Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
maibus2
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
maibus2
7y ago
"Should" is the key word there. When Last Pass was breached in 2015, they were using only 5k iterations of PBKDF-2 to create the encryption key (but it was changed to ~100k in Feb 2018) [1]. [1] https://palant.de/2
2.
▲
by
maibus2
7y ago
Yes. Given how mass data leaks have shown just how bad people are at choosing passwords - I think it's a very safe assumption that a large proportion of Last Pass users have weak, easily guessable master passwords. The ironic thing her
3.
▲
by
maibus2
7y ago
Your arguments are sound in theory. But not in practice (for LastPass, 1Password has a better design). For example LastPass was deriving their encryption key with only 5k rounds of PBKDF-2 iteration (but used ~100k rounds to create their au
4.
▲
by
maibus2
7y ago
This is not an irrational fear given how Last Pass and many other password managers are designed. Last Pass (and others) derive encryption keys from their users passwords (via PBKDF-2). Thus a (smart) attacker needn't guess the user&#x
5.
▲
The easiest way to build AWS Lambdas with Scala
(softwarebyjosh.com)
1 points
by
maibus2
8y ago
|
0 comments
6.
▲
by
maibus2
12y ago
Attribution issues aside, there's two scarier potential issues I see, actually I see these with all posts on "here's our company's cool new A/B testing framework", that really scare me: 1. You're running a
7.
▲
Nice Looking Open Source Charts That Work in IE
(softwarebyjosh.com)
2 points
by
maibus2
14y ago
|
0 comments
8.
▲
Design Pattern: Threaded Requests With Retries
(softwarebyjosh.com)
1 points
by
maibus2
15y ago
|
0 comments
9.
▲
How We Built a Product In Just 8 Hours
(softwarebyjosh.com)
1 points
by
maibus2
15y ago
|
0 comments