Breaking into 1Password, KeePass, LastPass and Dashlane
blog.elcomsoft.com
blog.elcomsoft.com
As my pass phrase is significantly stronger than that, I'm absolutely not worried..
They test an old version of Keepass with an old KDF (they recently switched to Argon2 which is much more resistant to GPU/ASIC attacks. Additionally KeepassDroid is intended to use vaults synched to the device via Google Drive, Dropbox or whatever, so having the vault in private storage makes no sense!
Even the project with most contributors - KeePassXC, doesn't yet support KDBX 4, and work on it doesn't look like its moving either[1]. Most other implementations also don't support KDBX 4 format.
Assuming they have something like rainbow tables for short passwords on all of these managers, it still seems like it would take a very long time to correctly guess longer master passwords (say 20+ characters). No?
This does not equate to "attack" or "remote attack".
It is mainly about having (legal) access to a seized storage device and trying to extract from it as much information as possible.
Although using the single NVIDIA GPU of a "normal" desktop is possible, normally some specialized hardware is needed/used (usually arrays of GPU's) to achieve a relatively high brute force attempt rate, something like :
https://www.shellntel.com/blog/2017/2/8/how-to-build-a-8-gpu...
"Different password managers employ different approaches to security. As an example, LastPass generates the encryption key by hashing the username and master password with 5,000 rounds of PBKDF2-SHA256, while 1Password employs even more rounds of hashing. This is designed to slow down brute-force attacks, and it almost works. Granted, these are still nearly an order of magnitude less secure than, say, Microsoft Office 2016 documents, but even this level of security is much better than nothing." I'm guessing they meant more secure then Office 2016.
Nothing to see here, move along.
For instance: commonChars of 1password of password length 20 will take 255,421,331,666,477,399,723,386 years, 3 months, 18 hours, 38 minutes, 39 seconds time
Well, this is the maximum amount of time, it could take considerably less than this, unless your password happens to be the very last one it tries to crack.
http://keepass.info/help/base/security.html
A question: does anyone have any idea why is it so much slower to crack Rar5 and Office 2016 than these password databases? What sort of magic sauce are they using to reduce the amount of guesses/second?
I have setup my KeePass to use around 100 mil iterations. It takes 1 second to validate the password on the CPU, on a GPU it will be maybe 100-1000 tries per second.
MS word, by comparison, does not offer this option, and so they simply default to something sanely high.
I understand this.
I was asking because the article says "[lastpass and 1password] are still nearly an order of magnitude less secure than, say, Microsoft Office 2016 documents, but even this level of security is much better than nothing.".
That, to me, implied that Office (and Rar5) were using some different - and much better! - algorithm that made guesses more expensive.
If indeed it is just a matter of more hashing rounds, then that sentence and the graph are very misleading and borderline FUD.
Doesn't this hark back to "If the attacker has local access, it's already game over"?