Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



there are those very thin lines, where a joke goes on too long, then for a second it gets funny again, then it goes on for way way too long, and youre not coming back to make it funny again anytime soon. forget it.

unless you bring it up at like a dinner in 3 years. thats funny as gently caress.

Adbot
ADBOT LOVES YOU

akadajet
Sep 14, 2003

spankmeister posted:

So, is the Safari plugin fixed?

nobody uses safari, so no need to wait on apple

flakeloaf
Feb 26, 2003

Still better than android clock

Powaqoatse posted:

there are those very thin lines, where a joke goes on too long, then for a second it gets funny again, then it goes on for way way too long, and youre not coming back to make it funny again anytime soon. forget it.

the lorne michaels quotient

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



flakeloaf posted:

the lorne michaels quotient

thats accurate as gently caress

EndlessRagdoll
May 20, 2016

Carbon dioxide posted:

It's the most wonderful time of the year again, folks.

https://www.youtube.com/watch?v=VgC4b9K-gYU

gently caress this.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



It’s Your Man Jeff, 9 Times

this is how you carry a joke over the edge and back and forth again

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Powaqoatse posted:

It’s Your Man Jeff, 9 Times

this is how you carry a joke over the edge and back and forth again

Not James don't care

WrenP-Complete
Jul 27, 2012

Hi James, I'm James.

Progressive JPEG
Feb 19, 2003

OSI bean dip posted:

so how many lastpass apologists do we have left?

Tried 1password. Apparently theres no support whatsoever on linux. The browser extensions require that the desktop app also be installed.

So lastpass it is then

minivanmegafun
Jul 27, 2004

is keepass so bad that you'd use last pass over it? i find lastpass's garbage user interface more offensive than their terrible security, keepass can't be worse, can it?

EndlessRagdoll
May 20, 2016

minivanmegafun posted:

is keepass so bad that you'd use last pass over it? i find lastpass's garbage user interface more offensive than their terrible security, keepass can't be worse, can it?

keepass x is great. also easier to run on Linux in my experience.

surebet
Jan 10, 2013

avatar
specialist


https://www.youtube.com/watch?v=97biyPDXnto

Wiggly Wayne DDS
Sep 11, 2010



the krypto key

Storysmith
Dec 31, 2006

lol Cisco how do you use 32 bit signed timestamps ityool 2017 http://www.cisco.com/c/en/us/support/docs/field-notices/642/fn64291.html

Cybernetic Vermin
Apr 18, 2005

OSI bean dip posted:

so how many lastpass apologists do we have left?

if you haven't managed to generalize the way tavis devastates most things he looks at into a far more dire view than "lol, lastpass seems like a pos" you may not be paying enough attention

what i mean to say is, you are likely just as hosed as any lastpass user

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Progressive JPEG posted:

Tried 1password. Apparently theres no support whatsoever on linux. The browser extensions require that the desktop app also be installed.

So lastpass it is then

it works fine under wine (ive been doing this for years)

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

Cybernetic Vermin posted:

if you haven't managed to generalize the way tavis devastates most things he looks at into a far more dire view than "lol, lastpass seems like a pos" you may not be paying enough attention

what i mean to say is, you are likely just as hosed as any lastpass user

generalizing anything to literally all software is kind of a ridiculous mindset

Cybernetic Vermin
Apr 18, 2005

you are just resisting the obvious here, all software is hosed, the idea of achieving security through education, individual hard work and expertise is doomed in a future where the average programmer is some shithead hired off the street, we need to burn everything to the ground and start again

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Cybernetic Vermin posted:

you are just resisting the obvious here, all software is hosed, the idea of achieving security through education, individual hard work and expertise is doomed in a future where the average programmer is some shithead hired off the street, we need to burn everything to the ground and start again

Ok well you can start by getting off the internet forever

Loving Africa Chaps
Dec 3, 2007


We had not left it yet, but when I would wake in the night, I would lie, listening, homesick for it already.

Shia le beouf is finding it pretty hard to hide his latest performance art project from 4chan

http://www.newyorker.com/magazine/2017/04/03/trolls-protest-shia-labeoufs-anti-trump-protest-art?mbid=social_twitter

quote:

"We might be able to do trigonometry with shadows on the flag,” another person wrote. One of the trolls quickly found a clue: a photo of LaBeouf, taken days earlier, at a diner in Greeneville, Tennessee.

More opsec then infosec but still pretty impressive

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

so how many lastpass apologists do we have left?

Progressive JPEG posted:

Tried 1password. Apparently theres no support whatsoever on linux. The browser extensions require that the desktop app also be installed.

So lastpass it is then

Cybernetic Vermin
Apr 18, 2005

Captain Foo posted:

Ok well you can start by getting off the internet forever

snark aside i do literally believe that the next decade will have to bring a more constrained programming model for public-facing software, and it will have to be actual constraints, as we are not about to overcome human weaknesses in these areas as the number of people employed doing the work keeps skyrocketing

hackers are winning wars and elections at this point

it is misunderstanding the situation to laugh about the other guys software of choice turning out to not be entirely secure

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


am i insane for just using keepass and then saving the passwords in the browser store? i mean, I've never thought 'god this copy and paste is so hard when i have to do it literally once per devicei have, if only someone could automate it for me!", do i just not have enough passwords or devices or something?

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Cybernetic Vermin posted:

snark aside i do literally believe that the next decade will have to bring a more constrained programming model for public-facing software, and it will have to be actual constraints, as we are not about to overcome human weaknesses in these areas as the number of people employed doing the work keeps skyrocketing

hackers are winning wars and elections at this point

it is misunderstanding the situation to laugh about the other guys software of choice turning out to not be entirely secure

Your operating system is a piece of poo poo.

CrazyLittle
Sep 11, 2001





Clapping Larry

Powerful Two-Hander posted:

am i insane for just using keepass and then saving the passwords in the browser store? i mean, I've never thought 'god this copy and paste is so hard when i have to do it literally once per devicei have, if only someone could automate it for me!", do i just not have enough passwords or devices or something?

yes because browser stores are notoriously insecure. Firefox used to store in clear text

vOv
Feb 8, 2014

CrazyLittle posted:

yes because browser stores are notoriously insecure. Firefox used to store in clear text

how else would you store it without requiring a master password

pseudorandom name
May 6, 2007

use your operating system's secure keychain or equivalent

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

CrazyLittle posted:

yes because browser stores are notoriously insecure. Firefox used to store in clear text

Firefox used to store it with strong encryption but had to change cause they got too many complaints from people losing their passwords cause users are idiots. Now they use easily reversible encryption unless you set a master password. They've never stored in plaintext afaik

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

At least they're ramming sync down everyones throat so a copy of the keystore is backed up in the butt

pseudorandom name
May 6, 2007

pr0zac posted:

Firefox used to store it with strong encryption but had to change cause they got too many complaints from people losing their passwords cause users are idiots. Now they use easily reversible encryption unless you set a master password. They've never stored in plaintext afaik

I think you're confusing Firefox Sync with local password storage. afaik, the local password storage has always been unencrypted unless you set a master password.

Chalks
Sep 30, 2009

pseudorandom name posted:

I think you're confusing Firefox Sync with local password storage. afaik, the local password storage has always been unencrypted unless you set a master password.

If you're not using a master password then I doubt you expect your passwords to be all that secure considering you can just press two buttons to display them all in plaintext on screen.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
don't forget that those passwords are almost always transmitted to a remote server anyways

even warning you that it's a non-https connection to that server is a very recent thing

Theris
Oct 9, 2007

vOv posted:

how else would you store it without requiring a master password

Chrome uses Windows CryptoAPI to encrypt the password store and ties it to your windows user account even if you don't have a sync passphrase set. I think this means any other app run under that account can also access it but it's better than nothing I guess.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


pr0zac posted:

Firefox used to store it with strong encryption but had to change cause they got too many complaints from people losing their passwords cause users are idiots. Now they use easily reversible encryption unless you set a master password. They've never stored in plaintext afaik

Cocoa Crispies posted:

don't forget that those passwords are almost always transmitted to a remote server anyways

even warning you that it's a non-https connection to that server is a very recent thing


i dont use Firefox sync for passwords, that was an obviously bad idea but i assumed the locally saved ones were tied to the windows account ir something...though yeah that text has gotta get decrypted at some point.

time to dehumanize i guess \/:v:\/

Truga
May 4, 2014
Lipstick Apathy
i use keefox, it works. have autofill disabled tho

wolrah
May 8, 2006
what?

Cybernetic Vermin posted:

if you haven't managed to generalize the way tavis devastates most things he looks at into a far more dire view than "lol, lastpass seems like a pos" you may not be paying enough attention

what i mean to say is, you are likely just as hosed as any lastpass user

Though it's a bit quirky from a UI standpoint, this is something I like about using KeePass and the way it supports browser extensions. The vault has its own HTTP API (optional plugin for the official client, built in to KeePassXC) that listens only on localhost and is connected to by the browser extension with AES encryption. The extension has to ask for access in general, then also for access to each individual password and I can either approve or deny once or always.

The quirky part is that the popup when it's looking for a password tends to show up underneath all other windows and doesn't even bother to flash the taskbar icon, so I still find myself getting frustrated at it not auto-filling a password until I realize why.

Even if the extension developer went full rogue there is no ability for them to list the contents of the database, nor would they be able to access the passwords I consider truly important unless I had inadvertently selected "always allow" on them. The attack surface is as limited as it can be while still being useful.

pseudorandom name
May 6, 2007

Powerful Two-Hander posted:

i dont use Firefox sync for passwords, that was an obviously bad idea

Firefox Sync used to use strong crypto which required you to pair new devices with an existing client to do the key exchange, but users were too stupid to understand the concept and thought Sync was a backup mechanism and got mad when they lost everything when they deleted all their Firefox installs

so Mozilla changed it to just derive the key from your Sync password because we can't have nice things

akadajet
Sep 14, 2003

Truga posted:

i use keefox, it works. have autofill disabled tho

aren't these things going to be susceptible to the same kind of browser plugin bugs?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

pseudorandom name posted:

I think you're confusing Firefox Sync with local password storage. afaik, the local password storage has always been unencrypted unless you set a master password.

it was encrypted but with a fixed key if there was no master password to use instead, going back to 1998

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Theris posted:

Chrome uses Windows CryptoAPI to encrypt the password store and ties it to your windows user account even if you don't have a sync passphrase set. I think this means any other app run under that account can also access it but it's better than nothing I guess.
if you password-protected your chrome password store long ago, that password is used instead of the windows account

  • Locked thread