Skip to content

KDF values shown wrong(?) in webvault, upon changing algo type. CLIENT ISSUE. #5111

Answered by BlackDex
rdslw asked this question in Q&A
Discussion options

You must be logged in to vote
  1. If I cancel popup, without any changes, it does not appear on subsequent login (even after full logout). Where this cancellation state is stored? Client cookie? DB?

If you mean the popup regarding the Low KDF Warning, that is stored in the browsers local storage.

  1. 'password_iterations' column from db is "Vaultwarden KDF settings" not account settings, correct?

That is a Vaultwarden setting. That is used to hash the already hashed master-password the clients send.
This is done to prevent easy decryption of the users/hashed-masterpassword from the database.

  1. why then it can differ per account basis?

The hash stored in the database is hashed using the password_iterations amount of …

Replies: 8 comments 5 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
5 replies
@stefan0xC
Comment options

@rdslw
Comment options

@rdslw
Comment options

@BlackDex
Comment options

Answer selected by rdslw
@rdslw
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
bug Something isn't working
3 participants
Converted from issue

This discussion was converted from issue #5109 on October 19, 2024 17:57.