Bitwarden · @bitwarden
14183 followers · 911 posts · Server fosstodon.org

Protect your sensitive information with end-to-end encryption and enjoy the benefits of a centralized, secure solution. Get started today: bitwarden.com/products/secrets

#SecretsManagement #cybersecurity #security #datasecurity #secretsmanager

Last updated 1 year ago

Luka Manestar · @rusty1281
65 followers · 535 posts · Server fosstodon.org

@portainerio Hi there! Any plans in the future to support upcoming @bitwarden

Tnx!

#secretsmanager

Last updated 1 year ago

Bitwarden · @bitwarden
13307 followers · 856 posts · Server fosstodon.org

Get an introduction to the secrets management industry and the challenges that shaped it in this quick guide: bitwarden.com/resources/presen

#developer #cybersecurity #security #datasecurity #secretsmanager

Last updated 1 year ago

Ijohnson · @Ijohnson
5 followers · 40 posts · Server noc.social

Upon prompting from my buddy at GH, wanted to check out Access using Connect (OIDC). Today, I covered setting up federated to , and . In all three cases, I tackled secrets using , and , respectively. The key feature of OIDC is the use of OAuth flow; meaning no persisted Access Secret needs to be in your for access. freshbrewed.science/2023/02/09

#cloud #ci #secretsmanager #parameterstore #AKV #gcp #aws #azure #oidc #openid #GitHub

Last updated 2 years ago

Justin Pagano · @p4gs
59 followers · 160 posts · Server infosec.exchange

Last night as I was finishing part 2 of my blog post series "Protecting against a password manager breach" (justinpagano.substack.com/p/pr), I saw the news that LastPass had updated their security incident notification stating that customer data had been obtained by attackers, including encrypted password vault data (blog.lastpass.com/2022/12/noti)

While they did a good job explaining the nuances of which of their customers are most vs. least at risk of their decrypted vault data being accessed, I think they are a little too overconfident in their implementation of PBKDF2 to protect their customers against offline brute-force attacks against their encrypted vault data, as Dan Goodin from ArsTechnica explains in his article here: arstechnica.com/information-te

So I guess now is as good time as any to check out the hot-off-the-presses part 2 of my blog post series where I go over specific steps to take to ensure online accounts are protected in the event of a password manager breach (or really any kind of compromise of your passwords): justinpagano.substack.com/p/pr

If you're lazy (i.e. "efficient") and just want the checklist that's in the guide, you can check it out in GitHub here: github.com/p4gs/online-account

#passwordmanager #passwordvault #lastpass #data #breach #1password #bitwarden #authy #yubikey #webauthn #Passkey #mfa #2fa #credentials #vault #secretsmanager

Last updated 2 years ago

Justin Pagano · @p4gs
44 followers · 131 posts · Server infosec.exchange

Last night as I was finishing part 2 of my blog post series "Protecting against a password manager breach", I saw the news that LastPass had updated their security incident notification stating that customer data had been obtained by attackers, including encrypted password vault data (lnkd.in/eHCx3xyq)

While they did a good job explaining the nuances of which of their customers are most vs. least at risk of their decrypted vault data being accessed, I think they are a little too overconfident in their implementation of PBKDF2 to protect their customers against offline brute-force attacks against their encrypted vault data, as Dan Goodin from ArsTechnica explains in his article here: lnkd.in/enx5U7dY

So I guess now is as good time as any to check out the hot-off-the-presses part 2 of my blog post series where I go over specific steps to take to ensure online accounts are protected in the event of a password manager breach (or really any kind of compromise of your passwords): lnkd.in/emazfY47

If you're lazy (i.e. "efficient") and just want the checklist that's in the guide, you can check it out in GitHub here: lnkd.in/eRNXKKDC

#passwordmanager #passwordvault #lastpass #data #breach #1password #bitwarden #authy #yubikey #webauthn #Passkey #mfa #2fa #credentials #vault #secretsmanager

Last updated 2 years ago