Noah · @knoawyls
120 followers · 599 posts · Server metalhead.club

Steve's Next Password Manager After the LastPass Hack - On Security Now, Steve Gibson shares with Leo Laporte his plan in the shadow of the devastating LastPass hack and which password manager he plans to use next. - youtu.be/9XWHCF4pLmI

#securitynow #leolaporte #stevegibson #applekeychain #passwordmanager #passwordvault #1password #bitwarden #dashlane #twit #lastpass

Last updated 2 years ago

James Harris · @DawnPaladin
151 followers · 752 posts · Server toot.cafe

If you're affected by the data breach, I have a full walkthrough for how to set up a local password vault and sync it between computers, including your phone. jamesharris.design/blog/Harden

#decentralization #keepass #passwordvault #keepassxc #lastpass

Last updated 2 years ago

Justin Pagano · @p4gs
59 followers · 160 posts · Server infosec.exchange

Last night as I was finishing part 2 of my blog post series "Protecting against a password manager breach" (justinpagano.substack.com/p/pr), I saw the news that LastPass had updated their security incident notification stating that customer data had been obtained by attackers, including encrypted password vault data (blog.lastpass.com/2022/12/noti)

While they did a good job explaining the nuances of which of their customers are most vs. least at risk of their decrypted vault data being accessed, I think they are a little too overconfident in their implementation of PBKDF2 to protect their customers against offline brute-force attacks against their encrypted vault data, as Dan Goodin from ArsTechnica explains in his article here: arstechnica.com/information-te

So I guess now is as good time as any to check out the hot-off-the-presses part 2 of my blog post series where I go over specific steps to take to ensure online accounts are protected in the event of a password manager breach (or really any kind of compromise of your passwords): justinpagano.substack.com/p/pr

If you're lazy (i.e. "efficient") and just want the checklist that's in the guide, you can check it out in GitHub here: github.com/p4gs/online-account

#passwordmanager #passwordvault #lastpass #data #breach #1password #bitwarden #authy #yubikey #webauthn #Passkey #mfa #2fa #credentials #vault #secretsmanager

Last updated 2 years ago

Justin Pagano · @p4gs
44 followers · 131 posts · Server infosec.exchange

Last night as I was finishing part 2 of my blog post series "Protecting against a password manager breach", I saw the news that LastPass had updated their security incident notification stating that customer data had been obtained by attackers, including encrypted password vault data (lnkd.in/eHCx3xyq)

While they did a good job explaining the nuances of which of their customers are most vs. least at risk of their decrypted vault data being accessed, I think they are a little too overconfident in their implementation of PBKDF2 to protect their customers against offline brute-force attacks against their encrypted vault data, as Dan Goodin from ArsTechnica explains in his article here: lnkd.in/enx5U7dY

So I guess now is as good time as any to check out the hot-off-the-presses part 2 of my blog post series where I go over specific steps to take to ensure online accounts are protected in the event of a password manager breach (or really any kind of compromise of your passwords): lnkd.in/emazfY47

If you're lazy (i.e. "efficient") and just want the checklist that's in the guide, you can check it out in GitHub here: lnkd.in/eRNXKKDC

#passwordmanager #passwordvault #lastpass #data #breach #1password #bitwarden #authy #yubikey #webauthn #Passkey #mfa #2fa #credentials #vault #secretsmanager

Last updated 2 years ago

Justin Pagano · @p4gs
29 followers · 101 posts · Server infosec.exchange

In light of the recent breaches of LastPass’ infrastructure systems, I've been thinking:

What would happen if the data in my password manager were successfully breached?

And what can I do right now to reduce the impact of such a breach?

If you've ever wondered the same thing but have never come across a satisfying answer, well, do I have some Thought Leadership™ for you!

justinpagano.substack.com/p/pr

#passwordsecurity #passwordmanager #passwordvault #lastpass #1password #bitwarden #authy #yubikey #Passkey #yubico #mfa #2fa #multifactorauthentication #twofactorauthentication #securityarchitecture

Last updated 2 years ago

olav · @olav
35 followers · 195 posts · Server bonn.social

I have started to port to the . Ultimately, I hope to get a nice platform for my project.

#uxn #WioTerminal #passwordvault

Last updated 3 years ago

olav · @olav
35 followers · 195 posts · Server bonn.social

V1.10 meines Passwortmanagers auf ist raus und supereinfach zu installieren: github.com/PasswordVault/passw

#passwordvault #WioTerminal

Last updated 4 years ago

Chris :fedora: :flag_nl: · @RyuKurisu
339 followers · 8545 posts · Server fosstodon.org

@eff we've got a nice selection of password vaults, but none that can automatically change your in case of breach or other emergencies as far as I'm aware of. It is something that the can do, so how likely is it that there will be open source software that also has this ability? vs

#opensource #passwords #proprietary #lastpass #passwordvault #passwordmanager

Last updated 7 years ago