Light

Episode #905 Quiz

1
Date: 2023-01-10 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

Rob Woodruff’s PowerShell GUI deobfuscates LastPass XML vault exports, revealing cleartext URLs and flags ECB-encrypted entries. Listener discoveries showed many accounts still used PBKDF2 iteration counts of 1, 500, or 5,000. With known metadata, attackers can prioritize weak vaults; low iterations plus GPU cracking can expose passwords, notes, and identities.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what is the practical effect of leaving a LastPass account’s PBKDF2 iteration count set to 1 after the breach data was stolen?
Question 2: What did Rob Woodruff’s PowerShell tool reveal about LastPass vault entries, beyond merely exporting the vault data?
Question 3: Which metadata did Steve say was visible in the HTML output from the deobfuscator, in addition to the logon URLs?
Question 4: How did Steve characterize LastPass’s handling of users whose iteration count had remained at 1 for years?
Question 5: What alternative to PBKDF2 did Steve recommend password managers consider because it is memory-hard and not GPU-friendly?
Cancel