dside, to infosec Russian
@dside@mastodon.ml avatar

Это надо в школьную программу.

Игра про придумывание пароля, но после каждого правильного ответа появляется новое правило допустимости пароля, которое тоже нужно соблюсти, причём с учётом всех предыдущих.

Начинается с относительно знакомых требований, но быстро скатывается в концентрированный упорин.

https://neal.fun/password-game/

Найдено тут (спойлеры!): https://youtu.be/S9EAUtKVY4E – но после 7 минут я порвался и решил, что хочу пройти сам.

hazel, to security

Could anyone give me recommendations for a password manager? Google is basically useless now and I don't know anywhere else to ask. 😅

So far, I've never found one that I trust enough to use. I do understand the importance but I'm extremely, incredibly hesitant to hand over my passwords to a 3rd party program. I'm even more hesitant to use randomly-generated passwords that I can't memorize as a backup.

All that being said, here's what's important to me:

  • Transparency - public audits, published whitepaper, and/or open source.
  • Export to a printable format. I don't have reliable backups, so this is a must-have!
  • Works with desktop & mobile Firefox.
  • Works on Windows & Linux (I regularly use both).
  • Works on Android - not critical, but would be really helpful.
  • Can work offline (I don't trust any sync server to stay online).

For everything else, I'm more flexible. I don't mind paying a small amount for a better / more trustworthy option, either.

Any suggestions, recommendations, or just boosts are appreciated! Thanks so much in advance! 💙

avoidthehack, to Cybersecurity

As you probably know, it's awareness month.

During this month, I am placing renewed emphasis on basic tips for individuals.

To start, I highly encourage everyone to start with what I consider 3 essential and foundational aspects of "personal" security in cyberspace:

  • develop good management practices (stop reusing passwords is top of this)

  • keep / updated

  • use multifactor authentication/two-factored authentication

To be honest, even if you do only one of these things (especially if coming from doing none), you're on the right track.

Security is a process. Baby steps are okay.

https://avoidthehack.com/getting-started-cybersecurity

alwynispat, to apple

So here’s the problem with iCloud Passwords by Apple.
As long as the url’s domain, username and password is the same, Apple treats it as the same credential. Even when they are different systems.

Then when you have OTP, it becomes like this.

How am I to know which OTP is for which system?
You can’t even split them.

alwynispat,

Reached out to Apple, hope they fixes it.

michael, to iOS
@michael@thms.uk avatar

Huh. iOS 17 allows you to keep using your old passcode for 72 hours after you’ve changed it.

That seems like a non-ideal thing to do by default. And it certainly seems like something that should be highlighted really prominently when changing the passcode 🤔

https://support.apple.com/en-us/HT213849

CondeChocula, to GNOME Spanish

I'm looking for other password manager. Thinking to install Secrets from apps gnome circle. Anyone using it? Has 2fa codes too?

Thanks!

j_opdenakker, to infosec

Do use a password manager. Please.

Don’t use LastPass. Please.

Their latest move just shows they care more about their reputation and rather put responsibility and blame on their customers than solving the very serious security issues they have.

If you still use LastPass migrate asap to another password manager and change the secrets you have been storing in LastPass.

https://krebsonsecurity.com/2023/09/lastpass-horse-gone-barn-bolted-is-strong-password/

TechDesk, to random
@TechDesk@flipboard.social avatar

As hacks become more sophisticated, our need for more complex passwords is growing. But even using password managers can feel like work, ZDNet explains what passkeys are and how using them can make accessing accounts and software much easier.

https://flip.it/qMfsrg

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

Donald Trump Jr’s hacked Twitter account announces his father has died.

That'll be his dad who previously chose Twitter passwords like "yourefired" and "MAGA2020!"

https://grahamcluley.com/donald-trump-jrs-hacked-twitter-account-announces-his-father-has-died/

matdevdug, to security
@matdevdug@c.im avatar

I had a super obvious idea. Why don't password managers guard against spoofing by checking whether the hostname they have saved matches the site you are trying to enter the credentials into? I was spoofed a month ago and have been thinking about it since. Does anyone know if that's ever been proposed to a browser?

It's so obvious I assume I'm not the first person to think of it, but I cannot find anything online. Links appreciated.

pbx, to python
@pbx@fosstodon.org avatar

compatible one-line generator:

import secrets; "-".join(secrets.choice(open("/usr/share/dict/words").read().split()) for i in range(4))

My new password is "thoracoacromial-subapprobation-pyritohedral-autoconverter" and none of y'all will ever guess it.

Not sure how I'm going to come up with a mnemonic though...

Nonog, to linux

Password-stealing Linux malware served for 3 years and no one noticed
It's not too late to check if a Linux device you use was targeted.
The site, freedownloadmanager[.]org, offered a benign version of a Linux offering known as the Free Download Manager. Starting in 2020, the same domain at times redirected users to the domain deb.fdmpkg[.]org, which served a malicious version of the app.
https://arstechnica.com/security/2023/09/password-stealing-linux-malware-served-for-3-years-and-no-one-noticed/

majorlinux, to linux
@majorlinux@toot.majorshouse.com avatar

Hiding in your configs and stealing your data!

Password-stealing Linux malware served for 3 years and no one noticed https://arstechnica.com/security/2023/09/password-stealing-linux-malware-served-for-3-years-and-no-one-noticed/

publicvoit, to security
@publicvoit@graz.social avatar

People who were using are now losing also Millions of Crypto-Dollars:
https://krebsonsecurity.com/2023/09/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach/

No pity from my side for using -based services in the first place. Sorry, it's your own fault when you prioritize convenience over . Security experts were warning you before and you ignored it. 🤷

https://karl-voit.at/cloud/

omeraltundal, to Cybersecurity

Be careful what you say.

Socializing too much might lead you to give some secrets about yourself. This is a good example of Social Engineering

video/mp4

phillipdewet, (edited ) to random

Blocking paste in a field is a crime.

Not allowing users to see what they type counts in aggravation of sentencing.

Blocking paste, making us type in blind and then HAVING A TIMEOUT AFTER WRONG ATTEMPTS should be grounds for whipping the entire dev team and everyone above them in the org chart.

mattwilcox, to random
@mattwilcox@mstdn.social avatar

I really wish @1password had a concept of tabs. When i'm trying to reference the structure of one entry to recreate it on a new one, it's a real ball-ache having a non-tabbed interface.

kkarhan,
@kkarhan@mstdn.social avatar

@case2tv I chose since it literally runs on everything* - espechally and and doesn'r equire some subscription or charges people for the "privilegue" of self-hosting, like .
It's also -friendly.

*Okay it doesn't run on and except macOS & iOS, but then again:
People who daily drive , or are usually enough to basically setup their own storage system from scratch & sync and backup stuff.

kzimmermann, to opsec
@kzimmermann@fosstodon.org avatar

Sounds like Luigi needs to level up on his skills...

aburtch, to infosec
@aburtch@triangletoot.party avatar

Boost if your parent or grandparent keeps a physical printed out list of all the usernames and passwords for various websites and software applications.

thakshiladamsak, (edited ) to illustration

Website login screen illustration.
Made using Inkscape.

Download SVG - https://bit.ly/loginsvg (watermark becomes nearly invisible after download. You can also remove it using Inkscape or something.)

Original Upload - 11/12/2022

pacenoge, to privacy

Amankan Password Kalian! 🔐

  1. Syarat 🚨
    Password harus memenuhi syarat2 sebagai berikut:
  • Minimal 8 karakter
  • Kombinasi huruf besar kecil, angka & karakter spesial
  • Buat password dengan kata2 yang unik
  • Jangan gunakan tanggal lahir, kota domisili, nama anak, nama ortu, nomor telepon dll yang mudah ditebak

Contoh:
P3m@d4m_Ke8ak4raN!
Urc8M|W87BY%Dd@K

  1. Password Manager 🚧
    Jika syarat2 diatas dianggap susah/ribet, kalian bisa gunakan password manager untuk menyimpan password2 yang ribet itu. Password manager bisa autofill user pass sesuai dengan apa yang kita simpan. Bisa juga untuk generate password yang secure.

Macam2 password manager antara lain:

  • 1Password
  • Bitwarden (open source)
  • Dashlane
  • Keeper
  • NordPass
  • Enpass
  • KeePass (open source)
  1. Ekstra 🔑
  • Jika memungkinkan, ganti password secara berkala
  • Jangan tulis/simpan password dinotepad
  • Jangan tulis & tempel password dimonitor kantor
  • Jangan gunakan satu password untuk semua akun online

@indonesia

summeremacs, to macos
@summeremacs@fashionsocial.host avatar

I want to thank everyone who has replied so far to my post about a password app for MacOS and iOS. I haven't had the time to reply to everyone because I'm super busy for the next few days, through the weekend, but I have saved all of the links you have sent to me into an org-mode project in Emacs to review later on. 🙃

summeremacs, to foss
@summeremacs@fashionsocial.host avatar

One more post I've been looking to replace 1Password with something more friendly. So, it has to be on Mac AND iOS, it has to have Face/TouchID, and it should do iCloud sync as well as syncthing or another. Can contain more than passwords (like files)

I found AuthPass: https://authpass.app

I haven't tried it yet, so I'm appealing to some Mac people out there: Do you guys know? Is it any good? Is it here to stay? Does it do these things? Opinions?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • slotface
  • ngwrru68w68
  • everett
  • mdbf
  • modclub
  • rosin
  • khanakhh
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Youngstown
  • GTA5RPClips
  • InstantRegret
  • provamag3
  • kavyap
  • ethstaker
  • osvaldo12
  • normalnudes
  • tacticalgear
  • cisconetworking
  • cubers
  • Durango
  • Leos
  • anitta
  • tester
  • megavids
  • lostlight
  • All magazines