NeadReport, to random
@NeadReport@vivaldi.net avatar

Sweet. Proton community members are now beta testing the Proton Pass Windows desktop app. That means me, too.

RedForkian, to random

This was written in 2015, but it is just as correct today as it was then. Passphrase generation is just as important as the method.

https://theintercept.com/2015/03/26/passphrases-can-memorize-attackers-cant-guess/

ap236, to bitwarden
@ap236@mastodon.social avatar

Bitwarden Tutorial | The Full Beginners Guide - YouTube https://bit.ly/3Ps7Ims @cdnpoli

epixoip, to random

Happy !

I've cracked billions of from tens of thousands of in the past 12+ years, and because of this, I likely know at least one for 90% of people on the Internet. And I'm not alone! While I primarily crack breached passwords for research purposes and the thrill of the sport, others are selling your breached passwords to criminals who leverage them in and attacks.

How can you keep your accounts safe?

  • Use a ! I recommend @bitwarden and @1password

  • Use a style - four or more words selected at random - for passwords you have to commit to memory, like your master password!

  • Enable MFA for important online accounts, including cloud-based password managers!

  • Harden your master password by tweaking your password manager's KDF settings! For , use Argon2id with 64MB memory, 3 iterations, 4 parallelism. For and other PBKDF2 based password managers, set the iteration count to at least 600,000.

  • Use unique, randomly generated passwords for all your accounts! Use your password manager to generate random 14-16 character passwords for everything. Modern password cracking is heavily optimized for human-generated passwords, because humans are highly predictable. Randomness defeats this and forces attackers to resort to incremental brute force! There's no trick you can do to make a secure, uncrackable password on your own - your meat glob will only betray you.

  • Use an ad blocker like Origin to keep you safe from password-stealing and other browser based threats!

  • Don't fall for attacks and other social engineering attacks! Browser-based password managers help defend against phishing attacks because they'll never autofill your passwords on fake login pages. Think before you click, and never give your passwords to anyone, not even if they offer you chocolate or weed.

  • : require ad blockers, invest in an enterprise password management solution, audit password manager logs to ensure employes aren't sharing passwords outside the org, implement a Fine Grained Password Policy that requires a minimum of 20 characters to encourage the use of long passphrases, implement a password filter to block commonly used password patterns and compromised passwords, disable authentication and disable RC4 for , disable legacy broadcast protocols like LLMNR and NBT-NS, require mandatory signing, use Group Managed Service Accounts instead of shared passwords, monitor public data breaches for employee credentials, and crack your own passwords to audit the effectiveness of your password policy and user training!

Septem9er, to random German
@Septem9er@chaos.social avatar

How did I end up making calculations in a spreadsheet instead of studying now?

I just quickliy wanted to check what the picture about password security, that is currently shared a lot means for the security of / .

Ehm, the Internet in the train was shitty, so I couldn't study! Let's use that as excuse. (He says, hours after exiting the train.)

Septem9er,
@Septem9er@chaos.social avatar

In case anyone else is interested on a comparison of passphrases vs. passwords, here is the result.

Number in the top row refers to the number of words in the and the hardware used. The number in the first column refers to the number of words in the
For comparison the original table for passwords from hive systems.

We assume the attacker knows we use a passphrase and uses a wordlist attack. Other than that method and calculation basis as in: https://www.hivesystems.io/blog/are-your-passwords-in-the-green

Original table for using 1000x A100s to crack the passwords
Original table for using 12x RTX 4090s to crack the password

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • Youngstown
  • everett
  • slotface
  • rosin
  • osvaldo12
  • mdbf
  • ngwrru68w68
  • megavids
  • cubers
  • modclub
  • normalnudes
  • tester
  • khanakhh
  • Durango
  • ethstaker
  • tacticalgear
  • Leos
  • provamag3
  • anitta
  • cisconetworking
  • lostlight
  • All magazines