Earlier quoted context omitted.
I have to disagree with the Authy recommendation. I switched to Authy a few years ago, but it was nothing but painful and I have recently migrated away from it. For a long time the "TouchID Prompt" was slow and buggy, but that does appear to be fixed now. The real pain point is that it managed to corrupt one of my keys (how??) and the app tries to get me to backup my keys to their servers with multiple popups (which…
a major advantage is if I throw my phone into the ocean(not a theoretical attack!) I can still recover my OTP on another machine. Authy offers this pretty nicely I would recommend testing theories of : - losing phone - losing computer - losing both and have reasonable backup strategies for these scenarios.
The Dropbox hack is real
261–270 of 557 posts
Re: The Dropbox hack is real
#262Earlier quoted context omitted.
> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…
My favourite was the unique email I used for a Russian visa application. Either the consulate was ridden with malware, or they just sold my address.
Re: The Dropbox hack is real
#263Earlier quoted context omitted.
I cannot agree more, I do the same, and invite everyone else to do so. - Useful as a canary of which website has been breached - Useful as a canary of which website sold your details - and if your details are in the wild, you can stop the spam by deleting the address Credit cards should work the same way: a unique authorization code specific to this vendor or this transaction and useless to any other actor.
For credit cards, check out privacy.com I recently started using it, works great.
Re: The Dropbox hack is real
#264> 1Password now has a subscription service for $3 a month and you get the first 6 months for free. Don't pay for this people. Use the open source password manager Keepass http://keepass.info/
Re: The Dropbox hack is real
#265Earlier quoted context omitted.
> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…
Oddly enough I have had the opposite experience. I have been running per-service emails for 10 years and wonder to myself if it is worth the bother as I can recall only one ever spreading.
Re: The Dropbox hack is real
#266Earlier quoted context omitted.
> Unique-per-service email addresses work pretty well and they're so easy with Gmail - anything following a '+' character after your username (or alias, if using your own/company domain) will go to the same box, but keep the distinct address. Unfortunately, depressingly many sites validate email fields, and get it wrong - thinking '+' is not allowed. IMO it's not even worth trying to get an email regex (or other vali…
I'm pretty sure they do know a `+` is allowed...
Re: The Dropbox hack is real
#267It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…
> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…
Re: The Dropbox hack is real
#268Earlier quoted context omitted.
Download a password manager like Keepass, Lastpass or Password Safe: https://en.wikipedia.org/wiki/List_of_password_managers I use Keepass, it does exactly what I need. Secure the password manager itself with a long password. Put your logins into it, and generate a unique random password for each one, then go to the website in question and change the password to the new one. When you want to login to that website, op…
Is Keychain Access from OSX a safe password manager? Also, how comes all security-aware people trust 1Password and LastPass, even though they are not open source? Isn't that one of the rules of security, publish the source so we can trust it?
I don't think this is true at all. Many people do not recommend using these services for exactly that reason. Plenty of so-called experts make lots of compromises in their choices and recommendations for various reasons.
Re: The Dropbox hack is real
#269Earlier quoted context omitted.
> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…
How do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?
Re: The Dropbox hack is real
#270Earlier quoted context omitted.
> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…
How do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?
E.g. myaddress+service1@gmail.com will go to your inbox and you can filter on it.