[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

>LastPass password manager suffers 'major' secu

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 197
Thread images: 19

File: LP.png (9KB, 500x100px) Image search: [Google]
LP.png
9KB, 500x100px
>LastPass password manager suffers 'major' security problem

http://www.independent.co.uk/life-style/gadgets-and-tech/news/lastpass-hack-security-problem-password-manager-a7658806.html

>LastPass users are being advised to avoid the password manager while it addresses a “unique and highly sophisticated” security issue.
>LastPass hasn’t revealed any further details about the problem, but Google’s Project Zero security researcher Tavis Ormandy, who discovered it, says it’s a serious one.
>“It will take a long time to fix this properly, it's a major architectural problem,” he tweeted.
>we’d recommend disabling LastPass’ browser plugins, just to be on the safe side.
>>
>>59664122
HAHAHAHAHAHAHA
>>
KeePass #1
>>
>not using Master Password
>not being Master Race
>>
>>59664177
but I'm lazy

I'd rather unlock a database once and have my username/emails and passwords available instantly
>>
Why have these things?

I store my shit on my browser.
>>
>>59664267
>I store my shit on my browser.

As you should. Some people are just too retarded to handle that though.
>>
>we’d recommend disabling LastPass’ browser plugins, just to be on the safe side.

Lastpass has not said this

fake news
sage
>>
>>59664311
Are you mentally retarded or just a fucking idiot?
>>
>>59664326
https://blog.lastpass.com/2017/03/security-update-for-the-lastpass-extension.html/

Fucking mouth breather
>>
>>59664351
>being this angry cause your shitty password manager got BTFO
>>
>>59664372
>lie
>get called out
>try to damage control
>get called out with sources
>lol u mad bro?

Goddamn dimwit
>>
>>59664351
>>59664393
Confirmed for retarded.
>>
>>59664423
The idea of storing a password database in the cloud is completelly retarded.
>>
>>59664552
Yes, indeed it is.
>>
is there anything that can read the lastpass export and put it into a cleaner list?
>>
>>59664744
Post your export and I'll clean it for you.
>>
>>59664744
I don't know what the lastpass export looks like, but I would assume it could be cleaned up with a simple script.
>>
>>59664267
>>59664284

Enjoy having a 13 year old with an install of darkcomet steal your banking info
>>
>>59664845
Enjoy having down syndrome. Retard.
>>
>>59664853
How so?
>>
Is there a password manager where I enter all my passwords into it, it autofills websites on my PC, but I have to use the fingerprint scanner on my phone to do it?
>>
>>59664845>>59664845
You've have to be retarded to have darkcomet on your systme unchecked.
>>
>>59664945
What is a crypter? Retardo.
>>
>>59664122
>not using UNIX pass
Jesus fucking Christ is this board full of retards or what?
>>
>>59664985
How can you be so profoundly retarded and still manage to continue breathing?
>>
File: laughing.jpg (20KB, 400x266px) Image search: [Google]
laughing.jpg
20KB, 400x266px
>>59665009
>it's a retard calling everybody else retards episode again
>>
>>59664991
If you weren't such a newfag then you'd know this board is literally full of retards.
>>
>>59664905
Avast sends a push notification to your phone.
>>
File: 1411504280228.jpg (7KB, 225x225px) Image search: [Google]
1411504280228.jpg
7KB, 225x225px
>>59665021
>>
>>59664991
Can't even compare to the glory of Master Password.

Pleb.
>>
>>59665122
enjoy ur botnet
>>
>>59665144
>literally offline
>botnet
You've exposed yourself as a complete retard.
>>
>>59664122
>using a password manager and not memorizing unique random keyed passwords for everything

retards
>>
>>59664311
>he thinks a company would actually tell you to stop using their software

Holy kek, you're fucking dumb.
>>
>>59665175
>he doesn't know about the offline botnet
Holy shit this guy everyone
>>
>>59665223
You've already outed yourself as a retard, there's no need to prove how retarded you actually are.
>>
File: 1487484034887.png (47KB, 518x518px) Image search: [Google]
1487484034887.png
47KB, 518x518px
>>59665283
>calls others retard
>doesn't realize they are the true retard
really gets the ole noggin a joggin
>>
Why would anyone use a password manager? It's seems like a fucking retarded idea to trust all your passworss with some idiot developers.
>>
>2017
>Not keeping all your passwords encrypted manually onto a piece of paper in invisible ink and storing it in a bulletproof safe in a vault.
>>
>>59665340
>makes an ironic shitpost about calling people retards
>doesn't realize he's profoundly retarded

really gets the ole noodle a doodling
>>
>>59664351
>ctrl f "recommend" to see which one of you is retarded
>recommend not found
wew lad everyone in here is retarded
>>
File: 1451752603148.jpg (10KB, 285x177px) Image search: [Google]
1451752603148.jpg
10KB, 285x177px
>>59665379
>invisible ink
>>
>>59665355

Same reason Geek Squad can stay in business
Same reason OS X and iOS are popular
>>
I like how every password manager thread always devolves into everyone calling each other retarded. I take it as proof that password managers are retarded programs made for retarded "people".
>>
is 1password any better?
>>
>>59665455
Easy way to boost personal security (i.e. avoiding shared, easily guessable, whatever passwords).

I'm not trying to fight off the NSA or anything, but now I have unique, """strong""" passwords for all the accounts I care about with little to no inconvenience to me.

Also for what it's worth, KeePass (and probably others) make it easy to change your passwords on a schedule if you desire.

Guess you can place lazy and retarded people in the same camp.
>>
File: 1485150861452.png (34KB, 171x160px) Image search: [Google]
1485150861452.png
34KB, 171x160px
>>59665392
>Replies to an ironic shitpost
>Calls poster retarded
>Doesn't realize he in fact is the retarded one
>>
>>59665568
Yes. Not worth it as individual, so get your whole family on it.
>>
>>59665597

why not as an individual?
>>
>>59665597
Whole family? Would my wife and her boyfriend and I count as a family?
>>
>>59665614
Cause the more passwords in one place, the better. Trust me I'm an expert.
>>
>>59665672

oh I see, you're an expert, thanks!
>>
File: incredulous.jpg (5KB, 182x180px) Image search: [Google]
incredulous.jpg
5KB, 182x180px
>>59664122
>using anything based on the ""cloud""
>especially trusting passwords on said """"cloud""""
>>
What's the best way of creating unique passwords for every service you use without using a password manager?
>>
>>59665723
the passwords don't leave your PC, only an encrypted container which is essentially random data
>>
>>59665771
>the passwords don't leave your PC, only an encrypted container which is essentially random data

So is Keepass and it doesn't have this problem tho.
>>
>>59665766
Memorizing a single password at least 32 characters long which was randomly generated.
>>
>>59665798
This has nothing to do with the passwords on the "cloud" being broken, idiot. The plugin is where the problem is, and that could happen to keepAss too if it was integrated to the browser.
>>
>>59665830
wow ur a rude dude
>>
>>59665830
Keepass still doesn't have this problem tho.
>>
>>59665869
sorry.
>>
>>59665766
Use only emojis
>>
>>59665877
We don't even know what the problem is though. It possibly could, we just don't know yet, or the project zero people haven't looked into it yet.

The problem could be anything from a leak in the browser plugin, to a failure at the encryption stage.
>>
>>59665877
and it still doesn't have browser integration
#btfo

And before you say keefox, that plugin is spotty, doesn't work with firefox forks, is going to break with FF soon when xul is deprecated, and may very well have the same vulnerabilities as lastpass
>>
>>59665892
>The problem could be anything from a leak in the browser plugin, to a failure at the encryption stage.
It's some kind of privilege escalation problem https://twitter.com/taviso/status/845717082717114368
>>
>>59665892

Probably the browser plugin. Not the first time it has caused issues.
>>
>>59665830
>http://www.independent.co.uk/life-style/gadgets-and-tech/news/lastpass-hack-security-problem-password-manager-a7658806.html
>“It will take a long time to fix this properly, it's a major architectural problem"

I don't think it's just the fucking addon from this quote, you fuck.

>>59665896
>and it still doesn't have browser integration

Who gives a shit? Never stopped me or anyone else using it. Does your mom still wipe your ass?

>and may very well have the same vulnerabilities as lastpass

Lol doubt it. Enjoy being wrong, again.
>>
>>59665910
LASTPUSSY BTFO!
>>
>>59665920
>I don't think it's just the fucking addon from this quote, you fuck.
>hurr hurr look at me I'm stupid
https://twitter.com/taviso/status/845717082717114368

>Lol doubt it. Enjoy being wrong, again.
Nobody has ever audited keefox because compared to lastpass, practically nobody uses it. It's probably full of holes a google-tier researcher could find.
>>
>>59665798
>>59665877

I trust the developers of the dozens of KeePass programs even less than I trust LastPass at this point. Didn't one of them purposefully leave a MITM exploit unpatched for advertising money? There's a dozen other options for KeePass programs, but I have no idea how much outside scrutiny any of these programs has had.

I think I'm going to look into 1Password instead. They seem to have a pretty good track record.
>>
>>59665959
1password is all closed-source so I would trust it even less with encryption
>>
File: 1473827620629.jpg (150KB, 575x323px) Image search: [Google]
1473827620629.jpg
150KB, 575x323px
>>59664122
>trusting anybody or any software with your passwords
>not writing them down on a notepad
I seriously hope you guys don't do this
>>
>>59665955
>hurr hurr look at me I'm stupid
>https://twitter.com/taviso/status/845717082717114368

Still waiting on you to prove your claim it's the addon.

>keefox

I don't use this and never mentioned it. You did, therefore, dropped.
>>
>>59665959
>KeePass

Keepass passed an audit by the European union and found a couple negligible issues. I think I know what to trust.

https://www.ghacks.net/2016/11/22/keepass-audit-no-critical-security-vulnerabilities-found/
>>
>>59666005
>Still waiting on you to prove your claim it's the addon.
Are you unironically retarded? What else would a privilege escalation vuln mean? Do you think he got codeexed on Lastpass servers?

>I don't use this and never mentioned it. You did, therefore, dropped.
No addon for you then, loser. I'd rather take the 0.000001% risk of the addon leaking something than laboriously copy-paste everything from a separate program tens of times a day
>>
>>59666047
>Are you unironically retarded? What else would a privilege escalation vuln mean? Do you think he got codeexed on Lastpass servers?

Still waiting on you to prove your claim it's the addon.

>No addon for you then, loser

Don't care, it has autofill without addons. Mommy still wipe your ass then?
>>
>>59666072
>Still waiting on you to prove your claim it's the addon.
It's either the addon or he hacked to the lastpass servers, which he didn't do, otherwise he would have said just that. Your IQ must be sub-80 so there's no point in me trying to explain this to you further, you won't get it anyway
>>
>>59666098
So you can't prove your claim. Better luck next time sweetie.
>>
>>59666047
>laboriously copy-paste
Who copy-pastes with KeePass? Just use autotype
>>
>>59666151
>Who copy-pastes with KeePass? Just use autotype

Shhhh, he prefers using vulnerable plugins.
>>
>>59666019
Does that include keepass2?
>>
>>59665766
"site"passwordstring
Won't help if you're specifically targeted, but it will stop an automated attempt spamming your username/password from finding any other matches.
>>
>>59666180
Vulnerable plugins that don't even work except on Windoze
>>
>>59666151
>goto site
>find your keepass window
>search for the site you're currently at
>press ctrl-v
>wait for the slow auto-type to finish
vs
>goto site
>have the field filled out for you
>>
>>59665959
It's regular keepass that had that issue, and the "MITM attack" is just the software letting you know an update is available
>>
>>59665355
Because the reality of Internet security is that passwords are hot fucking garbage and you end up with the choice of either finding a convenient way to manage your huge passwords or not having secure passwords at all
>>
>>59666019
That's an audit of the "official" Windows version of the old deprecated 1.x branch of KeePass. 2.x is a completely different codebase written in .NET of all things.
>>
>>59665355
You haven't really thought this through, have you.

If you don't have a password manager, you probably have a few passwords that you use everywhere. About the best you can possibly do is maybe have a site-specific suffix, but if somebody owns a site and decrypts your password they can probably figure it out just by looking at it. "Oh hey, this one is hunter2reddit.com, I wonder if..."

Now, using a password manager isn't foolproof. The password manager itself can be a weakness, as LastPass has demonstrated. But that is one point of potential weakness, as opposed a potential weakness in literally every website you have ever created an account on.

Storing your passwords in the cloud for ease of use creates a second point of weakness - the cloud provider. However, the only thing that happens if the "cloud" gets popped (no matter if it's a cloud password manager like LastPass or if you store your KeePass data on Dropbox), is that the attackers now have tons of encrypted binary blobs that they have to decode, which takes time.

Password Managers are the best choice of a bunch of imperfect options.
>>
>>59666019
>Keepass passed an audit by the European union
wow a bunch of kikes and other fat fucks in suits spending your money rubber stamped a seal of approval, thank god we have the EU pls fuck my wife mohammed
>>
>storing passwords anywhere other than in your head
it's like you're asking to be compromised
>>
>Using botnet pass
>Not using comfy KeePassX stored in your OpenBSD desktop.
>>
>>59665869
Get raped and kill yourself, you retarded kike loving fucking faggot sack of ugly nigger shit with down syndrome.
>>
>>59666991
Your head can be compromised with a pipe wrench, some pliers, and a car battey
>>
I'm going to delete this anyway because it keeps undeleting logins I deleted for sites like twitter where I lick to troll, so I have lots of them
>>
>>59666563
The only websites that matter have 2-tier mobile authorization (FB, VK, GitHub, Gmail, Skype, anything money related etc.) and I use 20 character pass there. All the other sites are worthless, I use same 6 character password there, because I don't care for them.
>>
>>59665959
>Shill spreads FUD about well known FOSS password manager
>Proceeds to recommend close source password manager that no one has hear about

I hope you are getting paid.
>>
>Not remembering your password in anno domini 2017

Cucked
>>
>>59664122
>Using password managers at all
I though /g/ was smarter than this
>>
>>59664122

LOLL

KeePass master race reporting in.

LastPass sucks dick
>>
File: 1489484337903.gif (992KB, 240x135px) Image search: [Google]
1489484337903.gif
992KB, 240x135px
>using a password manager instead of storing your passwords in a txt file
>>
>>59667511
Use same password just add selfmade word to each website, cucks think they can brute wordlist madeup words anytime in the next million years
>>
>>59664122
Sigh....why did I even....
>>
if i were to use keepass on mac, which version variation should i use? i doubt more than one has been audited.
>>
>>59664122
>people actually use lastbotnet
HAHAHAHAHAHAHAHAHAHAHAHAHA
>>
File: wZjWF0l.jpg (71KB, 550x448px) Image search: [Google]
wZjWF0l.jpg
71KB, 550x448px
>storing all your passwords on someone else's computer
>>
That's why you don't fucking use cloud pw managers. KeePass FTW
>>
>>59667329
so you memories at least 6 20 character long random passwords?
>>
>>59664209
Keepass.
>>
>>59668664
It's /g/, what did you expect?
>>
>not using pass
>>
>another one
kek
>>
I need someone to explain to me why all password managers aren't fucking trash and way less secure than just not using them at all. They're there for convenience but just make you way more vulnerable.

Tell me, how is it more secure to have all my passwords hidden behind the wall of 1 password, if someone somehow gets into my password manager they have EVERYTHING.
>>
>>59669846
Because your one master password can be much more secure than any other password.
That and you have the added convenience of having a different, secure password for every web application that requires one.
One exception though; don't store your main email address passwords in there.
>>
>>59669846
It is easier to keep something on your own system protected than it is to remember multiple secure passwords to every service you use.

That's why local password managers are the best. If you fail at securing your own system then you are fucked either way because you'll probably get a keylogger anyway.
>>
>>59666454
1.x is still maintained and does it's job just fine
>>
I don't get why we have passwords in 2017 when we have asymmetric encryption.

wtf is the point of some shitty plaintext + salt -> hash bullshit when you could generate some 4096B RSA key and send the server your pubkey blob to identify.

if you lose your key, just use the same email password recovery bullshit to set a new privkey.

hell you could even have device specific privkeys too so you could even have finer grained access control.
>>
>>59666960
gb2r/the_donald
>>
>>59669838
How many have they been? I swear they're finding major CVE's every two days for the last month
>>
>>59664122

>Travis "KeePass Marketing Manager" Ormany

Of course.
>>
>>59669668

Now which 35 plugins do I use to not have to manually upload it to have it everywhere I go, to autofill from within webpages and to 2step the master password login?

KeePass does nothing for convenience at all, it's a digital equivalent of a notebook full of passwords in your drawer.
>>
>using a network enabled password manager
>>
>>59664122

>Over the weekend, Google security researcher Tavis Ormandy reported a new client-side vulnerability in the LastPass browser extension.
>client-side vulnerability

So it's a problem for people whos laptop gets stolen or have a RAT.

Cool
>>
>>59669846
>how is it more secure to have all my passwords hidden behind the wall of 1 password

Because that wall can also be 2step authenticated, good luck to anyone trying to man in the middle your lastpass login
>>
>>59669959
KeePass 2 offers a RPC interface so plugins can get passwords from it, there's one for a Firefox that does autofill and all that crap
>>59669978
Client side doesn't mean local access
>>
3-factor authentication is the only way to go.
>Random Token Ring
>Phone authentication
>Secure Password

The only way someone is going to get access is if they literally beat you up, but knowing you guys that's probably likely ;)
>>
File: security.png (26KB, 448x274px) Image search: [Google]
security.png
26KB, 448x274px
>>59670090
>>
>>59664905
Lastpass
>>
>>59664167
KeePassX you mean, KeePass is junk.

LastPass is junk too. The only decent password managers on a design level is 1Password but it costs money so stuck with KeePassX.

There is of course that command line tree of gpg encrypted passwords but gpg is shit for password security since it doesn't slow down attacks. The whole point is a slow cipher designed for password mgt that can't be attacked by some cloud cracking service running dozens of GPUs w/Hashcat (these cost like $15).
>>
>>59670090
More usually they will just impersonate you contacting support and guess the 'security questions' or get access to some old email account and use that to reset/disable the 2FA. Seen it happen numerous times security ques are the root of all evil
>>
Just write down your password on a piece of paper dumb losers if you're paranoid write it on edible paper so you can swallow it if needed to
>>
>>59664845
>darkcomet on linux
ok anon
>>
File: rms.jpg (93KB, 640x426px) Image search: [Google]
rms.jpg
93KB, 640x426px
>>59671951
I'd just like to interject for a moment. What you're referring to as Linux, is in fact, GNU/Linux, or as I've recently taken to calling it, GNU plus Linux. Linux is not an operating system unto itself, but rather another free component of a fully functioning GNU system made useful by the GNU corelibs, shell utilities and vital system components comprising a full OS as defined by POSIX.

Many computer users run a modified version of the GNU system every day, without realizing it. Through a peculiar turn of events, the version of GNU which is widely used today is often called "Linux", and many of its users are not aware that it is basically the GNU system, developed by the GNU Project.

There really is a Linux, and these people are using it, but it is just a part of the system they use. Linux is the kernel: the program in the system that allocates the machine's resources to the other programs that you run. The kernel is an essential part of an operating system, but useless by itself; it can only function in the context of a complete operating system. Linux is normally used in combination with the GNU operating system: the whole system is basically GNU with Linux added, or GNU/Linux. All the so-called "Linux" distributions are really distributions of GNU/Linux.
>>
>>59671950
All paper is edible, fucktard.
>>
>>59671972
>implying I'm not just using the kernel
>>
>>59671993
>implying Linux works without GNU
>>
>>59672007
>implying I said it works
>>
>>59671991
Are you really this dense you fucking loser? I'm talking about paper meant for eating regular paper takes a long ass time to chew you are using a password manager after all so I should assume you're a little slow
>>
>>59667210
too late fuckhead. your accounts are permanently stored on their servers
>>
>>59672338
Source ?i
Master Pass and Keepass sucks, no sync between devuces, autofill whatsoever. 1password looks appealing so. How does the 2way authentification works?
>>
>>59672478
>no sync between devuces, autofill whatsoever
hm
>>
Why don't you guys keep your passwords on a piece of paper?
It's that fucking simple.
>>
>>59672641
it's more annoying. and also very susceptible to losing everything.
>>
>>59672641
because someone can just pick it up and read it and it doesnt provide protection from keylogs and phishing like a password manager does
>>
>>59672478
>>59672864
Please be joking
>>
>>59672885
Please be joking
>>
>>59664122
>lets put all passwords on the fucking internet, what could go wrong?
>>
About 1password, does the one time payment include mac and android version ?
>>
>>59672918
you mean where they are already?
>>
>>59672918
Really, don't be retarded.

The biggest security issue with passwords is that a lot of people use weak passwords and re-use the same password for everything. Because that is the most convenient. So Accounts are easy to hack. Or when a service got compromised and the passwords were leaked all other accounts are compromised, too.

The best way to combat this is by offering a convenient, easy to use service, that makes it easy to use strong and unique passwords for each service.
>>
>>59664122
>people actually paid to use this
>>
>>59672030
>calls others retarded
>is literally too retarded to know that all paper is edible

kek
>>
>>59673027
>Still being retarded enough to not know the difference in nuance between words.

Off yourself
>>
>storing passowrd in other people's computer.
>>
>>59671908
What's an example of a GPU resistant asymmetric cipher?
>>
>>59672833
>>59672864
Not really. You can also keep them on an encrypted flash drive.
You can hide them in a notebook full with writing or whatever info.
>>
Or just remember a unique password for every site you go on. It's really not that hard.
>>
>>59673520
unless you only go on a few sites if you remember them and they are all unique it means they are weak
>>
File: 1489567943400.gif (458KB, 256x256px) Image search: [Google]
1489567943400.gif
458KB, 256x256px
>>59672007
>what is newlib + busybox
>>
>>59669192
You can create for yourself 6-letter (or less) building blocks and make combinations of them.
i.e.
P8xSK2 YeUD7Q 6C8gth
P8xSK2 6C8gth YeUD7Q
6C8gth P8xSK2 YeUD7Q
6C8gth YeUD7Q P8xSK2
YeUD7Q 6C8gth P8xSK2
YeUD7Q P8xSK2 6C8gth
>>
>>59674751
>spending this much effort when you can just use a computer to do it for you.
>>
>>59674751
>Need to remember each building block
>Need to remember which combination for which site
>If you make more than 6 accounts this won't work anymore and you have to think of a new building block (and again remember where the new one is used and where it isn't)
> --> high risk of re-using an already used password or using a weak one
> --> high risk of eventually forgetting or remembering one block wrong and locking yourself out of all accounts
Yeah, no, thanks.
>>
>>59674905
You can encode the combinations with something, it's not hard. Then you can write them somewhere.
>If you make more than 6 accounts this won't work anymore and you have to think of a new building block
6 letters or less. You can avoid this in advance, obviously.
>>59674855
>memorizing 20 letters is hard
>>
>>59675183
>>memorizing 20 letters is hard
It's not easy. Takes time and commitment to get them in your head at first and then constant training to not forget it again.
>>
>>59674751
If one of your passwords get leaked then the rest of your passwords are at risk.

And this wont work if you have more accounts.
>>
just don't use passwords lmao
>>
File: teh edge.jpg (18KB, 240x210px) Image search: [Google]
teh edge.jpg
18KB, 240x210px
>>59666960
>>59667136
>>
How the fuck am I supposed to memorize unique passwords for 300+ websites?
>>
>>59677999
fucking brainlet.
OUT OF MY BOARD
>>
>>59674751
Speaking as someone who did something like this in the past, you'll eventually run into trouble with this. You'll forget what your password is because you've got the muscle memory down, but then you mess up the muscle memory... "Wait, is that supposed to be a capital letter? Did I get the right order?" etc.

Also, good luck typing that on a phone.
>>
>>59664122
everytime

only millenials use these kind of shitty """apps"""
>>
>>59678087
this. people of generation x like us we just use the same password for everything.
>being afraid of nsa hacking your account
i have nothing to hide lol
>>
>>59678104
I don't care about the NSA, they wouldn't have trouble.

Just keeping myself safe from basement dweller leak of the month.
If I'm informed of one of my accounts being compromised it will have no bearing on any other.
>>
>>59678087
It's not the """"app"""", it's the extension/plugin. I guarantee you're using some right now you fucking sperg so you have no reason to feel superior to others.
>>
File: 1489670008462.jpg (46KB, 540x508px) Image search: [Google]
1489670008462.jpg
46KB, 540x508px
>>59665379
>I do this
>it's my e-hentai/sadpanda password
>>
>>59665766
Having sEARus mental problMes so ALl your ppasswords are unique end exclusIVe to yoruself
>>
omg who cares nobody wants the passwords of a pathetic loser virgin who spends all his time on 4chan anyways
>>
File: enpass.png (33KB, 300x300px) Image search: [Google]
enpass.png
33KB, 300x300px
>>59664122
>aes-256
>no cloud bullshit (unless if you want to, its your responsibility)
>no internet or account required
>convenient apps and plugins for all major systems (including loonix)
>Data is only stored on your system
>if you loose your main password ur fucked

why aren't you using enpass /g/?
>>
>>59678761
>proprietary
I'll pass.
>>
https://lastpass.com/support.php?cmd=showfaq&id=163
>>
>>59678761
Because Keepass is all of that and FOSS
>>
>>59664552
this.

If I were to ever do something remotely like this it would be like amazon backups where you encrypt with something stupid like 4096 and ONLY THEN transfer and even then for nothing > medium security

>>59666396
my security is worth more than this convenience

>>59666453
Agreed but alternatives include trusting an IDP (SAML /oAuth / Azure ACS) or certs which even half of IT seems to fail at.

>>59666960
this response is devoid of substance and understanding

>>59677999
you''re right >>59678057 is stupid, even systems like adding variations on the site visited etc are being adapted to. Also different sites have such varied password policies that MAX 16 chars w/o specials vs MIN 16 chars w/certain specials is common on different parts of the same site.

In addition to all this shit, no government will allow a single secure commercial 2-3 factor IDP to exist unless they have access. I'm still on keepass + yubikey where possible but I'm always looking for better because it's the best of a lot of bad solutions.

>t. IT w/500+ passwords between work and home
>>
>>59675692
How would that work I wonder?
>>
>>59671972
normally he looks pretty happy in photographs. That shirt looks familiar anyone know what lecture thats from?
>>
>tfw fell for LastPass once
>tfw deleted my account when they had security issues the first time
>>
>>59681511
>but not your passwords
>>
Holestly who is dumb enough to believe any password manager isn't a botnet?

Even if it's not expressly a botnet, the CIA will get a developer in there, or fuck with the code, or use the Intel Management Engine on the server or something.

Don't be fucking retarded, all password managers are botnet.
>>
>>59682791
keepass is open source idiot
>>
>>59682882
Who cares moron, it's still not secure.
>>
>>59671908
>KeePassX you mean, KeePass is junk.
no damn it, I just staring learning to use keypass and you're faggot ass tells me about something else
>>
>>59674751
congratulation, you successfully reduced the entropy of your passwords
>>
>>59682791
That's not the main point for using password managers though. You use them to have strong and unique passwords for each account. The average user isn't in danger of getting his accounts hacked by the CIA. No, the danger is using the same password over and over again. So that if one service is compromised, all of your accounts are.
>>
>>59671908
You can use add-ons for encrypting your key file with all kinds of different encryptions in KeePass.
>>
File: 1474351885982.gif (131KB, 382x310px) Image search: [Google]
1474351885982.gif
131KB, 382x310px
>>59679120
check out my blogpost
>>59686225
>>
File: 400.jpg (77KB, 300x250px) Image search: [Google]
400.jpg
77KB, 300x250px
why PaleMoon extension is still not updated?
>>
>Not using an IRL piece of paper for passwords
>not using on-screen keyboards to get passed keyloggers/RATs
>>
LastPass and everything from LogMeIn is garbage tier. I had to buy millions worth of software licenses from them for a company and they don't even bother to process the order. In the end we chose to implement KeePass and use the money to train employees.
Thread posts: 197
Thread images: 19


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.