TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

LastPass breach: The significance of these password iterations

47 pointsby hjuutilainenover 2 years ago

6 comments

AdmiralAsshatover 2 years ago
As I feared, I changed the iterations myself at some point, and they never &quot;migrated&quot; it to the new value. So it&#x27;s above the old default, but well below the recommended number of iterations.<p>I don&#x27;t suppose it being a non-obvious value makes it any more secure? Is an attacker brute forcing the thing likely to try obvious default values first and then give up if they don&#x27;t work? Or will they simply +1 the iteration count until they hit paydirt?
评论 #34170567 未加载
评论 #34167749 未加载
postpawlover 2 years ago
For anyone else having trouble finding the “show advanced settings” button: It’s at the bottom of the account settings pop up where ok&#x2F;cancel buttons usually are.
foreverCarlosover 2 years ago
Interesting. This is starting to look like gross negligence that might bite LogMeIn really hard.
stubishover 2 years ago
Can attackers can easily tell the 1 and 500 iteration databases and focus their resources in breaching those ones?
评论 #34170603 未加载
Havocover 2 years ago
&gt;GTX 1080 Ti graphics card (cost factor: less than $1000) can be used to test 346,000 guesses per second.<p>&gt;GeForce RTX 4090 graphics card could test more than 88,000 guesses per second!<p>Guessing we&#x27;re missing a zero there?
评论 #34170583 未加载
smoothgrammerover 2 years ago
The article is missing key data. The password iterations that are set low are client side. The server side is different.<p>The writer of the article needs to retract.<p><a href="https:&#x2F;&#x2F;support.lastpass.com&#x2F;help&#x2F;about-password-iterations-lp030027" rel="nofollow">https:&#x2F;&#x2F;support.lastpass.com&#x2F;help&#x2F;about-password-iterations-...</a>
评论 #34170595 未加载