Skip to main content

Search

Items tagged with: password


I'm excited to announce that I have successfully put together a #Signet #hardware #password manager, without any jumpers or hackery.

This means I will be making more of these so people who want to up their #security game will be able to just buy them.

I'll be honest: this one cost me over $300 in parts and many hours of labor. My goal is to get them down to about $45 each. That should allow me to break even (assuming I can produce them faster and my time is worth minimum wage). #infosec #foss

A small USB device with Signet v1.3 printed on the purple printed circuit board.


New study shows how scary fast today's AI is at cracking passwords

51% of common passwords can be cracked in less than a minute, 65% in less than an hour, 71% in less than a day, and 81% in less than a month.

Additionally, the group provided its findings in a table. As you can see in the image below, almost every password with six or fewer characters was instantly cracked.

#password #passwords #artificialintelligence #ai #security #cybersecurity #infosec #hacking

https://www.androidauthority.com/ai-password-cracking-3310709/


A website dedicated to example of wacky, poorly designed password rules that sometimes make little sense: https://dumbpasswordrules.com/sites/
#Password #PasswordUX
A list of screenshots with poor password conditions


Today, @fdroidorg offered me an update of #FreeOTP to version 2.0 after nearly exact 7 years of no FreeOTP update at all. Promises to be more secure. Yay, what could possibly go wrong? A lot. And now I regret that update: It requests to decide on a later #unchangeable (!) #password (Unchangeable?!? #WTF? What year do we have? How can this be "more secure"?) and has no more countdown timer. And downgrading back to 1.5 fails at F-Droid level with an unhelpful and generic error message. Great! 🤮
The new FreeOTP logo and the text "Welcome to FreeOTP 2.0" as shown upon first start of the FreeOTP Android app at version 2.0.
An Android app dialog saying

"Token backups allow you to recover from data loss and effortlessly transfer your tokens to a new device.

Backups are encrypted using the password provided below. The security of your backups depends on a strong password.

The FreeOTP security model dictates this password CANNOT be changed at a later time. Please take this into consideration when choosing a password."

Below that text is a input field labeled "Password" and a greyed out button labeled "DONE"


I'm writing an #Emacs #Elisp clone for Hash It! password hasher.

This is the repo: https://gitlab.com/cnngimenez/hashit-el
Now there are three implementations: Android, HTML/JS (Firefox add-on), and Emacs!

I want to add a HMAC-SHA512 support in a future time...
Perhaps a customization, or another interactive function?

#hashit #hash-it #password-hasher


UK IP Office (Intellectual Property) Claims Sharing Netflix Password Is "Illegal"

#News #Netflix #password #UK #streaming
https://www.techdirt.com/2022/12/26/uk-ip-office-tries-to-claim-netflix-password-sharing-is-illegal/


I hope that @Bitwarden will allow passwordless authentication also for the self-hosted instances soon, especially for those who have a paid license.
---
RT @avoidthehack
Passwordless Authentication - Access Your @Bitwarden Web Vault Without a #Password

New "login with device" option allows users to decrypt the vault (login) without a password.

#cybersecurity #infosec #privacybydefault

https://bitwarden.com/blog/passwordless-authent…
https://nitter.net/avoidthehack/status/1602347547879559168

(Nitter addon enabled: Twitter links via https://nitter.net)


Oh crap, again a commercial password manager are breached data.

»LastPass reveals another security breach: The password manager was hacked in August this year.«

😬 https://www.engadget.com/lastpass-reveals-another-security-breach-075158853.html

--
#lastpass #password #security #breach #hacked #databreach #hack #passwordmanager #privacy


Referenced link: https://thehackernews.com/2022/11/french-electricity-provider-fined-for.html
Discuss on https://discu.eu/q/https://thehackernews.com/2022/11/french-electricity-provider-fined-for.html

Originally posted by The Hacker News / @TheHackersNews@twitter.com: https://nitter.net/TheHackersNews/status/1598003423428849665#m

French data protection watchdog has fined the country's largest electricity provider Electricité de France (EDF) €600,000 for using insecure MD5 hash algorithm to store its customers' passwords.

Read: https://thehackernews.com/2022/11/french-electricity-provider-fined-for.html

#infosec #hacking #cybersecurity #password

(Nitter addon enabled: Twitter links via https://nitter.net)


http://www.ostechnix.com/4-easy-ways-to-generate-a-strong-password-in-linux/

My preferred :
openssl rand 14 -base64
gpg --gen-random --armor 1 14

... but the passwords are not easy to remember. A good argument to use a password manager.
#password #linux #gpg #openssl


Una excelente forma de compartir un #terminal para poder controlar desde otro lugar, para que te den una mano (o corrijan si estas rindiendo mmmmm) o simplemente para utilzar con #password cuando te haga falta.
Te rpesento #tmate miralo en #culturalibre https://culturalibre.ar/2022/06/08/tmate-compartiendo-nuestra-terminal/


(3/4) Of course, w/it comes to security, SMS 2FA w/be better than nothing...

-- unless further manipulation made available via Phone number. And in certain cases SMS can offer this (ie: pw change).

#2FA #Infosec #Cybersecurity #Security #FCC #password
https://krebsonsecurity.com/2021/03/can-we-stop-pretending-sms-is-secure-now/


Portal de autoservicio de cuentas con PWM # # # # # # # # # # # # # # # # # # # # # # https://www.bujarra.com/portal-de-autoservicio-de-cuentas-con-pwm/


Cdo elijan sus #contraseñas, usen LeTrAs, núm3r05, s|mbolø$ €sþeciales, y usen MIN 12 caracteres.

Y NUNCA usen la misma #password en mas de un servicio.

Cómo memorizamos todo?

No lo memorizamos, usamos gestores de contraseñas:

https://juncotic.com/keepass-gestor-contrasenas-seguro/

https://juncotic.com/keepass2android-sincronizar-contrasenas/
---
RT @smithmicro
Setting secure passwords is a critical component of #onlinesafety. For …
https://nitter.net/smithmicro/status/1469372090981748739

(Nitter addon enabled: Twitter links via https://nitter.net)

Este sitio web utiliza cookies. Si continúa navegando por este sitio web, usted acepta el uso de las cookies.