Live data from Hacker News

Hackers Stole My Website

medium.com

121–130 of 144 posts

Re: Hackers Stole My Website

#121
post #98
post #93

Earlier quoted context omitted.

Cool thanks for the link! Were you meaning to say that you consider the "correct horse" password selection principles bad advice? Or that the advice given by the author of the article is bad advice?

I feel the "correct horse" method is bad advice. Though, certainly not terrible. I actually followed it for a while and it works amazingly well for memory, but over time I was convinced that the best route is a password manager with randomly generated passwords.

That doesn't make it bad advice.

The comic advises using correct-horse style passwords rather than tr0ubaDour-style. That is good advice.

Re: Hackers Stole My Website

#122
post #115

Earlier quoted context omitted.

What about KeePass2?

KeePass is an open-source password manager. There are many compatible programs, many with confusingly-similar names, like KeePassX. KeePass2 is the new version of KeePass, which uses a new file format. Most KeePass-compatible programs, including KeePassX, support the old file format and the new one.

Sure, but why prefer say KeePassX over KeePass2?

Re: Hackers Stole My Website

#123
post #98
post #93

Earlier quoted context omitted.

Cool thanks for the link! Were you meaning to say that you consider the "correct horse" password selection principles bad advice? Or that the advice given by the author of the article is bad advice?

I feel the "correct horse" method is bad advice. Though, certainly not terrible. I actually followed it for a while and it works amazingly well for memory, but over time I was convinced that the best route is a password manager with randomly generated passwords.

What do you use to unlock your password manager?

A 7 word diceware passphrase would be a good idea.

Re: Hackers Stole My Website

#124
post #37

Earlier quoted context omitted.

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

www.nearlyfreespeech.net (mainly a host but you can register domains with them) offers Google Authenticator 2fa and control over what recovery options are allowed, including none, which is something I wish anyone that supports 2fa would offer.

NFS also emails you if someone tries an incorrect password on your account. Kind of a nice feature.

Re: Hackers Stole My Website

#125

Earlier quoted context omitted.

Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.

I like keepassx. It just works and no need for any online account. You use a good master key/password and rest of the passwords, don't even remember.

And keepass has also (some sort of) 2FA via a local key file. While it's of course not as good as a real token generator, it helps against password sniffing and makes cracking much harder.

Re: Hackers Stole My Website

#127
post #4

>3. Turn off your computer and personal devices when they’re not in use. This article reads like an AOL scare from 1995 directed at my grandma.

> 3. Turn off your computer and personal devices when they’re not in use. Even Bruce Schneier recommends you do that[1]. The idea is that if your machine is a spambot and you don't know it, there are fewer windows of time where your machine can be blasting the Internet with spam. Or if there's some network-based exploit, you're not vulnerable while your device is off. 1. https://www.schneier.com/blog/archives/2004/12…

I guess if your computer is already a spambot, just limiting the amount of time you are spamming isn't really solving the problem. What is the real advantage to spamming for eight working hours vs 24. For you, no advantage. Disadvantage goes to the spam operator, but again, who really cares at that point?

Re: Hackers Stole My Website

#128
Anyone who uses godaddy add 2FA now and i mean now.

This is my story

I enabled 2FA i don't why. I think i read somewhere, how someone got there domains stoled.

Last month ago, I got a text message out of the blue, I googled the number and it was godaddy service.

So this person had got my username and password in godaddy and hit the 2FA, godaddy uses customer IDs and the password i use was a old password but one i didn't use in any other service.

So someone is running through all the customers Id numbers with a password dictonary because i knew this password was on one of those leaked password dictionaries.

They can do this because the godaddy site doesn't lock the account out for 24 hours after 5 wrong times. The hacker can try different combinations multiple times.

This is a major flaw on there site.

Re: Hackers Stole My Website

#129
post #115

Earlier quoted context omitted.

KeePass is an open-source password manager. There are many compatible programs, many with confusingly-similar names, like KeePassX. KeePass2 is the new version of KeePass, which uses a new file format. Most KeePass-compatible programs, including KeePassX, support the old file format and the new one.

Sure, but why prefer say KeePassX over KeePass2?

Unless they know something I don't, I assume people recommending KeePassX are not Windows users.

Re: Hackers Stole My Website

#130
post #74

Want to share a strange experience I had: in the year 2014, I was looking for buy a .io domain and was surprised to find that citi.io was available, so I bought it in domains.google.com with an expiration date in 5 years and I also noticed that there was a website called citi.io that I could still visit. I didn't change the DNS settings of the new domain I bought and didn't use the domain. Then sometime in 2016, I no…

Check for confirmation emails?
Post reply on HN