-
Notifications
You must be signed in to change notification settings - Fork 2
Open
Description
The number of iterations used for PBKDF2
Line 5 in bf474ee
| const iteratrions = 1000; |
is most likely too low for most settings.
According to NIST recommendations (https://pages.nist.gov/800-63-3/sp800-63b.html),
Therefore, the iteration count SHOULD be as large as verification server performance will allow, typically at least 10,000 iterations.
In 2016, 1Password was using 100,000 iterations for example (https://support.1password.com/pbkdf2/).
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels