RE: Unable to log in to my account
March 30, 2016 at 6:23 pm
(This post was last modified: March 30, 2016 at 6:25 pm by Tiberius.)
(March 30, 2016 at 6:15 pm)Cthulhu Dreaming Wrote: ...and that brute force attack would take a tremendous amount of time and resources for each user.
This.
LastPass by default takes your master password and hashes it using PBKDF2 5,000 times. That slows down the key generation process enough to effectively make attempting a brute-force a waste of time.
Ironically the fact that LastPass got hacked actually made me trust their security more, because as far as I am aware, the hackers never actually got into any of the password vaults, meaning their encryption protocols were top notch. Sure, it's a shame their infrastructure was breached, but the important thing was the data was still secured.