Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
33Backpack33
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
1.
▲
by
33Backpack33
5y ago
For the average person it's best they use a cloud password manager as they're not responsible enough to do their own backups of a local password manager.
2.
▲
by
33Backpack33
5y ago
You could do that salt and pepper thing found here: https://passwordbits.com/salting-passwords/ This way you don't store your full password in your password manager.
3.
▲
by
33Backpack33
5y ago
As far as I can tell Bitwarden doesn't inject any scripts. I know people complain it doesn't have that overlay like LastPass has but Bitwarden not having might be a plus now.
4.
▲
by
33Backpack33
6y ago
The original VICE article said it was $16 and they can take as many accounts as they want. It seems worth it to me.
5.
▲
by
33Backpack33
6y ago
You do know uber and doordash accounts are hacked all the time because of password reuse? There is a huge black market for hacked accounts from doordash and the like.
6.
▲
by
33Backpack33
6y ago
Not when script kiddies already have free tools like this https://vimeo.com/308709275
7.
▲
by
33Backpack33
6y ago
If we all agree it's not secure then why do we keep using it? I rather have a unique password then rely on SMS anything especially if that account allows you to reset your password by SMS.
8.
▲
by
33Backpack33
6y ago
username + unique password would be better than all the other options listed. Adding SMS seems to add new points of attack that either hurt the user or just delays the hurting.
9.
▲
by
33Backpack33
6y ago
When you consider SMS 2FA is often used to fix the poor or reused password problem we see it's not helping much at all but only delaying the problem.
10.
▲
by
33Backpack33
6y ago
It doesn't stop it but delays it. The attacker seeing a SMS 2FA screen doesn't mean they give up, it just means the user is now more valuable. This explains it https://passwordbits.com/dont-need-sms-2fa/
11.
▲
by
33Backpack33
6y ago
This article goes more in depth and answers the questions you bring up https://passwordbits.com/dont-need-sms-2fa/
12.
▲
by
33Backpack33
6y ago
This article does a better job of explaining how SMS 2FA doesn't solve the credential stuffing problem. https://passwordbits.com/dont-need-sms-2fa/
13.
▲
We Don’t Need SMS 2FA – Replacement Included
(passwordbits.com)
3 points
by
33Backpack33
6y ago
|
0 comments
14.
▲
by
33Backpack33
6y ago
Nothing more lazy than doing something like generate a password for the user. The way most browsers work you have to go out of your way to not let it save and fill passwords. If you create the password for the user they can't reuse it
15.
▲
by
33Backpack33
6y ago
If they made it that far to get your password why do they need to log into your account? Having multiple locks on your door don't matter if they got in through a window.
16.
▲
by
33Backpack33
7y ago
The paper also said, "websites should eliminate SMS based MFA altogether".
17.
▲
by
33Backpack33
7y ago
If it's nothing new then why do people keep saying it's better to have SMS 2FA then to not have it. The research says "websites should eliminate SMS based MFA altogether".
18.
▲
by
33Backpack33
7y ago
So can we finally stop saying it's better to have SMS 2FA then to not have it?!
19.
▲
by
33Backpack33
7y ago
Report for child labor!
20.
▲
by
33Backpack33
7y ago
I find a password manager is more than just for passwords. I store PIN codes, Code, security questions, important notes, and so many other things.
21.
▲
by
33Backpack33
7y ago
It's too expensive for what it does and don't trust it mostly from its auto password changer does it on their servers.
22.
▲
by
33Backpack33
7y ago
Isn't most OS's now blocking read access to text fields labeled as "password"? I'm pretty sure MacOS does this now.
23.
▲
by
33Backpack33
7y ago
I've confirmed it because you can see the data that the web browsers sends and it was encrypted. I've also tested this on LastPass and Bitwarden and from what I can see 1Password does it the best.
24.
▲
by
33Backpack33
7y ago
Can we not submit to Google to shut down for spreading malware or get the domain registrar involved?