mastouille.fr: À propos · Annuaire des profils · Politique de confidentialité
Mastodon: À propos · Télécharger l’application · Raccourcis clavier · Voir le code source · v4.3.4
W.r.t. password managers (pw mgrs):
1) Make sure that you *NEVER* forget your master password.
2) Make an *OFFLINE* backup of the (encrypted) pw database after each modification. For example, rotate between multiple USB storage media.
3) Use a pw mgr that can generate strong (random, long, unguessable) passwords. Use that functionality to generate a unique pw for each account.
LAST BUT NOT LEAST
4) At least on mobile devices, configure the OS and pw mgr to locate your credentials *automatically* based on the domain name of the website you're visiting (using "autofill", which lets the OS pass the domain name –as used by the browser– to the pw mgr).
EXAMPLE WHY
If you receive an email (with SPF, DKIM and DMARC all fine) from:
whomever@circle-ci.com
that instructs you to revalidate your 2FA settings in, e.g.:
https:⧸⧸circle-ci.com/revalidate
Then a properly configured pw mgr will not come up with ANYTHING - because the record is for (without the dash):
https:⧸⧸circleci.com
The deja vu after the 2022 attack (https://github.blog/news-insights/company-news/security-alert-new-phishing-campaign-targets-github-users/), described in https://discuss.circleci.com/t/circleci-security-alert-warning-fraudulent-website-impersonating-circleci/50899, is still alive and kicking since March this year (see https://crt.sh/?q=circle-ci.com and https://www.virustotal.com/gui/domain/circle-ci.com/detection). The fake site even looks better than the original one (I don't know whether it is actually malicious, or will just warn users who attempt to log in).
NOTE: if your pw mgr does not find a matching record in the pw mgr database, do NOT manually locate the "circleci.com" record. If you do: do NOT autofill or copy/paste your credentials for https:⧸⧸circleci.com to https:⧸⧸circle-ci.com! Using those creds, the fake site may immediately log in to the authentic website AS YOU - pwning your account.
WHAT I'M USING
I'm using KeePassium on iOS and KeePassDX on Android; they work just fine (disclaimer: I'm not in any way related to their authors, and do no warrant their reliability).
This is why storing passwords in the browser, any browser, is a bad idea. Keep them on a password manager and back it up. Many alternatives available. #infosec #passwords #passwordmanagers
Google Says Sorry After Passwords Vanish For 15 Million Windows Users
Boosts welcome & encouraged. Thank you!
How often do you change your Master Password for your password manager? Every:
What a surprise: @bitwarden explains setting up 2fa with Tuta Mail (slide 39)!
https://bitwarden.com/resources/presentations/the-triangle-of-security-success/
And rightly so: Because #encrypted email get even more secure with #2FA and #passwordmanagers
Getting security online right seems like a daunting task. But one thing is certain: Password managers help!
Here are our top three: https://tuta.com/blog/best-password-manager
What are your favorite #PasswordManagers
Mastodon est le meilleur moyen de suivre ce qui se passe.
Suivez n'importe qui à travers le fédivers et affichez tout dans un ordre chronologique. Ni algorithmes, ni publicités, ni appâts à clics en perspective.
Créer un compteSe connecter