Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I believe that my vault was similarly-low iteration, however my master password was an approximately 30 character string that contained no dictionary words.

Based on your understanding, does my master password length sufficiently mitigate the low-iterations, or is decryption a realistic possibility?



If your master password has enough entropy, you're safe with 1 iteration. It's not a great idea, and what "enough" is can be ambiguous. But if your master password is provably 70 bits of entropy or so, you should be fine.

But it's probably easier to just change your passwords anyway. At this point I wouldn't be suprised if the story gets even worse somehow.


I don't know enough to know. I'd change your passwords just to be safe.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: