GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    PerryM ✅ (perrym@newsie.social)'s status on Wednesday, 17-May-2023 03:27:59 JST PerryM ✅ PerryM ✅

    As a computer hobbyist, I often worry how good my passwords are. I've never seen anything to describe how important it is. This chart and the research is super. My hat off to HIVE!

    In conversation Wednesday, 17-May-2023 03:27:59 JST from newsie.social permalink

    Attachments


    1. https://assets.newsie.social/media_attachments/files/110/300/666/942/210/715/original/cfae59adb6dd7e89.jpeg
    • Embed this notice
      :blobcathug: (jain@blob.cat)'s status on Wednesday, 17-May-2023 03:27:59 JST :blobcathug: :blobcathug:
      in reply to
      @PerryM just use a hash of your password :blobcatgooglybadumtss:
      In conversation Wednesday, 17-May-2023 03:27:59 JST permalink
    • Embed this notice
      Kainoa (kainoa@calckey.social)'s status on Wednesday, 17-May-2023 03:40:47 JST Kainoa Kainoa
      in reply to
      • Steve Dinn 🇨🇦

      @steve@social.dinn.ca @PerryM@newsie.social that's good, especially since password-cracking algorithms are getting better.

      In conversation Wednesday, 17-May-2023 03:40:47 JST permalink
    • Embed this notice
      Steve Dinn 🇨🇦 (steve@social.dinn.ca)'s status on Wednesday, 17-May-2023 03:40:48 JST Steve Dinn 🇨🇦 Steve Dinn 🇨🇦
      in reply to

      @PerryM Ha! Thanks to password managers, all my passwords are 24 - 36 characters long and use all the combinations. Perhaps that's overkill.

      In conversation Wednesday, 17-May-2023 03:40:48 JST permalink
    • Embed this notice
      Kainoa (kainoa@calckey.social)'s status on Wednesday, 17-May-2023 04:20:09 JST Kainoa Kainoa
      in reply to
      • Bitwarden
      • Steve Dinn 🇨🇦
      • Johan S 🌀

      @spiralmind @steve@social.dinn.ca @PerryM@newsie.social 1Password has had some pretty bad data breaches, I'd recommend @bitwarden@fosstodon.org

      In conversation Wednesday, 17-May-2023 04:20:09 JST permalink
    • Embed this notice
      Johan S 🌀 (spiralmind@calckey.social)'s status on Wednesday, 17-May-2023 04:20:22 JST Johan S 🌀 Johan S 🌀
      in reply to
      • Steve Dinn 🇨🇦
      • Kainoa

      @kainoa @steve@social.dinn.ca @PerryM@newsie.social I use 1Password to generate (and store, of course) passwords, and I just keep it cranked up to whatever 60-something the maximum is in 1Password.

      Some sites get angry about that.

      In conversation Wednesday, 17-May-2023 04:20:22 JST permalink
    • Embed this notice
      Kainoa (kainoa@calckey.social)'s status on Wednesday, 17-May-2023 04:25:02 JST Kainoa Kainoa
      in reply to
      • Steve Dinn 🇨🇦
      • Johan S 🌀

      @spiralmind @steve@social.dinn.ca @PerryM@newsie.social https://password-managers.bestreviews.net/faq/which-password-managers-have-been-hacked/

      2020 and 2016.

      In conversation Wednesday, 17-May-2023 04:25:02 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: password-managers.bestreviews.net
        Which Password Managers Have Been Hacked? – Best Reviews
        Password managers can and have been hacked. Discover the biggest password managers hacks over the years and what to do to keep your passwords safe.
    • Embed this notice
      Johan S 🌀 (spiralmind@calckey.social)'s status on Wednesday, 17-May-2023 04:25:03 JST Johan S 🌀 Johan S 🌀
      in reply to
      • Steve Dinn 🇨🇦
      • Kainoa

      @kainoa @steve@social.dinn.ca @PerryM@newsie.social That sounds like LastPass, I'm not aware of any published 1P breaches.

      In conversation Wednesday, 17-May-2023 04:25:03 JST permalink
    • Embed this notice
      Johan S 🌀 (spiralmind@calckey.social)'s status on Wednesday, 17-May-2023 04:28:34 JST Johan S 🌀 Johan S 🌀
      in reply to
      • Steve Dinn 🇨🇦
      • Kainoa

      @kainoa @steve@social.dinn.ca @PerryM@newsie.social Ah, that kind of vector, I was thinking more actual data exfiltration attacks. Bit of an ingenious headline on that page, and BitWarden should also be included for that level of vulnerability. https://flashpoint.io/blog/bitwarden-password-pilfering/

      In conversation Wednesday, 17-May-2023 04:28:34 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: flashpoint.io
        Bitwarden: The Curious (Use-)Case of Password Pilfering
        from Flashpoint Intel Team
        While evaluating the behavior of Bitwarden, a popular password manager browser extension, Flashpoint’s Vulnerability Research team noticed that embedded iframes in a web page were handled in an atypical manner.
      Kainoa likes this.
    • Embed this notice
      Kainoa (kainoa@calckey.social)'s status on Wednesday, 17-May-2023 04:29:16 JST Kainoa Kainoa
      in reply to
      • Steve Dinn 🇨🇦
      • Johan S 🌀

      @spiralmind @steve@social.dinn.ca @PerryM@newsie.social fair enough. I wasn't aware bitwarden had a similar vector.

      In conversation Wednesday, 17-May-2023 04:29:16 JST permalink
    • Embed this notice
      matthieu_xyz@calckey.social's status on Wednesday, 17-May-2023 04:39:23 JST matthieu_xyz matthieu_xyz
      in reply to
      • Steve Dinn 🇨🇦
      • Kainoa
      • Johan S 🌀

      @kainoa @spiralmind @steve@social.dinn.ca @PerryM@newsie.social There are two kinds of password managers. Those that were breached and the one that haven’t been breached yet.

      Now, from the one that were breached. Did they loose your passwords or not?

      The real bad breach is lastpass loosing payment information. I was a free user at the time so I’m unaffected. But that sure didn’t look good.

      In conversation Wednesday, 17-May-2023 04:39:23 JST permalink
      Kainoa likes this.
    • Embed this notice
      Kainoa (kainoa@calckey.social)'s status on Wednesday, 17-May-2023 04:40:19 JST Kainoa Kainoa
      in reply to
      • Steve Dinn 🇨🇦
      • matthieu_xyz
      • Johan S 🌀

      @matthieu_xyz @spiralmind @steve@social.dinn.ca @PerryM@newsie.social the best password managers are the ones you host on your own machine. Far, FAR less chance of any breach.

      In conversation Wednesday, 17-May-2023 04:40:19 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.