Anyone here recommend a good security key? Is YubiKey still the best option? I noticed that they don't have any usb-c + NFC options.
They do have NFC and usb-c options (separately, though), and are planning to launch lightning as well https://www.yubico.com/2019/01/yubico-launches-the-security-...
773M Password ‘Megabreach’ Is Years Old
131–140 of 177 posts
Re: 773M Password ‘Megabreach’ Is Years Old
#132Anyone here recommend a good security key? Is YubiKey still the best option? I noticed that they don't have any usb-c + NFC options.
I believe their upcoming HW will have support for NFC, but at this time iOS will not support NFC as MFA, though of course YK would love Apple to support them. Correction: Looks like YK is saying iOS does support YK as MFA via NFC[1] [1] https://www.yubico.com/2018/05/yubikey-comes-to-iphone-with-...
Re: 773M Password ‘Megabreach’ Is Years Old
#133Earlier quoted context omitted.
I've used KeePass and one issue I do take with it is the UX. Bitwarden and 1password feel like cohesive apps and have good integration with many platforms. For KeePass I felt uneasy about some of the ports of it. There's a lot of good ones on desktop, less so on mobile. Syncing is also a thing I prefer 1password and Bitwarden for. They both have cloud syncing by default. Some won't want that but I definitely do.
The problem I personally have with KeePass is sharing and that you are on your own for many things. You CAN make mistakes with KeePass. You pretty much can’t make mistakes with a service. I’ve set about 100 people up on LastPass including my mom. I recommend it as a very good thing normal people will actually use.
Re: 773M Password ‘Megabreach’ Is Years Old
#134Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…
I received the same email to "myspace@" my domain. I wouldn't have used that email anywhere else..
Re: 773M Password ‘Megabreach’ Is Years Old
#135Naive soul here, but is it really wise to type live passwords into someone's site that ostensibly is looking for matches with its existing database? That seems awfully trusting.
Re: 773M Password ‘Megabreach’ Is Years Old
#136Naive soul here, but is it really wise to type live passwords into someone's site that ostensibly is looking for matches with its existing database? That seems awfully trusting.
He describes the security measures behind the process here:
https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...
Of course, it all still boils down to how much you trust the guy, the approach, etc etc.
Re: 773M Password ‘Megabreach’ Is Years Old
#137Earlier quoted context omitted.
There are good reasons to provide unique aliases to companies requesting an email: - if they start sending you spam you can severe their capacity to contact you by deleting the alias - if they give your contact to a third party, you know from the alias who leaked your email address - if you see an email on a data breach like this one, you know immediately which website got hacked - it makes it really hard to correlat…
Agreed. And it's so easy to set up when you have your own domain, I'm somewhat surprised not more people are doing it. Oh well.
Re: 773M Password ‘Megabreach’ Is Years Old
#138Naive soul here, but is it really wise to type live passwords into someone's site that ostensibly is looking for matches with its existing database? That seems awfully trusting.
The reasoning given is: if you're aware it's a bad idea, great! Don't do it. If you don't yet know it's a bad idea, and do it, you'll see how many places it has already been leaked, and hopefully start using different passwords, and a password manager ...
Re: 773M Password ‘Megabreach’ Is Years Old
#139Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…
The best defense, just in case one of these cases turns out to be legit, is to send a video of myself watching porn to all my contacts preemptively. Take out their leverage, you know?
Re: 773M Password ‘Megabreach’ Is Years Old
#140Earlier quoted context omitted.
But how will I guess my email when I do want to reconnect with my account? I see why obfuscation (well, anything to avoid predictability, up to that random hex) is advisable, but the convenience trade-off is real.
If you do that out of memory, you are most likely re-using passwords. Re-using passwords with an easily guessable login isn't a good combination.
What I and many others do is reuse not a password, but reuse a password formula (in my case with slight but easily memorable variations depending on importance, or if forced by stupid password rules). If you saw a dozen of my email/password combinations in the clear you would be able to reverse engineer the rules and then guess combinations for arbitrary sites almost as good as me. It's a calculated risk, just like trusting a password manager is a calculated risk. Right now I consider password managers the better trade-off, but still only slightly better, by a margin small enough to make it not worthwhile to invest in a habit change. If the "formula" I happen to use was just a little harder to reverse engineer than it sadly is I would consider it strictly safer than password managers.