Earlier quoted context omitted.
Yes! Me too. Not adding anything here except a confirmation on the above approach. You kind of need your email password as a "break glass" scenario. But mostly, you just need your password manager.
and root disk encryption, unless you have some alternative method set up.
Two billion email addresses were exposed
271–280 of 470 posts
Re: Two billion email addresses were exposed
#272Earlier quoted context omitted.
I used per-account email with alias services and password managers. Also started migrating old accounts in free time. Now its pretty easy to tell the source of leak by email addresses as well as sources of spam. --- Per-account alias might sound much, but using sieve filtering [1] is amazing, and you can get a comprehensive filtering solution going with 'envelope to' (the actual address receiving the email) + 'header…
I just use + @gmail.com At the end of day day it’s all delivered to myname@gmail.com mailbox, but I can use filters based on part after “+”.
This does help in filtering spam though
Re: Two billion email addresses were exposed
#273Earlier quoted context omitted.
No, it doesn't mean that, that's ridiculous. How would that work? Magic?
Download all the hashes first - not practical.
Re: Two billion email addresses were exposed
#274On the plus side, Troy can save a lot of DB space now. Instead of storing which emails have been compromised at this point he can replace that with just def email_compromised(email): return True
Not necessarily. Both my main addresses still come back clean after years in use. The one I use for random crap has 9 hits though.
Re: Two billion email addresses were exposed
#275Earlier quoted context omitted.
I used per-account email with alias services and password managers. Also started migrating old accounts in free time. Now its pretty easy to tell the source of leak by email addresses as well as sources of spam. --- Per-account alias might sound much, but using sieve filtering [1] is amazing, and you can get a comprehensive filtering solution going with 'envelope to' (the actual address receiving the email) + 'header…
I just use + @gmail.com At the end of day day it’s all delivered to myname@gmail.com mailbox, but I can use filters based on part after “+”.
I've started using grouped aliases instead for a bunch of things.
Re: Two billion email addresses were exposed
#276Earlier quoted context omitted.
+1 for Bitwarden. It is literally the best solution out there. Been getting to increase uptake in personal circles with (very) limited success. The wife keeps trying to convince me that the ship has sailed in trying to protect info online. She's probably right.
Can anyone with experience with 1Password and Bitwarden share their opinions on each. I've been on 1Password for years and am wondering if I'm missing anything.
Re: Two billion email addresses were exposed
#277Re: Two billion email addresses were exposed
#278Interestingly, the HIBP data seems to have an expiration date. My email address from the Dropbox data breach [0] is now shown as having no recorded breaches, although it did back in 2016 after HIBP acquired that dataset. [0] https://haveibeenpwned.com/breach/Dropbox
My 2012 Dropbox leak still shows up for my account.
Re: Two billion email addresses were exposed
#279Re: Two billion email addresses were exposed
#280Earlier quoted context omitted.
Now that I'm not only using a Macbook and iPhone, I've been looking for cross-platform solutions. For a week I've been using KeePassXC + Syncthing between four devices. Syncthing is also syncing my Obsidian vaults which has replaced Apple-only Notes.app. Bitwarden is definitely more polished, and Syncthing is definitely (much) more fiddly than using Bitwarden's and Obsidian's ($5/mo) native syncing tools. But I like…
strongbox is a reasonable app for iOS and you can set it up for sftp to your main self hosted server.
I've switched to KeePassium. Not quite as polished UX, but works for me