Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The relavent part is what KDF they use on the master password.

Afaict They use pbkdf-sha256, with 100k rounds. which is not bad, but i think a memory hard function like argon2 would be much much better.

So its not terrible, but its not amazing either



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: