Skip to content

Higher number of iterations for PBKDF2 #2

@fabrice102

Description

@fabrice102

The number of iterations used for PBKDF2

const iteratrions = 1000;

is most likely too low for most settings.
According to NIST recommendations (https://pages.nist.gov/800-63-3/sp800-63b.html),

Therefore, the iteration count SHOULD be as large as verification server performance will allow, typically at least 10,000 iterations.

In 2016, 1Password was using 100,000 iterations for example (https://support.1password.com/pbkdf2/).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions