The number of iterations is needed for login. The user enters their email address and password, and the app needs to know (before they actually log in) how many iterations to apply. There are approaches like the OPAQUE protocol which avoid having the iterations count in the open, but LastPass didn’t implement that. To their defense, OPAQUE is relatively new.