nlinecomputers
Well-Known Member
- Reaction score
- 8,565
- Location
- Midland TX
Bitwarden design flaw: Server side iterations
Bitwarden is a hot candidate for a LastPass replacement. Looking into how they encrypt data, it doesn’t do things that much better however.
palant.info
TL : DR Bitwarden like Lastpass has NOT updated all clients to its stated default of 100,001 iterations nor have they changed it to the new default (only a few days ago) of 350,000 iterations. OWASP has bumped up its recommended default of 600,000. The server side additional 100,000 iterations are only for the transmitted password hash NOT the vault! Bitwarden has hinted that it will drop PBKDF2 in favor of the much better Argon2 protocol but no timeline for that has been announced.