I am not 100% sold on one particular password manager. Any hints/suggestions?
https://jmcphers.github.io/security/2016/05/08/passwords.htm...
31–40 of 70 posts
I am not 100% sold on one particular password manager. Any hints/suggestions?
https://jmcphers.github.io/security/2016/05/08/passwords.htm...
The article is very slightly more nuanced but the conceptss the title purports is DANGEROUSLY INCOMPETENT for any security expert / discussion / context. 1) idea that security is something you check off and be done with is dangerously wrong. Security must be continuous, must be updated, reviewed, etc. 2) idea that you can "encrypt" [secure] your entire life is ludacris and leads to many dangerous security misconcepti…
FastMail is a decent paid service. Or ProtonMail, Hushmail who market on privacy and security.
Earlier quoted context omitted.
Personally I like keepass. I don't love it, and it's UI could definitely use some work, but it suites my needs fairly well.
I also use Keepass[x]! The issue that I see people facing is that it isn't multi-device (it's an offline password manager). For me, that is the selling point though.
Me too! Though I'm curious as to what you mean by multi-device? I use it on multiple devices just fine, though I have to sync them by hand.
How is it possible for DuckDuckGo to offer google search results legally? Aren't Bing and Google constantly sniping at each other for implementing each other's results?
It just redirects to a Google page. It doesn't host the results.
http://security.stackexchange.com/questions/32367/what-is-th...
Earlier quoted context omitted.
Can you elaborate on why.
So that your shop doesn't mess your bank. (Shops are regularly hacked with leak of email addresses and possibly compromising passwords.)
I use separate addresses for banks, brokerage, etc. Because the email address associated with each isn't used elsewhere, I can almost always identify the culprit when it starts getting spammed, so I can cease business with and blacklist anyone who does it[1].
Because of that, any phishing attempts that go to the wrong address, even well done, tricky ones, are so obvious a machine can trash them with certainty.
Yet another reason is that if someone is going to try to guess/steal your password, if they don't know the email address used for that account, that's something else that can slow them down/trip them up.
[1] That is how Wells Fargo lost my business, well before they made a surprisingly strong go at proving Lenin right about capitalists.
I am not 100% sold on one particular password manager. Any hints/suggestions?
The article didn't cover email: Get off of the freebie services like Yahoo! and Gmail and go someplace else because we already know that these companies are in big-time cahoots with the government. Also, Google was working hard to get Clinton crime cabal elected to the point of messing with search results. WE WON'T FORGET. FastMail is a decent paid service. Or ProtonMail, Hushmail who market on privacy and security.
They pay a large expert security team to work hard on security all the time (including both mitigating attacks on Google's own infrastructure, and detecting sophisticated phishing attacks against Gmail users).
They pay a large expert legal team to work hard on legal issues all the time.
They're so popular that metadata analysis actually starts to get difficult a lot of the time.
They attract a lot of attention from governments. Governments have put resources into figuring out how to request data from Gmail. Gmail fights many of these requests vigorously, and ends up complying with many of them.