22 random alphanumeric characters - is hard to remember - and long enough that they are difficult to type correctly. 70 bits might be a more sensible goal - but still long. (6/7 words, 12 characters from a set of 62). This is the "trust anchor", so something the user needs to remember and type in - from what I've seen - remembering/representing and inputting 128 random bits is tricky. And with modest stretching and a salt, probably overkill anyway.
- adament 4y agoI think your point is valid and important, especially considering the average user. However in my experience it worked surprisingly well with a long word based master password. Since I only needed to remember 1 password that I then used daily it was not that difficult. And typing it was quick since it was all lowercase which most keyboards are optimized for. However the issue came when I started using my password vault on my phone and tablet. I was way too slow at typing on them. I now have a 22 character password which takes the same time for me to type on a keyboard, maybe a bit slower, but is faster on my phone though still annoyingly slow. As for 70 bits password, it might be enough, but you need a lot of iterations (2^58) if you want to completely make up for the lost security margin. Which will also be unusably slow in practice.
- j1elo 4y agoWhy are you upping it up that much? I guess "too much is not a bad thing" in this case, and Bitwarden itself says: "We recommend a value of 100,000 or more.". When I see that I read: "With our knowledge of security and encryption, which by the way is much greater than yours, we consider that 100,000 is a perfectly safe number and a good middle point so go ahead and use it". Am I wrong to think like that? My Master password is a battery-horse-staple thing, but not with 12 words as some other commenter says; that's absurdly long and would be too difficult for me to remember. I usually strive for around 18-20 characters, that's already in the verge of me forgetting it. I use incorrect or derived words of my own (so not really existing in dictionaries).
- pricechild 4y agoOWASP seem to recommend that number. e.g. https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html https://cheatsheetseries.owasp.org/cheatsheets/Password_Stor...
- ThreePinkApples 4y agoThe current (and very recently updated) OWASP recommendation[1] is a minimum of 600 000 iterations [1] https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pbkdf2 https://cheatsheetseries.owasp.org/cheatsheets/Password_Stor...
- Daunk 4y agoI read that as a "total of 600 000" iterations, so 300 000 locally and 300 000 on the server. Am I wrong?
- ajb 4y agoAccording to the OP article, the server side iterations are ineffective for adding security in bitwarden, so you need 600,000 on the client. This would not be the case if the design was correct. (I'm not a security expert, so I'm going by the article)
- deleted 4y ago
- Kuinox 4y agoI've set it up to 2 millions when I created my account. My OnePlus2 freeze for 10 seconds when logging in ^^'.
- fencepost 4y agoIMPORTANT NOTE When you do this reset and sign back into your devices/browser plugins, you will need to go into the Bitwarden Settings on each one and set a few options again - notably timeout (defaults back to Browser Restart, change back to a time you're comfortable with), Biometric Unlock and PIN. All of those are local settings to each Bitwarden client/endpoint, so you need to do them on each device.