Bitwarden’s been throwing warnings on my phone telling me to scale back my hashing parameters because they might fail on this device.
Of course, now that I post about it, it’s not doing it so I can’t screenshot it…
#Bitwarden #PasswordHashing #Infosec
@c0dec0dec0de failing because your settings are... too secure? Sounds like a strange thing to discourage, unless it takes like several minutes to log in.
@groxx I mean, I’m well over the recommended Argon2id parameters from OWASP on purpose. But none of my devices actually struggle with it, so I don’t mind.
https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
@c0dec0dec0de do they enforce a timeout on hashing?
@aimaz I don’t know. Aside from the warning, I didn’t actually have any problems - no crashing or noticeable delays - so I haven’t tried to investigate further.
@c0dec0dec0de ah ok it’s the memory factor not the iterations. That makes more sense.