Live data from Hacker News

How to encrypt your entire life in less than an hour

medium.freecodecamp.com

21–30 of 70 posts

Re: How to encrypt your entire life in less than an hour

#21

I would also add another tip: create a separate email to use for financial accounts. Don't use this email for anything else.

Can you elaborate on why.

So that your shop doesn't mess your bank.

(Shops are regularly hacked with leak of email addresses and possibly compromising passwords.)

Re: How to encrypt your entire life in less than an hour

#23

I am not 100% sold on one particular password manager. Any hints/suggestions?

I like Keepass becuase it is not tied to any ongoing subscriptions or providers. You can use the file sync tool of your choice to distribute your file. The downside/feature is not having tight browser/app integration.

Re: How to encrypt your entire life in less than an hour

#25

I am not 100% sold on one particular password manager. Any hints/suggestions?

Personally I like keepass. I don't love it, and it's UI could definitely use some work, but it suites my needs fairly well.

I also use Keepass[x]! The issue that I see people facing is that it isn't multi-device (it's an offline password manager). For me, that is the selling point though.

Re: How to encrypt your entire life in less than an hour

#26
post #19

If you're being specifically targeted by a sufficiently capable adversary, this is, at best, a speed bump. Categorize your levels of paranoia appropriately.

I really wonder if intelligence services are paid to demoralize user groups when I see posts like this.

If you do all these things, your resistance to even NSA-level incriminating evidence goes WAY down, and your vulnerability to local LEO and hackers goes to near-zero.

This is, at best, a brick wall, through which an adversary would have to bulldoze.

Re: How to encrypt your entire life in less than an hour

#27
post #8
post #4

Isn't 2FA considered dangerous now? We've seen how susceptible it can be to social engineering. On a related note, I noticed that my Windows Phone displays text message notifications even when it's locked... So adding a PIN doesn't prevent an attacker from doing 2FA if they have access to my phone.

SMS 2FA isn't safe at least, and even NIST is deprecating it. The rest depends on dumb implementations, like Paypal allowing 2FA bypass with a change of the login link, or Google allowing 2FA bypass of all of its other methods by forcing you to use a phone number as "backup", which is to 2FA what secret questions were to passwords (their Achilles's heel).

Secret questions are horrible when they're predefined, and what's worse is when the options are also predefined (e.g. United Airline's website).

However a secret question like "who did you have a crush on back in 5th grade" is limited to maybe 10 people the world who know and I'm comfortable with that (of course this changes with the over-publicising of our lives on social media).

But I'm digressing and agree TOTOP 2FA is great for the masses. Just be sure to have the backup codes stored in a safe space.

Re: How to encrypt your entire life in less than an hour

#28
The article is very slightly more nuanced but the conceptss the title purports is DANGEROUSLY INCOMPETENT for any security expert / discussion / context.

1) idea that security is something you check off and be done with is dangerously wrong. Security must be continuous, must be updated, reviewed, etc.

2) idea that you can "encrypt" [secure] your entire life is ludacris and leads to many dangerous security misconceptions. You don't even have control of your entire life, let alone ability to secure it. Most the data on you is owned by others and not even available to you to secure. The world is not private or secure. Everyone needs to know and think about this when they are tweeting, sexting, talking shit about future president and then being surprised when SS comes to investigate.

3) idea that security is either on/off, a binary, that you can be secure or not. Is False and leads to extremely poor security choices, over/under securing. Nothing is secure. There is not such thing as SECURE. Things lie on a gradient of security from easy to break to impractically difficult. Things on the impractical to break technically end are still broken due to social engineering, externalities (power consumption of cpu), poor practices surrounding item, etc. Security is making the effort required to get an item greater than the value of getting the item.

Re: How to encrypt your entire life in less than an hour

#29

I am not 100% sold on one particular password manager. Any hints/suggestions?

I love 1password. The team behind it seems really dedicated and the various applications for each platform show a level of polish you'd expect from a team like that.

Re: How to encrypt your entire life in less than an hour

#30

The article is very slightly more nuanced but the conceptss the title purports is DANGEROUSLY INCOMPETENT for any security expert / discussion / context. 1) idea that security is something you check off and be done with is dangerously wrong. Security must be continuous, must be updated, reviewed, etc. 2) idea that you can "encrypt" [secure] your entire life is ludacris and leads to many dangerous security misconcepti…

> your entire life is ludacris

I'm sure you means ludicrous and not https://en.wikipedia.org/wiki/Ludacris

Post reply on HN