Earlier quoted context omitted.
Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.
At least in the security circles I'm in, 1Password is the favorite. KeePassX is recommended sometimes too, but is definitely for the more technically-minded. There's a low level of distrust for Lastpass.
Hackers Stole My Website
51–60 of 144 posts
Re: Hackers Stole My Website
#52Earlier quoted context omitted.
I like keepassx. It just works and no need for any online account. You use a good master key/password and rest of the passwords, don't even remember.
How do you personally handle passwords on multiple devices? Just host it somewhere publicly accessible and use a really strong master?
This way it's safe to store the database in the cloud without having to worry about attackers trying to brute force my master password if Dropbox gets compromised (since they'd also need the key file, which is only stored locally), and even if the key file is stolen the attacker would still need my master password to access the database.
Re: Hackers Stole My Website
#53The most surprising thing is how helpful (and immediate) the FBI was. Wouldn't have guessed that. Can you really stop a wire transfer? I thought the whole point of wires is that they are immediate and irreversible? Also, couldn't the FBI track the bank account info back to the thief? Or I guess it's possible the bank account is opened through a stolen identity. I guess the smartest thing the thief could do is then us…
Re: Hackers Stole My Website
#54It sounds like the core of this hack was an attack on her email (followed by password resets for registrar, etc.). So the #1 step to reducing your risk of an attack like this would be setting up 2FA on your email account. The industry standard is password resets via email. If an attacker has access to your email, they have access to every online account you own. Stealing email passwords is easy. So easy. No matter ho…
Yeah so about that 2FA. I have a local email client, which uses IMAP and hence cannot do 2FA. What now? I've always thought this is rather a gaping hole. Of course i use app-specific passwords which presumably won't allow access to webmail or changing the account password, but still, if someone got my app password for IMAP, they could still siphon out password reset emails for all my other services. What do the rest…
What this means is if you enable 2FA for your gmail account, you can generate a one-time password to authorize any client which does not support a 2FA auth flow. This password is then destroyed by both parties.
If you run your own email server, I think you are at low risk of being attacked in a more general phishing net. An attacker targeting you personally still has many options but that is much less likely.
Re: Hackers Stole My Website
#55> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…
I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.
Re: Hackers Stole My Website
#56> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…
Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.
Re: Hackers Stole My Website
#57>3. Turn off your computer and personal devices when they’re not in use. This article reads like an AOL scare from 1995 directed at my grandma.
Even Bruce Schneier recommends you do that[1]. The idea is that if your machine is a spambot and you don't know it, there are fewer windows of time where your machine can be blasting the Internet with spam. Or if there's some network-based exploit, you're not vulnerable while your device is off.
1. https://www.schneier.com/blog/archives/2004/12/safe_personal...
Re: Hackers Stole My Website
#58> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…
I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.
Re: Hackers Stole My Website
#59Earlier quoted context omitted.
EDIT: If you're going to downvote me, did you even read the article? Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash - - - But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience? The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking…
I think the mere fact that they leveraged her email to steal her domain is interesting. You generally don't think of a domain as something people steal
Re: Hackers Stole My Website
#60Earlier quoted context omitted.
At least in the security circles I'm in, 1Password is the favorite. KeePassX is recommended sometimes too, but is definitely for the more technically-minded. There's a low level of distrust for Lastpass.
I'd love to use 1password still, but they have no Linux client (even cli), the web client is long gone, and the Android app is awful. It's really great software, but I don't feel valued as a customer at all.