Earlier quoted context omitted.
It absolutely blows my mind that people are okay with giving their passwords (encrypted or not, see this very breach for why that's not always enough) to a 3rd party, but are not okay reusing a password somewhere. If 1Password ever got owned, the Internet would be severely fucked. And to stem the potential flood a bit, I realize there are plenty of good counterargument built up over the years to try and combat this g…
Using a strong key and cipher, you should feel safe giving anyone your information.
The Dropbox hack is real
351–360 of 557 posts
Re: The Dropbox hack is real
#352Earlier quoted context omitted.
> On a side note, don't forget the time dropbox accepted ANY password during logins - http://www.cnet.com/news/dropbox-confirms-security-glitch-no... I've not forgotten, and this glitch has kept me from ever considering opening a Dropbox account. I'm surprised everyone else seems so forgiving of this massive screw up.
Totally. You wanna talk about people forgetting? It seems everyone has totally forgotten (or forgiven) that Dropbox was mentioned specifically in the Snowden leaks as a source.
Re: The Dropbox hack is real
#353Earlier quoted context omitted.
Totally. You wanna talk about people forgetting? It seems everyone has totally forgotten (or forgiven) that Dropbox was mentioned specifically in the Snowden leaks as a source.
are there better alternatives though?
Re: The Dropbox hack is real
#354Earlier quoted context omitted.
1Password is well worth the money. It is well designed for both desktop and mobile and I am happy to pay for software that I use every day.
It absolutely blows my mind that people are okay with giving their passwords (encrypted or not, see this very breach for why that's not always enough) to a 3rd party, but are not okay reusing a password somewhere. If 1Password ever got owned, the Internet would be severely fucked. And to stem the potential flood a bit, I realize there are plenty of good counterargument built up over the years to try and combat this g…
Re: The Dropbox hack is real
#355Earlier quoted context omitted.
Totally. You wanna talk about people forgetting? It seems everyone has totally forgotten (or forgiven) that Dropbox was mentioned specifically in the Snowden leaks as a source.
are there better alternatives though?
Alternatives, though? Plenty: Google Drive, Box, OneDrive, iCloud Backup and iCloud Drive.. the list goes on with a simple Google search for "online storage"
Re: The Dropbox hack is real
#356Earlier quoted context omitted.
I used to do this before switching to a password manager; the problem with pattern-based passwords is that while in paper it sounds better than password reuse (unique passwords for each site/service while still being able to remember them, yay!) in practice you are still using the same pattern for all of them. A potential smart adversary could figure out the pattern used and then apply it to every site/service much l…
Right. But the idea does take advantage of the fact that some kinds of patterns are more obvious to humans and some to machines. Most people's threat model is a massive data breach rather than a determined single attacker focused on them who actually uses a smart human brain to analyze the passwords.
Most password leverage comes from breaches and people running larger scale operations for scamming and spamming.
Re: The Dropbox hack is real
#357Since lots of people will be rotating passwords, this is probably a good time to set up Two-Factor Authentication (2FA) as well. I recommend Authy as your 2FA app, as it lets you set a backup password, which you can use to move your 2FA tokens between devices. For your critical services, keeping encrypted copies of your backup codes is a must.
I also recommend authy. Makes 2fa slightly less painful. Not a fault of authy, but namecheap and paypal both don't offer support. I'm especially angry at namecheap because their homegrown 2fa solution is unreliable. Especially when travelling. I'm considering leaving them agter 4 years of promises to support authy but nothing!
https://www.namecheap.com/support/knowledgebase/article.aspx...
FWIW, Gandi.net supports TOTP, but their prices are a bit higher. However if you only own a handful of domains, the $20/year difference won't really matter.
Re: The Dropbox hack is real
#358Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.
Not sure if 1Password does as well, but it seems like a fairly obvious feature to add.
Re: The Dropbox hack is real
#359Earlier quoted context omitted.
If you're using a password manager, that's a non-issue. And until we have something better than passwords, you really should be using one.
That's a solid point. I've generally avoided password managers because not knowing my (unique-per-service, strong) passwords makes me nervous in exactly the same way as not actually knowing the phone numbers of the most important N people in my life.
What's important is to keep a backup of your password database in a few places. I use KeePass because I have no desire to keep passwords, encrypted or not, in a cloud service. I also don't find value in browser integration (possible attack vector?). I'm generally very DIY-inclined anyway. Your preferences may vary.
Re: The Dropbox hack is real
#360Earlier quoted context omitted.
But not every website out there allows you to enter this as a valid email address. My earlier hypothesis was that this was on purpose, to make sure you don't use a filter on any email they might send. But these days I'm tending to think it's just a bad regexp on their side.
Even worse, some sites let you enter a plus address initially but that address will not work in some account management pages. I had an instance where I signed up to a pizza place with such an address and I could not unsubscribe or edit my mail preferences because of it.