Round 1
What one guess costs an attacker
Zen Passwords
Argon2id from the start, with no menu to find. New vaults work out what your phone can afford. They start at 256 MB of memory per guess and step down through 128 and 64, keeping the strongest setting that still unlocks in under a second.
Enpass
PBKDF2 with SHA-512, at 320,000 rounds, according to their own security whitepaper, with the vault itself encrypted using SQLCipher and AES-256. That is a careful, well documented design and a high round count for the method.
Zen Passwords. Zen Passwords. 320,000 rounds is a respectable number and PBKDF2 is not broken. It simply costs an attacker time and no memory, and memory is the thing a rack of graphics cards is short of. This is the one place where being younger helped us: we started after Argon2 won the argument.






