3 ms·
Yes, `cryptsetup luksFormat` selects the LUKS1 key slot pbkdf iteration count parameter at runtime by benchmarking against a target `--iter-time` [1] [2], which
by terom 3y ago
Yes, `cryptsetup luksFormat` selects the LUKS1 key slot pbkdf iteration count parameter at runtime by benchmarking against a target `--iter-time` [1] [2], which is either 1s or 2s depending on version [3].
For a LUKS1 image created with Ubuntu 18.04 on a i5-8265U (Q3'18) CPU, that seems to result in an iteration count on the order of 1.8M. Assuming the RTX 4090 hashcat benchmarks [4] scale linearly on the iteration count, that's about 10kH/s for PBKDF2-HMAC-SHA1 or 5kH/s for PBKDF2-HMAC-SHA256.
In terms of brute-force vs password entropy, that would give you roughly 45 bits of entropy for 1k gpu-months, or ~250k gpu-years to net 56 bits of entropy. Those would be on the order of [a-z0-9]{8} (41 bits), [a-zA-Z0-9]{8} (47 bits) or [a-z]{12} (56 bits).
Worryingly close enough to make replacing the KDF a relevant concern, but still enough to make this story about brute-forcing a random 20-character password somewhat implausible, unless the password was far weaker than implied.
[1] https://man7.org/linux/man-pages/man8/cryptsetup-luksformat.8.html https://man7.org/linux/man-pages/man8/cryptsetup-luksformat....
[2] https://wiki.archlinux.org/title/dm-crypt/Device_encryption#Iteration_time https://wiki.archlinux.org/title/dm-crypt/Device_encryption#...
[3] https://mirrors.edge.kernel.org/pub/linux/utils/cryptsetup/v1.7/v1.7.0-ReleaseNotes https://mirrors.edge.kernel.org/pub/linux/utils/cryptsetup/v...
[4] https://gist.github.com/Chick3nman/32e662a5bb63bc4f51b847bb422222fd#file-rtx_4090_v6-2-6-benchmark-L1238 https://gist.github.com/Chick3nman/32e662a5bb63bc4f51b847bb4...