Master password authentication mechanism exposed without adequate protection
against brute force or credential attacks.
Master password authentication mechanism exposed without adequate protection against brute force or credential attacks.
### Threat
@@ -1541,32 +1539,26 @@ against brute force or credential attacks.
### Risk
**HIGH** - Compromise of master password provides complete access to all stored
credentials. Likelihood elevated due to targeted nature of password manager
attacks.
**HIGH** - Compromise of master password provides complete access to all stored credentials. Likelihood elevated due to targeted nature of password manager attacks.
### Requirement
-**R1.1**: SHALL implement key derivation function (KDF) with minimum 100,000
iterations (PBKDF2) or equivalent computational cost