<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What's the latest information about Firefox Sync password storage? in Discussions</title>
    <link>https://connect.mozilla.org/t5/discussions/what-s-the-latest-information-about-firefox-sync-password/m-p/21511#M9030</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Due to the &lt;A href="https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/" target="_self"&gt;recent LastPass breach&lt;/A&gt; I was having a conversation about how to store passwords.&lt;/P&gt;&lt;P&gt;Both LastPass and Firefox (Sync) seems to do a similar thing, but I actually don't know what's the last state of things in Firefox. The only article I found is &lt;A href="https://hacks.mozilla.org/2018/11/firefox-sync-privacy/" target="_self"&gt;this one&lt;/A&gt;&amp;nbsp; that is over 4 years old.&lt;/P&gt;&lt;P&gt;I am not by far a security expect but something that stood out was the use of PBKDF2 which is apparently the security concerns in the breach (leak was of encrypted passwords). LastPass says "LastPass utilizes a stronger-than-typical implementation of 100,100 iterations of the Password-Based Key Derivation Function (PBKDF2), a password-strengthening algorithm that makes it difficult to guess your master password. "&lt;/P&gt;&lt;P&gt;Apparently the &lt;A href="https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pbkdf2" target="_self"&gt;OWASP recommendation is to have even more iterations&lt;/A&gt; . And yet in the Firefox post mentioned above it says that "&amp;nbsp;We [Firefox] use 1000 rounds of PBKDF2" So something seems off.&lt;/P&gt;&lt;P&gt;It would be great to have a more detailed description of the current implementation that Firefox uses. Maybe a comparison what what other password providers use.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 23 Dec 2022 12:02:08 GMT</pubDate>
    <dc:creator>alexj</dc:creator>
    <dc:date>2022-12-23T12:02:08Z</dc:date>
    <item>
      <title>What's the latest information about Firefox Sync password storage?</title>
      <link>https://connect.mozilla.org/t5/discussions/what-s-the-latest-information-about-firefox-sync-password/m-p/21511#M9030</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Due to the &lt;A href="https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/" target="_self"&gt;recent LastPass breach&lt;/A&gt; I was having a conversation about how to store passwords.&lt;/P&gt;&lt;P&gt;Both LastPass and Firefox (Sync) seems to do a similar thing, but I actually don't know what's the last state of things in Firefox. The only article I found is &lt;A href="https://hacks.mozilla.org/2018/11/firefox-sync-privacy/" target="_self"&gt;this one&lt;/A&gt;&amp;nbsp; that is over 4 years old.&lt;/P&gt;&lt;P&gt;I am not by far a security expect but something that stood out was the use of PBKDF2 which is apparently the security concerns in the breach (leak was of encrypted passwords). LastPass says "LastPass utilizes a stronger-than-typical implementation of 100,100 iterations of the Password-Based Key Derivation Function (PBKDF2), a password-strengthening algorithm that makes it difficult to guess your master password. "&lt;/P&gt;&lt;P&gt;Apparently the &lt;A href="https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pbkdf2" target="_self"&gt;OWASP recommendation is to have even more iterations&lt;/A&gt; . And yet in the Firefox post mentioned above it says that "&amp;nbsp;We [Firefox] use 1000 rounds of PBKDF2" So something seems off.&lt;/P&gt;&lt;P&gt;It would be great to have a more detailed description of the current implementation that Firefox uses. Maybe a comparison what what other password providers use.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 12:02:08 GMT</pubDate>
      <guid>https://connect.mozilla.org/t5/discussions/what-s-the-latest-information-about-firefox-sync-password/m-p/21511#M9030</guid>
      <dc:creator>alexj</dc:creator>
      <dc:date>2022-12-23T12:02:08Z</dc:date>
    </item>
  </channel>
</rss>

