Gonçalo Valério · @dethos
333 followers · 1413 posts · Server s.ovalerio.net
Kevin Karhan :verified: · @kkarhan
1337 followers · 92578 posts · Server mstdn.social

@roywig @thatandromeda @leak it is "good enough", cuz we ain't 15 years ago where eberything needed archaic commands.

integrates / out of the box for some time.
& do support - and like are so easy, it literally took me 5 minutes to explain the use and setup a complete in it.

People aren't stupid, they are lazy and get groomed into being ...

That is the problem!

#consoomers #techilliterate #noob #Enpass #passwordmanagers #omemo #XMPP #monocleschat #Gaijim #gnupg #openpgp #Thunderbird

Last updated 2 years ago

Kevin Karhan :verified: · @kkarhan
1335 followers · 92247 posts · Server mstdn.social

@leak that's what are for...

#passwordmanagers

Last updated 2 years ago

· @MHowell
69 followers · 1103 posts · Server kolektiva.social

@bitwarden Not until your programmers solve this problem that other seem to have solved:
Rather than autofill, BW mobile app requires a second unnecessary authentication.

#passwordmanagers

Last updated 2 years ago

Tech news from Canada · @TechNews
692 followers · 20728 posts · Server mastodon.roitsystems.ca
Kevin Karhan :verified: · @kkarhan
1167 followers · 78388 posts · Server mstdn.social

@ShadSterling @nzakas well, I just block all but whitelisted Cookies and JS.

And Yes, is a problem in general...

Needless to say users can't be made liable for shitty of the company who's website they log in.

Point is: are the most secure option - period.

#passwordmanagers #ITSec #cryptojacking

Last updated 2 years ago

Kevin Karhan :verified: · @kkarhan
1167 followers · 78393 posts · Server mstdn.social

@nzakas it's an -Feature since it prevents people from using , resulting in weaker Passwords like:

Idonthavetimef0rthis$it!

instead of some solid password generated with cryptographic randomness...

Like a 128-digit password...
github.com/kkarhan/misc-script

#passwordmanagers #antisecurity

Last updated 2 years ago

Jonathan Kamens · @jik
564 followers · 2759 posts · Server federate.social

You should be backing up your password manager

It's a bad idea to entirely rely on the company hosting your password manager to back up your data.

blog.kamens.us/2023/06/26/you-

#computersecurity #computers #freesoftware #InformationSecurity #infosec #passwordmanagers

Last updated 2 years ago

mkj · @mkj
82 followers · 1558 posts · Server social.linux.pizza

@secbox Typical spreadsheet applications are NOT made for handling secrets, and there's a good chance that they'll litter plaintext temporary copies all over the place.

If you want to keep the TOTP secrets separate from your other account details, then at least use something that is designed and intended to handle secrets. I think most can store secrets, for example. Put them in a separate vault/file/database/refrigerator if you want & put a solid passphrase on that one.

#passwordmanagers #totp

Last updated 2 years ago

Kevin Karhan :verified: · @kkarhan
1019 followers · 62551 posts · Server mstdn.social

@kura once should be enough.

People should use anyway...

#passwordmanagers

Last updated 2 years ago

Kevin Karhan :verified: · @kkarhan
1017 followers · 62596 posts · Server mstdn.social

@zens
And worst of all:

- Ableist and preventing the use of is the biggest asshole move one can do - aside from preventing non- use in - like and

# Don't block or discriminate against @torproject users at all. If you want them to securely connect to your site [i.e. for logins], make an where every user will have their own & unique at runtime!

#circuit #onionservice #lynx #browsers #screenreader #JavaScript #passwordmanagers #captchas

Last updated 2 years ago

Gonçalo Valério · @dethos
309 followers · 1322 posts · Server s.ovalerio.net

"In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running."

github.com/vdohney/keepass-pas

KeePassXC (while the name is similar) is a different product, and doesn't seem to be affected.

#passwordmanagers #infosec #keepass #security

Last updated 2 years ago

Adam · @adam
346 followers · 813 posts · Server hax0rbana.social

I the file for the . If I did it right, it means I will be able to build using components that are actually available once I get the new boards.

Of course, not wanting anything to go to waste, I'm still planning on sourcing the elusive voltage regulators to build out the boards I have now.

I'm going to order some new boards this week. Exciting progress (assuming I didn't mess anything up).

#hacked #cad #signet #pcb #hardware #passwordmanagers

Last updated 2 years ago

Gonçalo Valério · @dethos
306 followers · 1295 posts · Server s.ovalerio.net
mkj · @mkj
45 followers · 632 posts · Server social.linux.pizza

@kubikpixel @Stark9837 doesn't get better because you use a library someone else has written to implement the .

Salted slow for passwords, yes. (Again, with the exception of where passwords really need to be stored securely in a reversible fashion.) But then you still aren't doing , you're doing , which was the point of my previous post.

#encrypting #passwords #encryption #hashing #passwordmanagers

Last updated 2 years ago

mkj · @mkj
45 followers · 632 posts · Server social.linux.pizza

@Stark9837 Passwords should never be stored encrypted. (The one exception being .) There is no legitimate reason to store passwords encrypted. Any service which encrypts, rather than hashes, should be treated as highly suspect.

I know a lot of people don't know the difference, but there is a HUGE one.

is by definition reversible.

is irreversible (if done right).

That said, I absolutely agree that every should be random and unique.

#passwordmanagers #encryption #passwords #hashing #password

Last updated 2 years ago

RonaldTooTall · @RonaldTooTall
203 followers · 270 posts · Server universeodon.com

There are several good options. I strongly recommend one that doesn't backup or store anything in the cloud and that also syncs between your devices.

wired.com/story/best-password-

#apps #programs #passwordmanagers #security #technology

Last updated 2 years ago

Doug · @doug
34 followers · 181 posts · Server mejia.social

Need a password manager? Check out these five that were reviewed by Wired Security..

wired.com/story/best-password-

#security #passwordmanagers #wired

Last updated 2 years ago

Trisha Clay (she/her) · @trisha_m_clay
77 followers · 288 posts · Server infosec.exchange

Hackers can steal your username and password for a website using an embedded iframe - Bitwarden elected not to address the issue techspot.com/news/97951-bitwar

#passwordmanagers

Last updated 2 years ago

Gonçalo Valério · @dethos
305 followers · 1269 posts · Server s.ovalerio.net