Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Vaultwarden
  3. Insecure KDF iterations settings

Insecure KDF iterations settings

Scheduled Pinned Locked Moved Vaultwarden
11 Posts 4 Posters 938 Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • potemkin_aiP potemkin_ai

    Vaultwarden is installed by default with non-secure kdf iterations settings - would you please, set it up to 600.000 as a minimum please? Ideally - have it set up till 2.000.000

    jdaviescoatesJ Online
    jdaviescoatesJ Online
    jdaviescoates
    wrote on last edited by
    #2

    @potemkin_ai said in Insecure KDF iterations settings:

    600.000 as a minimum please?

    Yeah, is the default on Bitwarden according to https://bitwarden.com/help/kdf-algorithms/

    I use Cloudron with Gandi & Hetzner

    potemkin_aiP 1 Reply Last reply
    0
    • jdaviescoatesJ jdaviescoates

      @potemkin_ai said in Insecure KDF iterations settings:

      600.000 as a minimum please?

      Yeah, is the default on Bitwarden according to https://bitwarden.com/help/kdf-algorithms/

      potemkin_aiP Offline
      potemkin_aiP Offline
      potemkin_ai
      wrote on last edited by
      #3

      @jdaviescoates it was not in case of my server setup, and I didn't touch a thing since it was installed!

      1 Reply Last reply
      0
      • potemkin_aiP Offline
        potemkin_aiP Offline
        potemkin_ai
        wrote on last edited by
        #4

        One more thing:

        You are using a plain text ADMIN_TOKEN which is insecure.
        Please generate a secure Argon2 PHC string by using vaultwarden hash or argon2.

        Admin token - which enables full access - is indeed stored plain text and accessible for cloudron admin.

        girishG 1 Reply Last reply
        0
        • potemkin_aiP Offline
          potemkin_aiP Offline
          potemkin_ai
          wrote on last edited by
          #5

          here is an official doc, just in case: https://github.com/dani-garcia/vaultwarden/wiki/Enabling-admin-page#secure-the-admin_token

          1 Reply Last reply
          0
          • girishG Offline
            girishG Offline
            girish
            Staff
            wrote on last edited by
            #6

            In my server atleast, config.json has

              "password_iterations": 600000,
            

            I don't remember changing this

            1 Reply Last reply
            0
            • girishG Offline
              girishG Offline
              girish
              Staff
              wrote on last edited by girish
              #7

              The default install has 600k, so maybe I am missing something with this report.

              image.png

              necrevistonnezrN 1 Reply Last reply
              0
              • potemkin_aiP potemkin_ai

                One more thing:

                You are using a plain text ADMIN_TOKEN which is insecure.
                Please generate a secure Argon2 PHC string by using vaultwarden hash or argon2.

                Admin token - which enables full access - is indeed stored plain text and accessible for cloudron admin.

                girishG Offline
                girishG Offline
                girish
                Staff
                wrote on last edited by
                #8

                @potemkin_ai said in Insecure KDF iterations settings:

                Admin token - which enables full access - is indeed stored plain text and accessible for cloudron admin.

                I think you have to regenerate it like https://docs.cloudron.io/apps/vaultwarden/#admin which already uses argon

                1 Reply Last reply
                0
                • girishG girish

                  The default install has 600k, so maybe I am missing something with this report.

                  image.png

                  necrevistonnezrN Offline
                  necrevistonnezrN Offline
                  necrevistonnezr
                  wrote on last edited by
                  #9

                  @girish said in Insecure KDF iterations settings:

                  The default install has 60k, so maybe I am missing something with this report.

                  The default Cloudron install (now) has even 600k, not only 60k.
                  But I think it wasn't always like this (see https://forum.cloudron.io/topic/11194/vaultwarden-security-enhancement-tip/) and @potemkin_ai has an old install?

                  girishG potemkin_aiP 2 Replies Last reply
                  1
                  • necrevistonnezrN necrevistonnezr

                    @girish said in Insecure KDF iterations settings:

                    The default install has 60k, so maybe I am missing something with this report.

                    The default Cloudron install (now) has even 600k, not only 60k.
                    But I think it wasn't always like this (see https://forum.cloudron.io/topic/11194/vaultwarden-security-enhancement-tip/) and @potemkin_ai has an old install?

                    girishG Offline
                    girishG Offline
                    girish
                    Staff
                    wrote on last edited by
                    #10

                    @necrevistonnezr said in Insecure KDF iterations settings:

                    The default Cloudron install (now) has even 600k, not only 60k.

                    ah, even in my screenshot it is 600k. I misread it!

                    1 Reply Last reply
                    0
                    • necrevistonnezrN necrevistonnezr

                      @girish said in Insecure KDF iterations settings:

                      The default install has 60k, so maybe I am missing something with this report.

                      The default Cloudron install (now) has even 600k, not only 60k.
                      But I think it wasn't always like this (see https://forum.cloudron.io/topic/11194/vaultwarden-security-enhancement-tip/) and @potemkin_ai has an old install?

                      potemkin_aiP Offline
                      potemkin_aiP Offline
                      potemkin_ai
                      wrote on last edited by
                      #11

                      @necrevistonnezr my installation is quite old - that's correct. Thanks for checking in!

                      @girish , thank you for the doc's reference! Guess it might make sense to stress that during the installation, as well as an offer to increase KDF up to 2 mln (as per Bitwarden docs as well).

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search