Showing posts with label password manager. Show all posts
Showing posts with label password manager. Show all posts

Friday, June 16, 2023

You've probably never heard of it

from here and here

Whenever the topic of password managers comes up, people generally promote the one they use, but I never hear anyone promote the one I use. That's fine, it doesn't need to be popular to do it's job, and in fact it might actually be better if it flies under the radar, because then it's a less tempting target for the bad guys.

Friday, June 9, 2023

Make some room for other things

from here and here

There's a life hack that says you should get things out of your head by writing them down so you no longer have to waste energy worrying about forgetting them, but when that comes to passwords you might want to take a little extra care and not simply write them in a notebook.

Tuesday, January 31, 2023

When you have a password manager

from here and here

It's easy when you don't have to remember them yourself.

Friday, December 23, 2022

The last straw for LastPass

from here and here

How does a password management company make such a grave error as not protecting URLs? Knowing you have an account on a questionable website is sensitive in and of itself, without giving away the username or password, and by sensitive I mean it can get folks killed in some places.

This metadata will also be useful for phishing attacks, so if you're a LastPass user, you might see an increase in phishing emails. However, since the breach itself was months ago, the increase might have already happened.

Password managers are still good, of course, but maybe not this particular one, and maybe not online ones. Online password managers are incredibly valuable targets, while each of us individually is  generally not. An offline password manager would require someone getting through your own defenses to compromise you instead of compromising millions of users at once. 

Wednesday, October 19, 2022

Why I outsource the job to a password manager

found on Reddit

Committing new strong passwords to memory is not the slightest bit easy. It's just not what human brains were built for, so don't feel bad about the fact that your memory is where new passwords go to die. Adapt to your own limitations and use assistive technology like a password manager.

Tuesday, March 29, 2022

Signs you're using a password manager wrong

from here and here

Hemingway's got nothing on the person who thought up the filename DomAdmins-LastPass.xlsx. That's a story all on it's own, and it's sure to send a chill down the spine of any infosec pro.

Monday, January 31, 2022

Mastering passwords

from here and here

You may have heard the advice work smarter, not harder - for passwords that means using a password manager. Let the manager do most of the work for you. 

Thursday, March 25, 2021

Credential Stuffing: The Dangers of Reusing Passwords Online


Watch on YouTube

A great explainer about account security that was apparently put out as an advertisement. You're not expected to buy anything, though. It seems someone struck on the idea of using the advertising facility at YouTube to expose people to security awareness training, which is actually quite brilliant.

Friday, February 26, 2021

It's just not right

from here and here (source article)

Trust is difficult to gain but easy to lose, so I have to wonder what LastPass was thinking when they stuffed their app full of trackers. Did they think no one would notice? Have they never heard the phrase "Trust But Verify"?

LastPass isn't my password manager of choice, but if it had been I'd be looking for a new one now.

Thursday, January 14, 2021

The one time you should be a Karen

from here

Honestly, in this one particular context, be a Karen. You're entitled to let technology do the remembering for you.

Friday, November 20, 2020

It's obviously not the year of the password manager

from here

You'd think with all the extra free time people had this year they'd have finally worked out how to use a password manager to keep track of their passwords so they wouldn't need to use ridiculous ones like "123456" and "password" anymore. 

Monday, October 12, 2020

You aren't still storing passwords in your brain, are you?

from here and here (image source)

The old advice about passwords being easy to remember and hard to guess isn't very good on it's own, but it did spread far and wide. If you ask people what makes a good password there's a good chance they'll respond with some variation on easy to remember and hard to guess. 

The good news is that it doesn't take much tweaking to upgrade it to modern requirements. If the computer is doing the remembering for you then that's going to be some sort of password manager, and once you have that in place you can basically get uniqueness and strength for free. Moreover, taking advantage of something that's already in people's heads is easier than getting something entirely new in there.

 

Wednesday, July 8, 2020

Maybe some day they'll unlock password managers of their own

from here

I bet you thought that was going to go in a different direction.

But seriously, the master password is meant to be better than all the passwords stored in the password manager. If it's weaker than the stored passwords then realistically that weakness transfers to the stronger passwords stored inside, because the weak password can be broken and reveal the supposedly stronger passwords.

The stored passwords aren't going to get stronger over time, though. They will never surpass the master..