epixoip, to random

Happy #WorldPasswordDay!

I've cracked billions of #passwords from tens of thousands of #data #breaches in the past 12+ years, and because of this, I likely know at least one #password for 90% of people on the Internet. And I'm not alone! While I primarily crack breached passwords for research purposes and the thrill of the sport, others are selling your breached passwords to criminals who leverage them in #AccountTakeover and #CredentialStuffing attacks.

How can you keep your accounts safe?

  • Use a #PasswordManager! I recommend @bitwarden and @1password

  • Use a #Diceware style #passphrase - four or more words selected at random - for passwords you have to commit to memory, like your master password!

  • Enable MFA for important online accounts, including cloud-based password managers!

  • Harden your master password by tweaking your password manager's KDF settings! For #Bitwarden, use Argon2id with 64MB memory, 3 iterations, 4 parallelism. For #1Password and other PBKDF2 based password managers, set the iteration count to at least 600,000.

  • Use unique, randomly generated passwords for all your accounts! Use your password manager to generate random 14-16 character passwords for everything. Modern password cracking is heavily optimized for human-generated passwords, because humans are highly predictable. Randomness defeats this and forces attackers to resort to incremental brute force! There's no trick you can do to make a secure, uncrackable password on your own - your meat glob will only betray you.

  • Use an ad blocker like #uBlock Origin to keep you safe from password-stealing #malware and other browser based threats!

  • Don't fall for #phishing attacks and other social engineering attacks! Browser-based password managers help defend against phishing attacks because they'll never autofill your passwords on fake login pages. Think before you click, and never give your passwords to anyone, not even if they offer you chocolate or weed.

  • #Enterprises: require ad blockers, invest in an enterprise password management solution, audit password manager logs to ensure employes aren't sharing passwords outside the org, implement a Fine Grained Password Policy that requires a minimum of 20 characters to encourage the use of long passphrases, implement a password filter to block commonly used password patterns and compromised passwords, disable #NTLM authentication and disable RC4 for #Kerberos, disable legacy broadcast protocols like LLMNR and NBT-NS, require mandatory #SMB signing, use Group Managed Service Accounts instead of shared passwords, monitor public data breaches for employee credentials, and crack your own passwords to audit the effectiveness of your password policy and user training!

ilyess, to security
@ilyess@mastodon.online avatar

If you're using #bitwarden, make sure to change the KDF algorithm to Argon2id^1 which is much more robust against GPU-powered attacks compared to its counterpart.

You can play around with this little calculator to see the impact of each algorithm on cracking cost estimation: https://passwordbits.com/passphrase-cracking-calculator/

#security #infosec #password

masek, to bitwarden German

My setup:

  • Primary storage ist via with a local installation (both needs to be version 23.10 at least)
  • Secondary storage is a 5 NFC which I carry with me. This one alllows me to use the passkey on my iPhone (iPad not tested yet)
  • Tertiary storage is another (cheaper) Yubikey which is deposited in a safe at home

Both Yubikeys are protected by a PIN which my wife knows. That way I canot lose access to my account and have taken precautions in case I become incapacitated.

But this setup requires quite some time for each web site to switch to passkeys. That's why I am so angry with companies like Paypal who make it practically unusable.

Edent, to bitwarden
@Edent@mastodon.social avatar

🆕 blog! “HOWTO: Sort BitWarden Passwords by Date”

I highly recommend BitWarden as a password manager. It is free, open source, and has a great range of apps and APIs. The one thing it doesn't have is a way to sort your accounts by creation date. I now have over a thousand accounts that I've added - so I wanted to prune away […]

👀 Read more: https://shkspr.mobi/blog/2024/02/howto-sort-bitwarden-passwords-by-date/

#bitwarden #HowTo #json #linux

tuxwise, to passkeys

2.7.7 released:

Don't be shy, @keepassxc - post about it, here, on Mastodon 😉

https://keepassxc.org/blog/2024-03-10-2.7.7-released/

governa, to bitwarden
@governa@fosstodon.org avatar
fabio, to bitwarden
@fabio@manganiello.social avatar

Just migrated from to .

Same API, same features, same UI, and support for other DBs than MSSQL.

One single stand-alone application vs. Bitwarden’s 10 Docker containers. 70MB of RAM vs. 2GB. 3MB of db storage vs. 300MB.

Why was a password manager supposed to take so many resources in the first place? Just because it runs on a Microsoft-only stack and on .NET’s inefficient VM? Just because somebody thought that it was a good idea to separate everything into different containers (even icons and 2fa are modeled as separate services in Bitwarden)?

It reminds me of my recent migration from Mastodon to Akkoma. I got more features, 5GB of RAM freed up and 300GB of storage freed up almost overnight.

Writing and running inefficient software that pointlessly consumes all the resources available on a machine should be a crime in a world with limited resources.

It makes me think of how much shitty bloated software like @bitwarden, probably based on awfully inefficient languages and frameworks like Java, Ruby on Rails and .NET, is running out there, pointlessly sucking up resources for doing simple jobs that could easily be done with 99% less resources.

Today’s developers, spoiled by IDEs, powerful machines, docker-compose and shortsighted “just throw more RAM at the problem” approaches, have forgotten how to write efficient software. Time for them to learn how to write good efficient software again. Software doesn’t eat the world. Only shitty software built on shitty framework does.

chfkch, to bitwarden
@chfkch@ruhr.social avatar

Since i am not celebrating this day for some reasons, i have time to code while my family is asleep. The last hour, i implemented the wrapper functions, for setting up/logging in/unlocking accounts and saving state to the db for the client.
We are getting somewhere.
Some GUI stuff and decryption is still on the list before you can check out the code.

inlovewithpda, to bitwarden
@inlovewithpda@chaos.social avatar

Is a good alternative to . Or what is the best way to have a password manager on Mac, iPhone and Linux with hosting a Family support?

gunther, to Signal
@gunther@fosstodon.org avatar

Somewhat inspired by @theprivacydad's most recent blog post, here's a list of privacy-friendly software that "just works" about as well as (if not better than) more invasive alternatives, even for the relatively non-tech savvy:

#uBlockOrigin
#Signal
#Bitwarden
#Firefox and/or #Brave
#StandardNotes
#Startpage (@StartpageSearch), #DuckDuckGo, or #BraveSearch
#Aegis
#AntennaPod (@AntennaPod)

markstos, to bitwarden
@markstos@urbanists.social avatar

I notified in early May that they have a security error on their homepage. It's still there. They don't care. They also wouldn't have the problem if they didn't have so many trackers on their homepage.

and are better options for password managers, among others.

unixtippse, to bitwarden German
@unixtippse@mastodon.online avatar

Ach so, 100 Millionen Venture Capital in #Bitwarden. Muss ich meiner Schwiegermutter demnächst etwa schon wieder einen anderen Passwortmanager an die Backe labern? 🙄

gracjan, to bitwarden

added support () for for all users (including those on a free plan). The ability to use Bitwarden to store passkeys for other things and to login to Bitwarden using just a passkey (without a password) is coming soon. https://bitwarden.com/blog/fido2-webauthn-2fa-in-all-bitwarden-plans

danie10, to bitwarden
@danie10@mastodon.social avatar

Bitwarden finally brings 2FA logins to free users

Previously, you had to pay for Bitwarden’s premium plan to add 2FA for your stored logins. Bitwarden is claiming they are the only password manager to now include 2FA logins for free.

As a paying customer, I’ve long been using Bitwarden’s 2FA for logins, a ...continues

See https://gadgeteer.co.za/bitwarden-finally-brings-2fa-logins-to-free-users/

governa, to bitwarden
@governa@fosstodon.org avatar

Adds Support for - Release Notes :bitwarden:

https://bitwarden.com/help/releasenotes/

redux, to 11ty Portuguese
@redux@fosstodon.org avatar
chfkch, to linuxphones
@chfkch@ruhr.social avatar

My first (very incomplete and WIP) iteration of my client. It ia usually not ready for others to use, but i need to publish it to stay motivated.
Works with aswell. You have to build it fron source though, for the time being.

https://codeberg.org/Chfkch/bitritter

chfkch, to linuxphones
@chfkch@ruhr.social avatar

My fellow fedizens, i have done it.
I have applied #BitRitter to https://nlnet.nl/propose/ in the category "Open Call". Well at least 2 features i want to implement.
Wish me luck.

If you have an awesome Mobile FOSS Project, maybe you want to apply too? Deadline is 2024-06-01 so this friday. Application process took me about half an hour, so that's doable.

@NGIZero

#LinuxMobile #Relm4 #gtk
#rbw #BitWarden #Vaultkwarden

devol, to bitwarden Italian
@devol@mastodon.uno avatar

Come già annunciato da diversi mesi i servizi per la gestione delle password ed per la sono migrati alle 24 del 24/1/24 e sono ora disponibili qua:

:bitwarden: https://vaultwarden.devol.it
è sostanzialmente lo stesso software open source compatibile al 100% con bitwarden, il progetto è stato rinominato dallo sviluppatore.

🗒️ https://etherpadmypads.devol.it
ora usiamo il nome completo del progetto e gira su un server più stabile.

BenjaminHCCarr, to Health
@BenjaminHCCarr@hachyderm.io avatar

data : Hackers stole raw data, reports
The used by the attackers to breach the customers' accounts were stolen in other data breaches or used on previously compromised online platforms. https://www.bleepingcomputer.com/news/security/23andme-data-breach-hackers-stole-raw-genotype-data-health-reports/

Please get a like . And please for the of all that is holy so

thomy2000, to firefox
@thomy2000@fosstodon.org avatar

Just finished helping my grandfather solve some of his issues with . He didn't know how to create lists of contacts. I quickly set this up and closed maybe 1000 tabs (I don't know how he opened that many). I was also surprised to see he still uses , although all his extensions were gone. Reinstalled , and . Now he's fully open sourced again. He even mentioned that he thought about sponsoring Thunderbird.

badnetmask, to Blog
@badnetmask@hachyderm.io avatar

New post! As I have promised multiple times, I'm demonstrating how you can use to read passwords (and other secrets) from (and as well). I hope this gives you fuel to your secrets in your . Happy automating!
https://mteixeira.wordpress.com/2024/04/04/ansible-vaultwarden/

governa, to bitwarden
@governa@fosstodon.org avatar
knightdave, to bitwarden Polish
@knightdave@mastodon.com.pl avatar

Każdemu komu rekomenduje założyć sejf w aplikacji od razu polecam kupić pendrivea za 20-30zł i robić szyfrowane kopie od czasu do czasu, a sam takich nie mam :D

Czas to zmienić! Kupiłem małego sandiska, utworzyłem szyfrowany kontener z pomoca i na niego zrzuciłem backup.

Teraz mogę spać spokojnie.

jpmens, to random
@jpmens@mastodon.social avatar

deleted_by_author

  • Loading...
  • unixtippse,
    @unixtippse@mastodon.online avatar

    @jpmens 😣 I've already tested the exporter, it's crazy barebones but works. Also, includes verbatim seeds in its export JSON. Do with that information whatever you wish. 🤐 https://github.com/token2/authy-migration

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • tacticalgear
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • ethstaker
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • lostlight
  • All magazines