An incident handler is investigating a breach where an attacker gained access to a system that uses a password manager. The password manager stores all user passwords in an encrypted vault protected by a single master password. The attacker was able to extract the encrypted vault and is now attempting to crack the master password offline. Which of the following characteristics of the password manager's key derivation function would most significantly increase the attacker's difficulty?
Argon2id is a memory-hard key derivation function that requires significant memory and CPU resources, making it highly resistant to GPU-based cracking. A high iteration count further increases the computational cost. This combination forces the attacker to expend substantial resources for each guessing attempt, dramatically slowing down offline cracking of the master password.
Why this answer
The key derivation function used to transform the master password into an encryption key is critical. A memory-hard function like Argon2id with a high iteration count requires large amounts of memory and CPU time per guess, making offline brute-force attacks impractical. This significantly increases the cost for the attacker, even with specialized hardware.
Exam trap
The trap here is focusing on the encryption algorithm (AES-256) or hardware protection (HSM) when the primary defense against offline master password cracking is the key derivation function's memory-hardness and iteration count.