OK higher is better sure, but is moving from 5K iterations to 100K per the recommendation a similar precaution to adding 1,2,3 digits to the master password?
OK higher is better sure, but is moving from 5K iterations to 100K per the recommendation a similar precaution to adding 1,2,3 digits to the master password?
The best precaution is to never use LastPass. If you used LastPass, the safe course of action is to change all your passwords that were in LastPass, and use a better password manager this time.
I'm not sure to whom the rest of your response is addressed, this was a technical question.
Adding a digit to a password can depend. Adding a 1 to the end of a password is such a well known thing that its basically useless because that's the first thing people try as its so common. Ultimately though, you are basically correct in a bruteforce scenario. However most password attacks involve a bit of knowledge about what the person likely choose, so the effect depends on what that knowledge is.
Keep in mind if you have a strong password (say 16 character randomly generated, never reused elsewhere) its not going to matter how many iterations as it will never be bruteforced even if the worst possible hash was used. This sort of thing protects people who use weak or maybe mid-tier passwords.