Not sure if this is already on the @Quexten’s and Bitwarden devs’ list of things to do, but I think it would be very helpful to update the Interactive Cryptography Tool to include an implementation of the new Argon2 KDF Support (including the ability for users to test the settings for iterations, memory, and parallelism parameters).
Among other uses, this would provide users a tool to test the performance of the client-side hashing on their own device, before making changes in the actual account settings. We’ve seen a few instances on the forum of users running into problems when increasing the kdfIterations setting for the current PBKDF2 hashing function, and subsequently being unable to log in to their accounts. The cryptography tool could provide a testing grounds for checking the browser responsiveness at various KDF cost settings, before committing to making such a change in the account settings.
I imagine that the cryptography page will eventually be updated, but I would recommend that this update be implemented a.s.a.p. , because as soon as the new Argon2 KDF support is released, there are sure to be some users who will push all parameter settings to their maximum values (and then be surprised at getting logged out from all sessions, despite the prominent warning message). Some of these users may have trouble logging back in…
To be honest I had no idea this existed. Is there an open source repo for the cryptography tool?
In the meantime, to get a sense for the performance for the non-native (so not mobile, cli) versions you can always try Argon2 in browser since it uses the same WebAssembly library as the Bitwarden clients.
The defaults in Bitwarden are (from memory) Iterations: 3, Paralellism: 4, Memory: 128MiB (131072 KiB), Argon2id.
The maximum values are: Iterations: 10, Parallelism: 16, Memory: 1GiB (1048576KiB).
When I try the maximums that @Quexten mentioned on my newish Chromebook, I get a memory allocation error and it fails to complete. Will that scenario lock users out of their Web Vaults if it happens in Bitwarden?
It seems like we need a Test button built into the Keys tab in the Web Vault.