3 ms·
I suspect the vast majority of Authy backups use passwords trivially susceptible to brute-force attacks despite only 1000 (!!!) iterations of PBKDF2. If Authy w
by dvzk 3y ago
I suspect the vast majority of Authy backups use passwords trivially susceptible to brute-force attacks despite only 1000 (!!!) iterations of PBKDF2. If Authy wanted to do things right, it would generate local encryption keys instead of asking normies for file encryption passphrases.
- yencabulator 3y agoargon2/scrypt with significantly larger costs sound like the right fix. Asymmetric crypto can make backing up still cheap, who cares if restoring takes 30 seconds.
- dvzk 3y agoThat would be a great improvement for technical users. But also consider that the target for Authy is the average mobile user. I’m not unconvinced that the typical backup password looks like S3cr3tP@s$w0rd, which no amount of key stretching will fix.