  1. NIST guidelines recommend at least 10K of iretations. So I'm pretty sure the current 24K rounds is more than enough -> Password with 8 letters + numbers + punctuation OR 4 random Diceware words would take 3250 years to crack if you use 10K rounds. So that's that
  2. Hi, it's been a while and there is no sign of update to password strength meter. I don't think that "123456123456123456" is "super" strong password - according to your meter it is.
