fell, to SmartHome
@fell@ma.fellr.net avatar

I stopped messing with client certificates and went back to good old HTTP basic authentication for my little digital light switch panel.

It's a shame nobody cares about TLS client certificates. With a bit more effort we could've gotten rid of passwords a long time ago.

I wish there was something like SSH keys for the web.

Yeah I know, Passkeys are a thing... but also not really.

skariko, to lealternative Italian

IYPS, controlla se la tua password è sicura

IYPS è un’applicazione (open source e senza connessione internet) che vi permette di scoprire se la vostra password è sicura o meno.

https://www.lealternative.net/2024/04/03/iyps-controlla-se-la-tua-password-e-sicura/

image/png
image/png

mmu_man, to random French
@mmu_man@m.g3l.org avatar

Anyone knows a good web form #password brute forcing tool?

This *** Samsung copier we got donated we don't know it, and the panel fails to boot, and reflashing it requires… the password 🤷

poke @aeris @imil

jrod3737, to security
@jrod3737@mstdn.social avatar

I’m all for the idea of passkeys. But I am not for the idea of Google or Apple knowing my fingerprint or face. I have all that turned off as strongly as possible without searing off my fingerprints or cutting off my face.

mdmrn, to infosec
@mdmrn@urusai.social avatar

They say my password now needs to contain at least one special character.

I chose Akuma from Street Fighter, but they said it still wasn't right.

Guess I'll figure it out later.

mjgardner, to passkeys
@mjgardner@social.sdf.org avatar

Shots fired at @bitwarden: “And many managers only support on specific platforms…”

When will we be able to create and use passkeys outside of the browser extension? https://mastodon.social/@protonprivacy/112134037609531372

maki, to apple German
@maki@social.tchncs.de avatar

An die 🍎-Kinder. Die Passwortmanagerapp kann ich nur empfehlen. Nutze diese schon seit Jahren und die ist jetzt im Angebot für heute 🫶

https://www.mydealz.de/deals/strongbox-pro-lifetime-fur-ios-ipados-und-macos-2332696

swiefling, to Cybersecurity German
@swiefling@hci.social avatar

Worried about account takeover? You're not alone! Attackers often misuse the "forgot password" mechanism to hack us.

Our latest study revealed a game-changer to counter this: Risk-Based Account Recovery! Platforms like Google now tailor recovery mechanisms based on your device and location context, making it hard for bad actors but easy for legitimate users.

Read more in our paper: https://riskbasedauthentication.org/state-of-practice/account-recovery/

#CyberSecurity #InfoSec #HCI #UX #Password #Authentication #Research #OpenAccess

Is It Really You Who Forgot the Password? When Account Recovery Meets Risk-Based Authentication Abstract Risk-based authentication (RBA) is used in online services to protect user accounts from unauthorized takeover. RBA commonly uses contextual features that indicate a suspicious login attempt when the characteristic attributes of the login context deviate from known and thus expected values. Previous research on RBA and anomaly detection in authentication has mainly focused on the login process. However, recent attacks have revealed vulnerabilities in other parts of the authentication process, specifically in the account recovery function. Consequently, to ensure comprehensive authentication security, the use of anomaly detection in the context of account recovery must also be investigated. This paper presents the first study to investigate risk-based account recovery (RBAR) in the wild. We analyzed the adoption of RBAR by five prominent online services (that are known to use RBA). Our findings confirm the use of RBAR at Google, LinkedIn, and Amazon. Furthermore, we provide insights into the different RBAR mechanisms of these services and explore the impact of multi-factor authentication on them. Based on our findings, we create a first maturity model for RBAR challenges. The goal of our work is to help developers, administrators, and policy-makers gain an initial understanding of RBAR...

clayrivers, to random
@clayrivers@mastodon.world avatar

What is there not like about Keke Palmer, Jimmy Fallon, and everything that is ?

Sagittarius_Galaxie, to random German
@Sagittarius_Galaxie@mastodon.social avatar

Passwörter und ihre Tücken



BryceWrayTX, to infosec
@BryceWrayTX@fosstodon.org avatar

Ente Auth for TOTPs • I’ve learned of another fully FOSS app that fills the bill where TOTPs are concerned.

https://www.brycewray.com/posts/2024/03/ente-auth-for-totps/

@ente

publicvoit, to random
@publicvoit@graz.social avatar

Late night, when you're entering your computer many times and get a negative feedback, start to question your ability to remember one of your most important and frequently used passphrases until you realize that you enter the (correct) passphrase of a different machine. 🤦‍♂️

adamsdesk, (edited ) to technology
@adamsdesk@fosstodon.org avatar

How To Enable Pasting Text on Websites That Block It

A comprehensive step by step guide to effectively removing the barriers from websites that want to take away the ability to paste text by blocking it.

https://www.adamsdesk.com/posts/enable-pasting-text-websites-block-it/

neatchee, (edited ) to security
@neatchee@urusai.social avatar

I am very annoyed with Sony. I can't log in to my PlayStation account because ALL of their sign-in forms were changed to only allow 32 characters. I default to 64 character random passwords, which they previously allowed, so now I can't enter my password anymore

WTF Sony? You decreased security everywhere and didn't even notify people with passwords that are no longer compliant? The least you could do is force a reset when I try to log in next.

EDIT: Obviously the solution is just change my password but jfc is this dumb

kuketzblog, to android German
@kuketzblog@social.tchncs.de avatar

Wie wird der Fingerabdruck unter Android gespeichert? Ist das sicher? Kann dieser ausgelesen werden? Was ist nun besser Fingerabdruck oder PIN/Password? Dies und mehr unter 👇

https://www.kuketz-blog.de/fingerabdruck-zum-entsperren-von-smartphones-sicherheitsrisiko-oder-kalkuliertes-risiko/

NeadReport, to random
@NeadReport@vivaldi.net avatar

Sweet. Proton community members are now beta testing the Proton Pass Windows desktop app. That means me, too.

Dariusz_w, to linux
@Dariusz_w@seocommunity.social avatar

🇬🇧 𝗖𝗵𝗿𝗼𝗺𝗲𝗢𝗦, 𝗟𝗶𝗻𝘂𝘅 𝗲𝗻𝘃𝗶𝗿𝗼𝗻𝗺𝗲𝗻𝘁 𝗮𝗻𝗱 𝘀𝘂𝗱𝗼 𝗽𝗮𝘀𝘀𝘄𝗼𝗿𝗱

https://dariusz.wieckiewicz.org/en/chromeos-linux-sudo-password/






BWPanda, to webdev
@BWPanda@fosstodon.org avatar

Website: Please enter your new #password. Oh sorry, you can't paste it; you'll need to manually type it out.

Me: It's cute that you think you can stop me from pasting text into a field opens [#DevTools...]

#browser #html #javascript #paste #f12

kubikpixel, to internet
@kubikpixel@chaos.social avatar

«Perform password based in the with zero dependencies»

What is your opinion on the article, does it make , e.g. secure transmission of 's for logging on to the ? I'm asking so bluntly because I'm unsure about this and every person gives me a different answer.

🔑 https://blog.elantha.com/encrypt-in-the-browser/

eff, to random
@eff@mastodon.social avatar

Most people should use a #password manager, but there's no one-size-fits-all recommendation. https://ssd.eff.org/module/choosing-the-password-manager-that-s-right-for-you

amadeus, to random
@amadeus@mstdn.social avatar

I really don't understand why so many (s) limit the of (s). 🤔️

mattburgess, to tech

NEW: The death of the password is really upon us. I spent the last month trying to ditch my passwords for passkeys, the more secure replacement.

The result: passkeys are great. But the user experience of setting them up and using them across multiple devices still needs some work

https://www.wired.com/story/stopped-using-passwords-passkeys/ #password #passkey #tech #privacy #technology

minioctt, to Catroventos Italian

Giusto un , che mi è venuto mentre ieri sera mi stavo addormentando, e che avrei perso credo per sempre se proprio ora non mi fosse tornato alla mente: la password” ha il potenziale latente di essere un . 🗿

Il letterale in , lo sapete, sarebbe “parola di passaggio”, cioè quella di che permette di accedere a qualcosa… ma se traducessimo la parola nella nostra dall’inglese correggiuto, anziché dal normale ? Ecco che avremmo la “passaparola“. E questo è , perché una è esattamente quel genere di che, di solito, si dovrebbe evitare di far finire nelle grinfie di un passaparola; va tenuta , in genere. 🤫

Credo che l’unico motivo per cui noi non abbiamo preso il vizio di dirla così, al contrario di altre che sono state distorte, è perché dire “registrati inserendo un nome utente e la tua passaparola” sembra una proveniente da un dialogo di Pokémon che menziona, che ne so, uno strumento chiave. 👾

E, un’altra cosa a riguardo della questione che fa molto pensare, ma è diversa: quella che in genere si definisce una “password sicura”, non può quasi mai essere una semplice “password”, ma piuttosto deve essere una “passphrase“, o anche, direi, una “passstring“; cioè, rispettivamente, una frase con multiple, oppure una sequenza di caratteri che abbia un’entropia più alta della parola media nella lingua umana media. Viviamo proprio in una società… 💀

https://octospacc.altervista.org/2024/02/06/se-solo-fosse-passaparola/

Viss, to random
@Viss@mastodon.social avatar

go to the cloud they said.
it'll be fine, they said.

OrionFed,
@OrionFed@mas.to avatar

@Viss
I'm all for managers, but not cloud-based
Personally, I use KeyPass2, which keeps the database local

kubikpixel, to business
@kubikpixel@chaos.social avatar

Sorry #VPN wie es momentan beworben wird war noch nie Sicher und ein klarer #MITM und nur bei den wenigsten Anbietern auch vertrauenswürdig - Da sind ganz dubiose & gruselige Firmengeflechte im Hintergrund. Dann kommen ein paar #Dumps und bestätigen deine Befürchtungen. VPN macht durch aus Sinn in einem #Business #Netzwerk aber eben nicht so.

»21 Million VPN User Records durchgesickert; VPN am Ende?«

🕳️ https://www.borncity.com/blog/2022/05/16/21-million-vpn-user-records-durchgesickert-vpn-am-ende/

#sicherheit #anonym #dump #db #itsec

kubikpixel,
@kubikpixel@chaos.social avatar

Thank you @dumbpasswordrules for your clarification and how NordVPN is not a secure tool. How many times do I have to mention that this is not security. To consume something country restricted is again (a little) different but also no privacy preserved.

🤦 https://dumbpasswordrules.com/sites/nordvpn/

#dump #password #nordvpn #vpn #internet #security #prevention #password

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • cisconetworking
  • DreamBathrooms
  • InstantRegret
  • mdbf
  • khanakhh
  • magazineikmin
  • Durango
  • Youngstown
  • slotface
  • rosin
  • everett
  • kavyap
  • Leos
  • megavids
  • ngwrru68w68
  • tacticalgear
  • osvaldo12
  • GTA5RPClips
  • ethstaker
  • thenastyranch
  • cubers
  • anitta
  • tester
  • modclub
  • normalnudes
  • provamag3
  • lostlight
  • All magazines