Hacker News new | ask | show | jobs
by maibus2 2635 days ago
"Should" is the key word there. When Last Pass was breached in 2015, they were using only 5k iterations of PBKDF-2 to create the encryption key (but it was changed to ~100k in Feb 2018) [1].

[1] https://palant.de/2018/07/09/is-your-lastpass-data-really-sa...