Add (optional) Secret Key functionality (Like 1Password) or keyfile (Like Keepass)

It would create security benefits for the cloud vault similar to what is achieved in 1Password with the secret key, but it is transparent to the user (i.e., there is no requirement for the user to store a secret key on each device). It will be applied automatically to all cloud vaults upon access. I’ll defer further commentary on this new feature until the revised whitepaper has been released.

P.S. @222 They are re-encrypting both the master password hash and the protected key. This shuts down the ability to by-pass server-side KDF iterations, that everybody was panicking about in January. :roll_eyes:

2 Likes