5 ms·
This in itself sounds like a phishing attack. Is the mail authentic?
by buschkowitz 8y ago
This in itself sounds like a phishing attack. Is the mail authentic?
- Bombthecat 8y agoNot a mail.you get that message when logging in to Google. I first thought that too.and tried another browser ( got that message in Vivaldi first,than tried IE) Same result. Here are some old articles about that: https://www.recode.net/2017/3/24/15054954/google-reassures-users-government-backed-hackers https://www.recode.net/2017/3/24/15054954/google-reassures-u... http://www.zdnet.com/article/google-heres-why-you-shouldnt-flip-out-over-government-backed-hacker-alerts/ http://www.zdnet.com/article/google-heres-why-you-shouldnt-f...
- buschkowitz 8y agoYea, it does look legit after reading the articles you posted. I am not a hacker per se, but I guess uncovering what a gov hacker did in your account is highly difficult. In terms of safety, use a password manager that creates and stores hard-to-crack passwords for you. I am pretty happy with Dashlane, 1password has a good reputation, too.
- zaphirplane 8y agoWhat ! Don’t use a password manager and turn on 2 factor Authentication
- amingilani 8y agoAbsolutely use a password manager, and a strong passphrase for the master password [1] Why would you say not? I'm not trying to be rude or anything. Let's have a discussion, and if I can convince you to do use one, I'd have made one more person safer. [1] I made this for a dead simple way to make passphrases: https://amingilani.github.io/password-maker/ https://amingilani.github.io/password-maker/
- herbst 8y agoNot OP but open for a chance. Last time I checked the popular password managers saved the passwords in one way or another. Which personally simply sounds like a bad idea to begin with. Even if in theorie they are safe. Even the slight chance that a single failure could lead to all my passwords getting in the wrong hands at once just is to scary.
- Angostura 8y agoI must admit, I use Apple’s Keychain, I wouldn’t trust a third party app.
- chopin 8y agoDo you have citations for this? AFAIK state of the art is to put the password through some password stretching algorithm (like PKBDF) and to encrypt the database with that. No need to store the password. I think NaCL offers out-of-the-box support for this. EDITED to add: I am using Password Safe which is recommended by Bruce Schneier. What you describe would be an absolute noob mistake. He would be pretty embarrassed if you were right.
- icebraining 8y agoI think herbst is saying that password managers store the passwords being managed, not the master password used to encrypt the DB.
- mercer 8y agoHow do you propose one memorizes a properly random/secure/long password, let alone multiple ones, without trusting 'something' with it, whether a password manager of good repute, a hand-rolled version with potentially bigger security issues, or a piece of paper somewhere?
- c22 8y agoI've memorized multiple long passwords, and routinely memorize new ones. Also phone numbers, poems, mailing addresses, digits of pi, etc. It's not really that challenging. Especially if you do it often.
- DyslexicAtheist 8y agointeresting. does anyone know how ProtonMail handles such situations and whether they alert their users?