

Because most people can't remember a string that has more than 128 bits of entropy, I think it is almost certain that master passwords used by 1P customers are much stronger than master passwords used by Bitwarden customers.
#1password alternative reddit password
If the master password in Bitwarden has the same level of entropy as the master password in 1P (made up of Secret Key and what you remember), Bitwarden technically can achieve a higher level of security because you can increase client-side PBKDF2 iterations. The current advice is that you want to have 600,000 Iterations.

And Bitwarden allows users to choose the number of iterations and 1P has it fixed at 100,000. Client-side PBKDF2 still offers security benefits. The "complication" that the server-side PBKDF2 was intended to provide, therefore, does not offer security benefits because would-be hackers don't need to target the master password hash. The blog post says it is possible to bypass server-side PBKDF2. We'll always be marked by an official flair, and will always love both 1Password and you. You'll see some friendly people from the 1Password team ready to help you - keep an eye out for /u/1PasswordCS-Blake, /u/agben, u/Zatara214, and more of us!
