Earlier quoted context omitted.
Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.
Or a text file or spreadsheet containing passwords, in a TrueCrypt container (I still trust it).
Notes on the Celebrity Data Theft
171–180 of 292 posts
Re: Notes on the Celebrity Data Theft
#172Earlier quoted context omitted.
Both groups certainly exist, but one is larger than the other by a few orders of magnitude.
(disclaimer: not meaning to start any kind of flame-war) To be honest, the one I perceive (as a straight, white, middle-class, educated male) larger is the misandristic one. As a person who strives to be good and helpful to every human being equally, regardless of race, gender, orientation or whatever, I get everyday on the Internet and I get flooded by articles and comments saying that everything I do or think is mi…
I'd say the main reason the leaks are all women is that hackers are predominately heterosexual men.
Re: Notes on the Celebrity Data Theft
#173Earlier quoted context omitted.
That's not how 1Password works. All passwords for 1Password are stored locally in an AES encrypted file. They never see, touch, or have any control over your passwords on their end. Even if they suddenly shut down tomorrow, all your passwords would still be accessible unless you chose to delete the application and have zero backups to restore from. They even have an export function to dump the passwords (unencrypted)…
You are 100% correct. To add to this all syncing on 1Password is done using 3rd party vendors. You can use dropbox, iCloud, Google Drive, etc to do the actual syncing of the encrypted files.
Re: Notes on the Celebrity Data Theft
#174Just to give OP a heads up: the article's font is rendering terribly in Windows Chrome.
Re: Notes on the Celebrity Data Theft
#175Earlier quoted context omitted.
Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.
My problem is that 1Password et al are curing symptoms, not solving causes. Personal infosec hasn't evolved quick enough to match the technology it depends on. Sure we're comfortable with 12 character, 3 month rotation passwords, but the average 'civilian'? Probably doesn't even have a passcode on their phone despite the massive personal security risk they're carrying around with them. We need to educate and/or provi…
(Most of mine are markedly longer.)
Though I'll admit to being a tad less aggressive on the rotation than I ought to be.
Re: Notes on the Celebrity Data Theft
#176Earlier quoted context omitted.
Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.
I got screwed by a password manager that got deleted during upgrading a hard drive. Never again
It also _probably_ means having these online somewhere. You're relying on strong crypto (and a really good base password) to protect you here.
Re: Notes on the Celebrity Data Theft
#177Earlier quoted context omitted.
Don't use an "idiot" password, use a long password.. Good passwords aren't complex, they're LONG.. "this is a really dumb password" is probably actually a really good password. ;-) And also, your "problem" is simply your decision to trade security for convenience. You need to weigh the risks vs. reward and make the choice for yourself. If something goes wrong, at least you'll know why.
Long passwords (aka the xkcd scheme) aren't secure anymore - https://www.schneier.com/blog/archives/2014/03/choosing_secu... The only good passwords are ones that stay well away from dictionary words..
There are archives of know passwords -- millions of them. These should be rejected on any online service.
There are tools for guessing passwords. Any password which falls into any of he likely-to-be-guessed divisions should _also_ be rejected.
Dictionary words _could_ work in a sufficiently large namespace. But that's pretty iffy.
Re: Notes on the Celebrity Data Theft
#178I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?
I also have my phone set up for iOS not to ask for the password for 5 or 15 minutes (can't remember the exact option) after I entered it.
Re: Notes on the Celebrity Data Theft
#179Earlier quoted context omitted.
Both groups certainly exist, but one is larger than the other by a few orders of magnitude.
(disclaimer: not meaning to start any kind of flame-war) To be honest, the one I perceive (as a straight, white, middle-class, educated male) larger is the misandristic one. As a person who strives to be good and helpful to every human being equally, regardless of race, gender, orientation or whatever, I get everyday on the Internet and I get flooded by articles and comments saying that everything I do or think is mi…
Re: Notes on the Celebrity Data Theft
#180Earlier quoted context omitted.
I've seen this argument come up before and I don't understand it. Why do you trust KeePass more than 1Password? In both cases you are sharing the datafile however you'd like (Dropbox, thumbdrive, etc...). The primary difference is if you have access to the source code or not. If KeePass purposefully injected a vulnerability, it would just be that dev/project that would fail. If 1Password were to do the same, that com…
Why do you assume every KeePass user is storing their passwords on a server somewhere? I would never send my password file over a network, and I don't consider USB storage "sharing."