Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Bitwarden didn't fail, there was no embarrassment. They actually encrypt the vault unlike Lastpass. There is heightened awareness around the various issues that came to light following the Lastpass attack, and PBKDF2 is one of them. In Bitwarden the iteration count is user configurable.

Note also that Bitwarden provides its server software (and there is a great alternate implementation in vaultwarden); it doesn't have to be an "internet-connected data vault".

Your position is not vindicated by TFA, but I applaud your caution and you are like 10% less of an old man howling at the moon.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: