• 6 Posts
  • 183 Comments
Joined 1 year ago
cake
Cake day: June 22nd, 2023

help-circle




  • 2FA should always be enabled. Doesn’t mean you always have to log out of a website. It’s a massive important security feature: it saves your ass if your passwords are leaked/cracked/bypassed and it warns you that someone is trying to access your account. Apps like ProtonPass literally make it extremely trivial to fill it in, just push the button that pops up and it will autofill the 6 digit code (or copy it to your clipboard in the worst case), it’s not SMS 2FA, so you’re frankly stupid for not using it if you have that option.

    You didn’t address shit, strong passwords will still be vulnerable to certain attacks even if everyone used them. This isn’t a privacy matter either it’s a security one and regardless of what your threat model is 2FA should always be part of your security, there’s a reason more and more websites and apps are pushing it, cause if you don’t force idiots to adopt it they won’t even if it’s extremely important, same reason as why we need rules to make passwords more complicated. It may be an inconvenience (very tragic for the user I know, how dare they make something that autofills and takes a few seconds of my day away from watching useful shit like brainrot and some dumb comments on my favorite social media platform) but it’s an extremely important and necessary measure.


  • It’s still nowhere near as secure and convenient as using an appropriate tool. You will either have one that is easy to decipher and remember or one that is hard to decipher and remember. And you have to do it every time but at that point you might aswell just remember one password/passphrase and use it for your password manager, defeating the whole point.

    Also bare in mind convenience is important in security, if a measure is very inconvenient you will eventually just bypass it on your own cause you can’t be arsed.




  • I disagree. Password managers are still target of threat actors, a juicy one at that, but it’s not too often you hear of breaches of good password managers. Chances are the people behind the good password managers are better at security than 99% of users (including more technical ones). Even after a breach exporting all the passwords and moving them to another service, and changing all your passwords again with more secure ones is trivially easy.

    If everyone used them sure there’d be more pressure on said password managers but hackers will find it a lot more difficult to hack anything in general and it will still not be worthwhile to hack average users who use a password manager.


  • Unless the website is handled by complete morons it stores credentials in an hashed format. Usually to crack this we’d use rainbow tables or wordlists of known passwords, and essentially we use every word to generate the hash until it matches.

    If your password is strong and hasn’t been compromised (check regularly on haveibeenpwned) it will likely not be in any wordlists and it also won’t be easy to crack. Now, password managers can generate the best passwords because they’re completely random and very long by default so to crack them you’d have to try every possible character combination, this takes time, and specifically a time so long that statistically the andromeda galaxy and milky way will merge into one before the password is cracked (at least until quantum computers become a thing, then it’s mere minutes).

    2FA helps because even if they crack the password they then need the 2FA code, which you can’t really guess or brute force and is seen on a third party app you don’t control (unless you use sms, they can spoof SIMs ro view the sms you receive and therefore degeat 2FA). It also doubles as something that alerts you that someone is trying to access your account.



  • EuroNutellaMan@lemmy.worldtoPrivacy@lemmy.mlUse a password manager
    link
    fedilink
    arrow-up
    2
    arrow-down
    5
    ·
    edit-2
    5 days ago

    No. Anyone near you or with access to your place can see it. And most people know of the tricks.

    Also you can’t encrypt it and most of all you can’t really generate as strong passwords as those generated by password managers, meaning I don’t even need the paper to try and crack your password









  • the only objective problem mint has is that it’s so good I struggle to get people I convinced to install it to be interested in other distros and stuff. And that’s fine.

    Mint is a solid choice and the one I recommend to anyone who just wants something that works or doesn’t care about having several choices, and even when someone wants to explore more options I always include Mint. It just works, it’s easy to install that even my non-tech savvy mother on a phone call with me managed to install it and Cinnamon has just enough customization options ootb to make it yours without being overwhelming to a noob like KDE.

    I personally don’t use it cause I am not the biggest fan of using GUIs, debian derivatives and I prefer KDE plasma so I just go with other options (currently Fedora 40, been using Arch and NixOS a lot before this), however even in my case I could most likely turn LM into what I want with some effort (I just don’t see the point in doing that), and my father who has been using Linux since Kernel 1.0 and is definitely a power user swears by it.