Saw this comment. And wanted to know your opinion.
I'll do this when I get back onto my laptop!No in the Bitwarden web vault itself.
Password Manager Web App | Bitwarden Help Center
Learn how to get started with the Bitwarden password manager web app, including creating your first login, generating a strong password, and creating an organization.bitwarden.com
View attachment 272359 View attachment 272360
I think Bitwarden should do this as a default for all users on their backend, regardless of it's open source, they need to act on flaws such as this quickly to prevent a LastPass-type breach from occurring, as nothing is 100% secure.You are probably a longtime user of Bitwarden.
The best thing that Bitwarden can do is change the iterations for all users to the their new default of 350,000.
Be sure to do one thing at the time (iterations and/or password change) you will be logged out after the change and have to login again.I'll do this when I get back onto my laptop!
~LDogg
Absolutely!Be sure to do one thing at the time (iterations and/or password change) you will be logged out after the change and have to login again.
no matter what you tell people they will not change, they are determined to use browser extension password managers despite all the weaknessesJeremi M Gosney :verified: (@epixoip@infosec.exchange)
@WPalant @dchest@mastodon.social @bitwarden@fosstodon.org I don't typically beat up password managers for PBKDF2, nor for iteration count. I don't like PBKDF2 but it's the only NIST and FIPS approved KDF outside of Balloon, and unlike Balloon it's widely supported. And while I've never given...infosec.exchange
I checked mine. It was on 50,000 as well.I see that mine is set to 50,000.
So that means when I created my account, the default was 50,000
View attachment 272361
I can't quite make out if this is being implemented for existing customers or new ones joining their service. Any updates on this from other avenues, noticed the question was asked in the reply but no answer from the devs.Default iterations are planned to change to 600,000
Bitwarden (@bitwarden@fosstodon.org)
In addition to having a strong master password, default client iterations are being increased to 600,000 as well as double-encrypting these fields at rest with keys managed in Bitwarden’s key vault (in addition to existing encryption). The team is continuing to explore approaches for existing...fosstodon.org
The answer was: “It will apply to new accounts as it rolls out, the team is exploring the process for existing accounts.”I can't quite make out if this is being implemented for existing customers or new ones joining their service. Any updates on this from other avenues, noticed the question was asked in the reply but no answer from the devs.
I can't quite make out if this is being implemented for existing customers or new ones joining their service. Any updates on this from other avenues, noticed the question was asked in the reply but no answer from the devs.
~LDogg
Nothing concrete yet.The team is continuing to explore approaches for existing accounts.
Okee dokey, keep me updated bro.Nothing concrete yet.
Gotcha, thanks.The answer was: “It will apply to new accounts as it rolls out, the team is exploring the process for existing accounts.”
From an evidence-based point of view yes, just enable 2 Factor Authentication too. You have to think that everything is not 100% secure. To credit BW, they are open source, their code is examined by IT professionals to disclose any vulnerabilities and security weaknesses. So as BW gets more popular the risk of people seeking to attack BW will increase. BW are normally good at closing any holes in their security.Is it safe to just stay with Bitwarden or should i switch to Dashlane/1Password?
BTW i set my KDF Iteration from 100.000 to 700.000, but is that enough at all?