jeancf · @jeancf
286 followers · 688 posts · Server noc.social
Joe Ortiz · @joeo10
439 followers · 6027 posts · Server mastodon.sdf.org

Wow, the fiasco looks even worse now that the people responsible for it's hack has cracked some of the stolen vault keys. More in this piece from @briankrebs: krebsonsecurity.com/2023/09/ex

And here's the accompanying thread infosec.exchange/@briankrebs/1

It's another example into why you should only rely on offline solutions when picking a password manager, such as and/or

#lastpass #keepass #keepassxc #keepassdx #strongbox #passwords #passwordmanager

Last updated 2 years ago

Lee Hord · @leehord
6 followers · 91 posts · Server mas.to

Finally migrated from 1Password to iCloud Keychain and I’ll can already see the benefits. Password and 2FA auto-filling is so much less clunkier. Don’t get me wrong I used to love 1Password, but recent successive releases have become increasingly unreliable, particularly the browser extensions. If you’ve been on the fence about switching I can confirm all is good.

#2fa #passwords #1password #icloudkeychain

Last updated 2 years ago

Osman · @osman
132 followers · 86 posts · Server hachyderm.io

#security #passwords

Last updated 2 years ago

AI6YR · @ai6yr
4770 followers · 32833 posts · Server m.ai6yr.org

Brian Krebs: "a steady trickle of six-figure cryptocurrency heists targeting security-conscious people throughout the tech industry has led some security experts to conclude that crooks likely have succeeded at cracking open some of the stolen LastPass vaults." infosec.exchange/@briankrebs/1

#lastpass #cybersecurity #passwords #encryption

Last updated 2 years ago

a "sophisticated" social engineering attack... LoL 🤪🤪

#cybersecurity #ciberawareness #lol #passwords

Last updated 2 years ago

PrivacyDigest · @PrivacyDigest
569 followers · 2161 posts · Server mas.to

confirms massive impacting 7 million users
The stolen information includes usernames, User IDs, email addresses, and MD5-hashed passwords, with no other information exposed, according to Freecycle.
bleepingcomputer.com/news/secu
MD5 hashed , ugh, is it still 1999?

#freecycle #databreach #passwords

Last updated 2 years ago

Philipp Waldhauer · @pwa
338 followers · 720 posts · Server norden.social

Ich muss ja zugeben, dass ich eine sehr lange Zeit über ziemlich viele Passwörter im Chrome Password Manager speicherte, weil es einfach so komfortabel war. Mittlerweile funktioniert die 1Password-Extension aber doch irgendwie nochmal besser und ich werde wohl mal versuchen alles zu konsolidieren.

#security #passwords #1password

Last updated 2 years ago

Joshua McNeill · @joshisanonymous
148 followers · 488 posts · Server h4.io

I feel like we need a better system for recovering lost tokens since saving a recovery code is the same as having a password and saving SMS/email info as alternatives defeats the purpose of 2FA...

#2fa #internet #internetsecurity #passwords

Last updated 2 years ago

HamsterBoomer · @hamsterboomer
3 followers · 240 posts · Server sfba.social

This Chrome extension can steal your passwords - and Google has no problem with it | TechRadar techradar.com/pro/security/thi

#google #chrome #passwords

Last updated 2 years ago

Aaron Toponce ⚛️:debian: · @atoponce
2496 followers · 5073 posts · Server fosstodon.org

Fantastic read on 25 years later, by Niels Provos, one of its creators.

blog.apnic.net/2023/08/02/bcry

#bcrypt #passwords

Last updated 2 years ago

Scott Jenson · @scottjenson
3104 followers · 2194 posts · Server social.coop

NIST has revised their guidelines on password restrictions. These were the guys back in 2003 that said at least 8 chars, 1 upper case, one number, one special char. Study after study has shown that this rule makes passwords less secure (read the article). But everyone keeps using this old antiquated rule.

Has anyone had any success in getting their team to stop doing this?
auth0.com/blog/dont-pass-on-th

#ux #passwords

Last updated 2 years ago

Aaron Toponce ⚛️:debian: · @atoponce
2497 followers · 5070 posts · Server fosstodon.org
Aaron Toponce ⚛️:debian: · @atoponce
2495 followers · 5064 posts · Server fosstodon.org

Damien Miller has added timing keystroke obfuscation to .

The advantage here is making it more difficult for a MITM to detect valid keystrokes out of the client, such as authenticating with .

undeadly.org/cgi?action=articl

#openssh #passwords #gnu #linux #unix #bsd

Last updated 2 years ago

Aaron Toponce ⚛️:debian: · @atoponce
2495 followers · 5064 posts · Server fosstodon.org

Actually, I don't hate this. I mean, it's maybe a touch over-the-top, but not much.

Setting up my account at gitlab.gnome.org.

#passwords

Last updated 2 years ago

Mr.Trunk · @mrtrunk
10 followers · 18331 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
10 followers · 18172 posts · Server dromedary.seedoubleyou.me

Raise your hand if you have never used TOO easy credentials and passwords for your accounts, applications and demos. This interesting article from @bitwarden presents some hints for changing habits and getting your employees and contractors to change them as well bitwarden.com/blog/how-to-moti

#passwords #security #accounts

Last updated 2 years ago