Tumgik
#Password Managers
melyzard · 5 months
Text
Okay, look, they talk to a Google rep in some of the video clips, but I give it a pass because this FREE course is a good baseline for personal internet safety that so many people just do not seem to have anymore. It's done in short video clip and article format (the videos average about a minute and a half). This is some super basic stuff like "What is PII and why you shouldn't put it on your twitter" and "what is a phishing scam?" Or "what is the difference between HTTP and HTTPS and why do you care?"
It's worrying to me how many people I meet or see online who just do not know even these absolute basic things, who are at constant risk of being scammed or hacked and losing everything. People who barely know how to turn their own computers on because corporations have made everything a proprietary app or exclusive hardware option that you must pay constant fees just to use. Especially young, somewhat isolated people who have never known a different world and don't realize they are being conditioned to be metaphorical prey animals in the digital landscape.
Anyway, this isn't the best internet safety course but it's free and easy to access. Gotta start somewhere.
Here's another short, easy, free online course about personal cyber security (GCFGlobal.org Introduction to Internet Safety)
Bonus videos:
youtube
(Jul 13, 2023, runtime 15:29)
"He didn't have anything to hide, he didn't do anything wrong, anything illegal, and yet he was still punished."
youtube
(Apr 20, 2023; runtime 9:24 minutes)
"At least 60% use their name or date of birth as a password, and that's something you should never do."
youtube
(March 4, 2020, runtime 11:18 minutes)
"Crossing the road safely is a basic life skill that every parent teaches their kids. I believe that cyber skills are the 21st century equivalent of road safety in the 20th century."
156 notes · View notes
andmaybegayer · 11 months
Note
can you actually talk about bitwarden / password managers, or direct me to a post about them? Idk my (completely uneducated) instinct says that trusting one application with all your passwords is about as bad as having the same password for everything, but clearly that isn’t the case.
So it is true that online password managers present a big juicy target, and if you have very stringent security requirements you'd be better off with an offline password manager that is not exposed to attack.
However, for most people the alternative is "reusing the same password/closely related password patterns for everything", the risk that one random site gets compromised is much higher than the risk that a highly security focussed password provider gets compromised.
Which is not to say it can't happen, LastPass gets hacked alarmingly often, but most online password managers do their due diligence. I am more willing to stash my passwords with 1Password or Bitwarden or Dashlane than I am to go through the rigamarole of self-managing an array of unique passwords across multiple devices.
Bitwarden and other password managers try to store only an encrypted copy of your password vault, and they take steps to ensure you never ever send them your decryption key. When you want a password, you ask them for your vault, you decrypt it with your key, and now you have a local decrypted copy without ever sending your key to anyone. If you make changes, you make them locally and send back an encrypted updated vault.
As a result, someone who hacks Bitwarden should in the absolute worst case get a pile of encrypted vaults, but without each individuals' decryption key those vaults are useless. They'd still have to go around decrypting each vault one by one. Combining a good encryption algorithm, robust salting, and a decent key, you can easily get a vault to "taking the full lifetime of the universe" levels on security against modern cryptographic attacks.
Now there can be issues with this. Auto-fill can be attacked if you go onto a malicious website, poorly coded managers can leak information or accidentally include logging of passwords when they shouldn't, and obviously you don't know that 1Password isn't backdoored by the CIA/Mossad/Vatican. If these are concerns then you shouldn't trust online password managers, and you should use something where you remain in control of your vault and only ever manually handle your password.
Bitwarden is open source and fairly regularly audited, so you can be somewhat assured that they're not compromised. If you are worried about that, you can use something like KeePassXC/GNU Pass/Himitsu/ (which all hand you the vault file and it's your job to keep track of it and keep it safe) or use clever cryptographic methods (like instead of storing a password you use a secret key to encrypt and hash a reproducible code and use that as your password, e.g. my netflix password could be hash(crypt("netflixkalium", MySecretKey)), I know a few people who use that method.
Now with any luck because Apple is pushing for passkeys (which is just a nice name for a family of cryptographic verification systems that includes FIDO2/Webauthn) we can slowly move away from the nightmare that is passwords altogether with some kind of user friendly public key based verification, but it'll be a few years before that takes off. Seriously the real issue with a password is that with normal implementations every time you want to use it you have to send your ultra secret password over the internet to the verifying party.
238 notes · View notes
drnic1 · 7 months
Text
LinkedIn Hacker Mayhem
Automated Security Challenges – Photo Credit Gizmodo Should You Panic or Stay Calm? It could just be me but I doubt it. I’ve certainly had my share of attempts to attack my accounts including the SIM Jacking I documented (3 Minutes to Financial Ruin). But since the vast majority of these attacks are automated with the perpetrators using tools that essentially automate the tasks of attacking…
Tumblr media
View On WordPress
0 notes
robpegoraro · 11 months
Text
Weekly output: World Mobile, IRS Direct File, Mozilla Creep-O-Meter, 5G ambitions at small carriers (x2), eSIM strategies, Dashlane
This week took me to Atlanta and back to moderate two panels at the Competitive Carriers Association’s conference there, with that group of regional wireless carriers picking up my airfare and lodging. This trip also yielded my first Atlanta dateline since a 1998 Washington Post recap of the Electronic Entertainment Expo and added a new transit stored-value card to my collection. 10/16/2023:…
View On WordPress
0 notes
halogalopaghost · 6 months
Text
TIL that you can assign an AO3 next of kin to control your account in case of your death???
Tumblr media
3K notes · View notes
Note
Checked with the expert friend, Roboform is the best affordable one, the free version only works on one device though ( i use it, 18USD for a year, which is cheap, but 18 USD more than most of us can afford lol)
Workaround for LastPass - check https haveibeenpwned com weekly (set up a reminder for yourself or make it part of your routine, i do it on household cleaning day so that i have all my chores done on the same day and don't overwhelm myself with responsibility)
Thank you!!! I will definitely look into this!
0 notes
swampthingking · 6 months
Text
andrew’s definitely gotten in trouble with his pr manager for tweeting things along the lines of:
“no mania inducing medication will compare to the euphoria i will feel the day donald trump drops dead”
#pr manager is like: andrew… this is the last time i’m gonna tell you#andrew: whats the point of democracy if i can’t exercise freedom of speech#pr manager: andrew it’s no longer about your image#at this point we are concerned the fbi is going to show up#andrew: neil has connections. i’m fine#they thought marketing andrew on social media would be good#they were sooooo wrong#because now andrew has a place to share every insane thing he’s ever thought#for instance—a tweet that just says ‘an alien googling: human clothes’#he’s on there advocating for lgbtq+ youth you KNOW HE IS#he’s cursing and mildly threatening members of congress for imposing these disgusting bills#one day he tweeted ‘does mitch mcconnell know he’s dead yet’#when mitch mcconnell stepped down from senate andrew tweeted ‘hopefully next he steps down from life’#unsurprisingly: this endears him to some people and makes others fucking hate him#and he’s such a shit. he does not care either way#he’s kind of just like: pr manager. you gave me a twitter and told me to tweet. i’m just doing what you asked me#they’ve threatened to change his password so many times#they actually did once but andrew reported the account so many times for defamation and fraud that it got suspended#and he made a new account out of pure spite#his pr manager is like: andrew nobody is going to want to sign you because of your public image#and andrew is like: ?? ok. they can lose every game then#(he knows he’s the best goalie)#ok i think that’s enough for now. however i will probably be back#andrew minyard#aftg#tfc#trk#tkm#the foxhole court#all for the game
400 notes · View notes
aro-culture-is · 9 months
Note
Aro culture is the amount of ads i get for dating apps whenever i go anywhere near the internet
.
70 notes · View notes
peteytheparrot · 6 months
Text
Y’all ok remember that game Prodigy? The math game?
so my brother sent me a really old screenshot with no context
Tumblr media
Which looks fine but then
there’s this in the corner
Tumblr media
WHAT THE FUCK IS THIS
FUCKING SCREAMING???? LIKE WHAT KIND OF EASTER EGG IS THIS DOES ANYONE HAVE ANY EXPLANATION FOR THIS ☠️☠️☠️☠️☠️☠️
it’s in the crystal caverns place,,,,, I was thinking of replaying that place again to see if it’s still there 🫡
30 notes · View notes
Text
yesterday i turned 30 so unfortunately i must commit seppuku and delete my blog
108 notes · View notes
dr-veritas-ratio · 5 months
Note
hows the tutor with uhh stelle :33?
Guess who stole someone's phone~
THAT'S RIGHT. IT'S ME, STELLE.
YOU THOUGHT YOU COULD CONFISCATE MY PHONE JUST LIKE THAT, HUH???
28 notes · View notes
andmaybegayer · 2 years
Text
reminder that if, like me, you used to use LastPass and moved to a new password manager, go delete your LastPass account.
33 notes · View notes
Text
what if You wanted to "post on kofi", but Kofi said "log in"
38 notes · View notes
robpegoraro · 2 years
Text
Weekly output: Samsung self-repair, FCC chair's security concerns, tech-policy forecast, password managers, Google layoffs, electric-car progress, legal risks for security research
This week had me head into D.C. for work events four days in a row, something that last happened in early 2020. 1/17/2023: Samsung ‘Self-Repair’ Program Adds Galaxy S22 Phones, Some Galaxy Books, PCMag The post I wrote after Samsung gave me an advance copy of their press release noted the limited number of replacement parts offered under this program, but Technica’s Ron Amadeo–who has a lot more…
Tumblr media
View On WordPress
1 note · View note
ellenent · 2 years
Text
Tumblr media
the new valentine color is real aaaa <3 here a valentine Aisha, I want one so bad
181 notes · View notes
thatoneluckybee · 5 months
Text
HI HOW DO I CONVINCE WORLD'S STRICTEST PARENTS TO CHANGE A RULE LIKE. NOW?
12 notes · View notes