mastouille.fr est l'un des nombreux serveurs Mastodon indépendants que vous pouvez utiliser pour participer au fédiverse.
Mastouille est une instance Mastodon durable, ouverte, et hébergée en France.

Administré par :

Statistiques du serveur :

632
comptes actifs

#passwordmanagers

0 message0 participant0 message aujourd’hui
Peter V. Tretter ✅ 🇨🇦<p><span class="h-card" translate="no"><a href="https://fosstodon.org/@bitwarden" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>bitwarden</span></a></span> <span class="h-card" translate="no"><a href="https://ottawa.place/@srgower" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>srgower</span></a></span> <span class="h-card" translate="no"><a href="https://1password.social/@1password" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>1password</span></a></span> too bad you don't have any servers in <a href="https://mastodon.social/tags/Canada" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Canada</span></a>. <a href="https://mastodon.social/tags/TradeWar" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TradeWar</span></a> <a href="https://mastodon.social/tags/PasswordManagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManagers</span></a></p>
Micah Ilbery :sloth_coffee:<p>The bitwarden android app is great, the browser extension is fine for the most part, but the desktop client is such an awful experience. It honestly makes me want to move to something like keepass where I can get a native client no matter the platform. But keeping keepass synced across devices I've heard is not a great experience as it wasn't designed with synchronization in mind. I wish there were more 3rd-party bitwarden clients for every platform because with mobile I'm pretty happy but on my laptop it's super frustrating.<br><a href="https://slothsneed.coffee/tags/selfhosting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SelfHosting</span></a> <a href="https://slothsneed.coffee/tags/bitwarden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Bitwarden</span></a> <a href="https://slothsneed.coffee/tags/vaultwarden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vaultwarden</span></a> <a href="https://slothsneed.coffee/tags/android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Android</span></a> <a href="https://slothsneed.coffee/tags/gnome" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GNOME</span></a> <a href="https://slothsneed.coffee/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> <a href="https://slothsneed.coffee/tags/keepass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>KeePass</span></a> <a href="https://slothsneed.coffee/tags/passwordmanagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManagers</span></a></p>
🆘Bill Cole 🇺🇦<p>6. Small developer in UK. Not clear where the "StrongBox Pro Sync" service lives, but it is not required for synch because you can use any file in the (local or remote-mounted) filesystem, SFTP or WebDAV to wherever, or multiple commercial cloud storage tools. </p><p><a href="https://toad.social/tags/Passwords" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passwords</span></a> <a href="https://toad.social/tags/PasswordManagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManagers</span></a> <a href="https://toad.social/tags/Strongbox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Strongbox</span></a> (3/3)</p>
🆘Bill Cole 🇺🇦<p>1. Native KeePass 2 vault format, so other programs can use the encrypted vault files. Each device has a complete copy of each vault, which can be opened offline if you have the passphrase, key file, or physical security key used to encrypt it. </p><p>2. Includes multiple peer-to-peer (ish) and cloud-based synch options including SFTP &amp; WebDAV. Works with Syncthing/MobiusSync if you want to be truly masterless. Has bespoke synch service of their own.<br>(1/3) <br><a href="https://toad.social/tags/Passwords" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passwords</span></a> <a href="https://toad.social/tags/PasswordManagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManagers</span></a> <a href="https://toad.social/tags/Strongbox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Strongbox</span></a></p>
🆘Bill Cole 🇺🇦<p>3. Runs on macOS and iOS, licensed per-platform not per-device. License is shareable across 6 devices via Apple Family Sharing. Vaults can be shared freely amongst any number of KeePass-compatible programs on any platform. </p><p>4. SBP itself only runs on iOS and macOS, but its vault files are usable by any KeePass-compatible tool. </p><p>5. Exports as CSV or KeePass. Imports from KeePass, 1Pass, LastPass, iCloud Keychain (via exported CSV) and others. (2/3)</p><p><a href="https://toad.social/tags/Passwords" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passwords</span></a> <a href="https://toad.social/tags/PasswordManagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManagers</span></a> <a href="https://toad.social/tags/Strongbox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Strongbox</span></a></p>
🆘Bill Cole 🇺🇦<p>I don't have a solution for all of those precise specifics but I've seen so many similar queries that I had to get the urge to answer out of my system... </p><p>A 🧵about <a href="https://toad.social/tags/Passwords" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passwords</span></a> <a href="https://toad.social/tags/PasswordManagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManagers</span></a> <a href="https://toad.social/tags/Strongbox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Strongbox</span></a></p><p>If one is mostly on Apple devices trying to avoid storing your secrets on other people's storage while sharing them between your own and maybe other devices, the StrongboxPro password manager provides answers for me: <a href="https://mk.absturztau.be/notes/a6gnynjjzuda01zb" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mk.absturztau.be/notes/a6gnynj</span><span class="invisible">jzuda01zb</span></a></p>
Tuta<p>The <a href="https://mastodon.social/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://mastodon.social/tags/Trinity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trinity</span></a> - spotted at <span class="h-card" translate="no"><a href="https://fosstodon.org/@bitwarden" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>bitwarden</span></a></span> explains how to secure your accounts with 2FA:</p><p>👉 <a href="https://bitwarden.com/resources/presentations/the-triangle-of-security-success/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">bitwarden.com/resources/presen</span><span class="invisible">tations/the-triangle-of-security-success/</span></a></p><p>And rightly so: Because <a href="https://mastodon.social/tags/encrypted" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>encrypted</span></a> email get even more secure with <a href="https://mastodon.social/tags/2FA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>2FA</span></a> and <a href="https://mastodon.social/tags/passwordmanagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwordmanagers</span></a> 💪</p><p>Check out our top 3:<br><a href="https://tuta.com/blog/best-password-manager" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">tuta.com/blog/best-password-ma</span><span class="invisible">nager</span></a></p>
Bob Carver<p><a href="https://thehackernews.com/2025/01/farewell-to-fallen-cybersecurity-stars.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">thehackernews.com/2025/01/fare</span><span class="invisible">well-to-fallen-cybersecurity-stars.html</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/MFA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MFA</span></a> <a href="https://infosec.exchange/tags/Antivirus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Antivirus</span></a> <a href="https://infosec.exchange/tags/VPN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VPN</span></a> <a href="https://infosec.exchange/tags/PasswordManagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManagers</span></a></p>
Erik van Straten<p><span class="h-card" translate="no"><a href="https://fosstodon.org/@lil5" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>lil5</span></a></span> : passwords *do* prevent phishing on Android and iOS/iPadOS if you set up autofill for your password manager and know what to be aware of.</p><p>Details: <a href="https://infosec.exchange/@ErikvanStraten/113022180851761038" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113022180851761038</span></a></p><p>With Android screenshot: <a href="https://infosec.exchange/@ErikvanStraten/113549056619471557" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113549056619471557</span></a></p><p>BTW passkeys suck: <a href="https://infosec.exchange/@ErikvanStraten/113730072998238596" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113730072998238596</span></a></p><p><span class="h-card" translate="no"><a href="https://hex.st/@robin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>robin</span></a></span> </p><p><a href="https://infosec.exchange/tags/Phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Phishing</span></a> <a href="https://infosec.exchange/tags/Autofill" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Autofill</span></a> <a href="https://infosec.exchange/tags/PasswordManagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManagers</span></a> <a href="https://infosec.exchange/tags/DomainName" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DomainName</span></a> <a href="https://infosec.exchange/tags/Passkeys" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passkeys</span></a> <a href="https://infosec.exchange/tags/WebAuthn" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WebAuthn</span></a> <a href="https://infosec.exchange/tags/Keepassium" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Keepassium</span></a> <a href="https://infosec.exchange/tags/KeePassDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>KeePassDX</span></a> <a href="https://infosec.exchange/tags/PasswordManager" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManager</span></a></p>
Gillinger<p>Can anyone please recommend to me a good free password manager for Android?<br>I was using Bitwarden but it's a bit clunky.<br>Thanks.</p><p><a href="https://mas.to/tags/password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>password</span></a> <a href="https://mas.to/tags/passwordmanagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwordmanagers</span></a> <a href="https://mas.to/tags/android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>android</span></a></p>
frankie (auto-rebootable)<p><span class="h-card" translate="no"><a href="https://fosstodon.org/@Nujtag" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Nujtag</span></a></span> </p><p>as promised, a comparison/review of proton pass and bitwarden :blobcatgiggle: </p><ul><li>Bitwarden is well-established with extensive features, while Proton Pass a newer player offers a polished user experience within the Proton ecosystem.</li><li>Proton Pass has a more refined UI/UX, whereas Bitwarden focuses on functionality.</li><li>Bitwarden offers more organizational tools (folders, multiple organizations), while Proton Pass allows multiple vaults.</li><li>Bitwarden provides more versatile password generation options and password history.</li><li>Both offer secure sharing, but Bitwarden has more free options.</li><li>Both support 2FA, passkeys, and maintain high security standards.</li><li>Proton Pass offers unique features like email aliases and AI-powered security (paid).</li><li>Bitwarden is more affordable, while Proton Pass integrates well with other Proton services.</li></ul><p>my conclusion is that for a basic user, bitwarden is well and good. a lot of proton pass's features are paywalled. <br>but if you're already into the proton ecosystem, you might as well use it 🤷 </p><p><a href="https://infosec.exchange/tags/Bitwarden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Bitwarden</span></a> <br><a href="https://infosec.exchange/tags/ProtonPass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ProtonPass</span></a> <br><a href="https://infosec.exchange/tags/Proton" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Proton</span></a> <br><a href="https://infosec.exchange/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <br><a href="https://infosec.exchange/tags/PasswordManagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManagers</span></a> <br><a href="https://infosec.exchange/tags/FOSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FOSS</span></a></p>
wilhelm<p><span>Can't say I am surprised, but seems </span><a href="https://fedia.social/tags/Bitwarden" rel="nofollow noopener noreferrer" target="_blank">#Bitwarden</a><span> is moving away from </span><a href="https://fedia.social/tags/OpenSource" rel="nofollow noopener noreferrer" target="_blank">#OpenSource</a><span> as per </span><a href="https://github.com/bitwarden/clients/issues/11611" rel="nofollow noopener noreferrer" target="_blank">github.com/bitwarden/clients/issues/11611</a><span><br><br>Glad I never jumped that train and went with </span><span class="h-card" translate="no"><a href="https://fosstodon.org/@keepassxc" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>keepassxc</span></a></span><span> instead, when leaving the </span><a href="https://fedia.social/tags/1Password" rel="nofollow noopener noreferrer" target="_blank">#1Password</a><span> enshittification train, with which I am very happy.<br><br>Any project with </span><a href="https://fedia.social/tags/VentureCapital" rel="nofollow noopener noreferrer" target="_blank">#VentureCapital</a><span> involved is a warning flag. I have seen so many nice software projects go down the </span><a href="https://fedia.social/tags/enshittification" rel="nofollow noopener noreferrer" target="_blank">#enshittification</a><span> path, it's not even funny.<br><br></span><a href="https://fedia.social/tags/passwordmanager" rel="nofollow noopener noreferrer" target="_blank">#passwordmanager</a><span> </span><a href="https://fedia.social/tags/passwordmanagers" rel="nofollow noopener noreferrer" target="_blank">#passwordmanagers</a><span> </span><a href="https://fedia.social/tags/keepass" rel="nofollow noopener noreferrer" target="_blank">#keepass</a><span> </span><a href="https://fedia.social/tags/keepassxc" rel="nofollow noopener noreferrer" target="_blank">#keepassxc</a></p>
Marcus "MajorLinux" Summers<p>Finally I can merge all my keys!</p><p>You'll soon be able to safely and easily move your passkeys between password managers </p><p><a href="https://www.engadget.com/cybersecurity/youll-soon-be-able-to-safely-and-easily-move-your-passkeys-between-password-managers-161025573.html?src=rss" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">engadget.com/cybersecurity/you</span><span class="invisible">ll-soon-be-able-to-safely-and-easily-move-your-passkeys-between-password-managers-161025573.html?src=rss</span></a></p><p><a href="https://toot.majorshouse.com/tags/Passkeys" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passkeys</span></a> <a href="https://toot.majorshouse.com/tags/PasswordManagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManagers</span></a> <a href="https://toot.majorshouse.com/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://toot.majorshouse.com/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://toot.majorshouse.com/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://toot.majorshouse.com/tags/Tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tech</span></a></p>
GÉANT<p>Your email can be used to both reset and recover access to all other services, so it's extremely important to use a strong and memorable <a href="https://mstdn.social/tags/password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>password</span></a> for it.</p><p>David Heed ( <span class="h-card" translate="no"><a href="https://social.sunet.se/@sunet" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>sunet</span></a></span> ) joins our <a href="https://mstdn.social/tags/CyberSecMonth" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecMonth</span></a> campaign, sharing some tips about <a href="https://mstdn.social/tags/PasswordSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordSecurity</span></a>.</p><p>🔗 <a href="https://connect.geant.org/csm24" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">connect.geant.org/csm24</span><span class="invisible"></span></a></p><p><span class="h-card" translate="no"><a href="https://mastodon.social/@nordunet" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nordunet</span></a></span> <a href="https://mstdn.social/tags/CSM24" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CSM24</span></a> <a href="https://mstdn.social/tags/CyberSecurityAwareness" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurityAwareness</span></a> <a href="https://mstdn.social/tags/Research" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Research</span></a> <a href="https://mstdn.social/tags/Education" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Education</span></a> <a href="https://mstdn.social/tags/NRENs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NRENs</span></a> <a href="https://mstdn.social/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://mstdn.social/tags/PasswordManagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordManagers</span></a></p>
Victoria (K8VSY) (she/her)<p>What does your password manager set up look like?</p><p><a href="https://mastodon.radio/tags/password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>password</span></a> <a href="https://mastodon.radio/tags/passwords" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwords</span></a> <a href="https://mastodon.radio/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://mastodon.radio/tags/passwordmanager" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwordmanager</span></a> <a href="https://mastodon.radio/tags/passwordsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwordsecurity</span></a> <a href="https://mastodon.radio/tags/passkey" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passkey</span></a> <a href="https://mastodon.radio/tags/2FA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>2FA</span></a> <a href="https://mastodon.radio/tags/MFA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MFA</span></a> <a href="https://mastodon.radio/tags/passwordmanagers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwordmanagers</span></a> <a href="https://mastodon.radio/tags/passwordless" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwordless</span></a> <a href="https://mastodon.radio/tags/Lastpass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Lastpass</span></a> <a href="https://mastodon.radio/tags/Keepass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Keepass</span></a> <a href="https://mastodon.radio/tags/KeepassXC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>KeepassXC</span></a> <a href="https://mastodon.radio/tags/ProtonPass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ProtonPass</span></a> <a href="https://mastodon.radio/tags/1password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>1password</span></a> <a href="https://mastodon.radio/tags/bitwarden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bitwarden</span></a> <a href="https://mastodon.radio/tags/secure" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>secure</span></a> <a href="https://mastodon.radio/tags/securityawareness" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>securityawareness</span></a> <a href="https://mastodon.radio/tags/cloud" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cloud</span></a> <a href="https://mastodon.radio/tags/cloudstorage" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cloudstorage</span></a></p>
A répondu dans un fil de discussion

W.r.t. password managers (pw mgrs):

1) Make sure that you *NEVER* forget your master password.

2) Make an *OFFLINE* backup of the (encrypted) pw database after each modification. For example, rotate between multiple USB storage media.

3) Use a pw mgr that can generate strong (random, long, unguessable) passwords. Use that functionality to generate a unique pw for each account.

LAST BUT NOT LEAST
4) At least on mobile devices, configure the OS and pw mgr to locate your credentials *automatically* based on the domain name of the website you're visiting (using "autofill", which lets the OS pass the domain name –as used by the browser– to the pw mgr).

EXAMPLE WHY
If you receive an email (with SPF, DKIM and DMARC all fine) from:

    whomever@circle-ci.com

that instructs you to revalidate your 2FA settings in, e.g.:

    https:⧸⧸circle-ci.com/revalidate

Then a properly configured pw mgr will not come up with ANYTHING - because the record is for (without the dash):

    https:⧸⧸circleci.com

The deja vu after the 2022 attack (github.blog/news-insights/comp), described in discuss.circleci.com/t/circlec, is still alive and kicking since March this year (see crt.sh/?q=circle-ci.com and virustotal.com/gui/domain/circ). The fake site even looks better than the original one (I don't know whether it is actually malicious, or will just warn users who attempt to log in).

NOTE: if your pw mgr does not find a matching record in the pw mgr database, do NOT manually locate the "circleci.com" record. If you do: do NOT autofill or copy/paste your credentials for https:⧸⧸circleci.com to https:⧸⧸circle-ci.com! Using those creds, the fake site may immediately log in to the authentic website AS YOU - pwning your account.

WHAT I'M USING
I'm using KeePassium on iOS and KeePassDX on Android; they work just fine (disclaimer: I'm not in any way related to their authors, and do no warrant their reliability).

@steelefortress

The GitHub Blog · Security alert: new phishing campaign targets GitHub usersOn September 16, GitHub Security learned that threat actors were targeting GitHub users with a phishing campaign by impersonating CircleCI to harvest user credentials and two-factor codes. While GitHub itself was not affected, the campaign has impacted many victim organizations.

This is why storing passwords in the browser, any browser, is a bad idea. Keep them on a password manager and back it up. Many alternatives available. #infosec #passwords #passwordmanagers

Google Says Sorry After Passwords Vanish For 15 Million Windows Users

forbes.com/sites/daveywinder/2

Forbes · Google Says Sorry After Passwords Vanish For 15 Million Windows UsersPar Davey Winder

Getting security online right seems like a daunting task. But one thing is certain: Password managers help! 💪

🔥Here are our top three: tuta.com/blog/best-password-ma 🔥

What are your favorite #PasswordManagers❓

TutaWhy Use A Password Manager - And Our Top 3!It's 2024, choose the best password manager already! Why you should use one? They're easy tools to increase your privacy and security.