PBKDF2 device benchmark

Times the key derivation the app runs at sign-in (#1271): WebCrypto PBKDF2-SHA256, salt = the Rocket.Chat user id, to an AES-256 key, exactly as deriveMasterKeyFromPassword does it. Nothing is sent anywhere; the page works offline once loaded.

Before starting: close other apps, keep the screen on and this tab in front for the whole run. A page that goes to the background is throttled, and the result is marked invalid. Running it a second time right after the first shows whether the device slows down when warm.

Ready.

Scenariomedianp90minmax

Target (#1271): a sign-in under about 2 s on a 10th-percentile device. The decisive row is “two derivations at 600,000” (recovery, password change, anonymous upgrade). If it is over target, the 310,000 rows show whether the documented fallback is.

Run the benchmark first.