Unable to change master password

I signed up for a bitwarden account a few years ago, only came back to my account today to really try it out. I remembered my password, no problems logging in.

The first thing I wanted to do (using the website, not an app) is update my master password since my old master password wasn’t particularly secure.

But every time I try to update my master password, I just get a red box in the corner “An error has occurred”. I’m certainly typing in the correct old password. My new password isn’t anything crazy, just a phrase. Tried a few different new passwords, tried safari, tried chrome, no luck. I’m stuck using my old password from a few years ago. Totally discouraging start.

Anybody else seen this before?

@CBSF Welcome to the forum!

On that same page, could you check the tab “Keys”? You probably see “PBKDF2” as your algorithm… check if it’s at least 600,000 iterations. If it’s not: make it so.

After that, try to change your master password again.

Depending on if you already have data stored in your BW account or not: it’s recommended to always make an export before such critical vault/account operations.

First of all, thank you! that worked. Very speedy reply appreciated too.

I’m not sure this increases my confidence in this product at all. My intent was to use this for my whole family, but I can’t imagine them tolerating any number of situations where I’m telling them to “adjust your PBKDF2 encryption iterations and then you’ll be fine :laughing:

Meanwhile, I go to the next step to put in my very first credential and WTF are you serious, they’ve got HTML barfing up in their help text? (See attached.) I didn’t find this in some deep down obscure menu feature, it’s just the first message literally any user will see creating a credential. My confidence is not high right now that this company can keep my secrets safe.

FWIW, I think you found two “bugs” that are related to current developmental work.

What you encountered here is very similar to this issue: Unable to change master password: The model state is invalid (validationErrors: UnlockData.Kdf) · Issue #20229 · bitwarden/clients · GitHub

As explained there, older accounts – with older encryption / KDF settings – are being migrated at the moment. I’m not sure if it’s still on hold (but seems like it, as it didn’t happen for you automatically as you logged in to the web vault).

Your family should be okay, as the encryption doesn’t have to be “migrated” in the same way when someone creates a new Bitwarden account right now.

Ah, interesting. Those “nudge” messages – or “onboarding” notices – are also fairly new… your screenshot shows a very similar thing as this recent issue was about: SSH nudhe message containts a broken <a> tag · Issue #20492 · bitwarden/clients · GitHub

PS:

Where exactly – also on what BW client – did you see this:

?