I hope it pleases you to know I sang this entire song to myself
I hope it pleases you to know I sang this entire song to myself
What about a price hike? If Netflix or Spotify increased their prices, would that be news?
After looking into this more, I’m definitely planning on switching from lastpass, but I did wanna clarify a couple things first.
Between this blog post, and this forum thread linking to this other blog post, I’m under the impression that LP’s number of PBKDF2 iterations used isn’t a big deal as long as your master password is secure, and I feel like that’s always gonna need to be the case no matter how much we want the password manager to take over.
That said if the crux of your point is that they didn’t do ANYTHING to address customers’ eventual concerns to low PBKDF2 iterations, whether that be via notification or forced config update, then that seems fair.
I’m no cryptography expert, but is it that big of a deal if hackers made away with the encrypted password data? LastPass says they encrypt with AES-256 so I figure that’s not getting cracked anytime this century. I’m more concerned about the unencrypted data, e.g. the Website URLs
If there’re no other alternatives, then I propose that going forward the new term for this should be “Crowd Striking”