GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Friday, 01-Dec-2023 05:43:06 JST Chester Wisniewski Chester Wisniewski
    • Bob Lord 🔐 :donor:
    • Per Thorsheim

    Great! TransUnion, whom I have the pleasure of receiving free credit monitoring from due to the MGM Casino breach in Sept, has a policy of only allowing 15 characters or less. Not like anything important is on the line or anything. Oh, they get bonus points for letting me skip the password with a trivial security question! #InfoSec #NotAFeature @boblord @thorsheim

    In conversation Friday, 01-Dec-2023 05:43:06 JST from securitycafe.ca permalink

    Attachments


    1. https://securitycafe.ca/system/media_attachments/files/111/491/619/473/573/872/original/15904c46b44cb4c7.png

    2. https://securitycafe.ca/system/media_attachments/files/111/491/633/581/200/337/original/e0270cb8722a4b80.png
    • Embed this notice
      Aral Balkan (aral@mastodon.ar.al)'s status on Friday, 01-Dec-2023 05:43:04 JST Aral Balkan Aral Balkan
      in reply to
      • Chris Johnson
      • Bob Lord 🔐 :donor:
      • Per Thorsheim

      @captainslim @thorsheim @chetwisniewski @boblord Wow, much entropy, such security!

      In conversation Friday, 01-Dec-2023 05:43:04 JST permalink
    • Embed this notice
      Chris Johnson (captainslim@infosec.exchange)'s status on Friday, 01-Dec-2023 05:43:05 JST Chris Johnson Chris Johnson
      in reply to
      • Bob Lord 🔐 :donor:
      • Per Thorsheim

      @thorsheim @chetwisniewski @boblord

      United Airlines makes you choose from a list of allowed answers for their security questions.

      In conversation Friday, 01-Dec-2023 05:43:05 JST permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/497/148/313/359/850/original/fb87e6cdba34a3b6.jpeg
    • Embed this notice
      Per Thorsheim (thorsheim@mastodon.social)'s status on Friday, 01-Dec-2023 05:43:06 JST Per Thorsheim Per Thorsheim
      in reply to
      • Bob Lord 🔐 :donor:

      @chetwisniewski @boblord
      1) do not use security questions. :)
      2) if you use a pwd.manager, use that to generate & remember random pwds as answers to security questions
      3) if a service provider uses security questions, tell them to stop using them.
      4) Recommending them a little bit of MFA, in particular WebAuthn/passkeys, is a good idea.
      5) Tell them using security questions is close to negligence, if not gross negligence, of recommended practices & standards today.

      In conversation Friday, 01-Dec-2023 05:43:06 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.