Hacker News new | ask | show | jobs
by stubish 1267 days ago
Can attackers can easily tell the 1 and 500 iteration databases and focus their resources in breaching those ones?
1 comments

Disclaimer: I’m the author of this article.

Yes. The number of iterations is presumably stored in the same customers database that they stole. Even if not: the number of iterations can be queried via a public API, anyone can do it if they know the email address.