Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

duTrieux. posted:

the solution is to educate people on basic digital security, not to dumb everything down so as to be worse than nothing

How's that one working out?

Adbot
ADBOT LOVES YOU

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


anthonypants posted:

when i paid for lastpass, keep rear end was still an open sores nightmare where you needed third-party plugins for anything you actually wanted to use it for, and a lot of plugins weren't compatible between keep rear end v1 and keep rear end v2. i've since switched to 1password but i don't believe keep rear end has gotten any better. like, if i wanted to get chrome integration with keep rear end, i'd go to their plugins page, ctrl+f chrome, the first result is a plugin called KeeForm, here is their website, whoops it doesn't actually work with chrome

I'm not sure why you need a plugin for this, when the builtin keyboard shortcut autotype functionality works perfectly well. That webpage describes opening keepass, selecting it and using autotype from there, but that is not the best way to do it.

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

Volmarias posted:

How's that one working out?

Pretty well actually. My users are technological idiots for a large part, but when I explain things like "don't share accounts" and "don't email passwords that belong to other people", they understand and learn. Sure, they forget their passwords after a long weekend, but they know the complexity requirements and why, and not to store PII on Dropbox.

surebet
Jan 10, 2013

avatar
specialist


what worked well for my family (notorious non computer touchers) was to move them to laptops with biometrics & dell ddpe

some of them are using pure ddpe with the ie plugin, others (myself included) are using keep rear end with ddpe's sign-in:


biometrics have their own issues, but it removes a lot of friction in user adoption

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

https://twitter.com/wendynather/status/870094831082651648

flakeloaf
Feb 26, 2003

Still better than android clock

duTrieux. posted:

the solution is to educate people on basic digital security, not to dumb everything down so as to be worse than nothing

the path to paradise goes straight up mount giveafuck and edgar from personnel showed up in flipflops today

Shame Boy
Mar 2, 2010

Volmarias posted:

So it was a rhetorical question but also a real question?

it was a rhetorical question that was treated like a real question, yeah

Volmarias posted:

Sure, but don't cluck at non-technical end users for picking the thing that appears to be good enough when there's no reasonable alternative for them.

ah ok i think i see the disconnect, i didn't interpret it as clucking at general end users but as clucking at thread posters, i guess i can see how it could be either :shobon:

duTrieux.
Oct 9, 2003

Volmarias posted:

How's that one working out?

i actually work in field of training/instructional design/screaming into the void

so in short, it's not working very well at all!

duTrieux.
Oct 9, 2003

all of human history is a struggle against the fact that we're all goddamn animals

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
our sophos license renewal is coming up, the sales rep has this in his email signature

Only registered members can see post attachments!

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer
lastpass and other browser plugin password managers are bad because they are constantly revealed to be vulnerable to a litany of attacks that give away all the users' credentials, making it worse than just writing things down because it gives the user a false sense that they are being safe when they are not.

Zil
Jun 4, 2011

Satanically Summoned Citrus


anthonypants posted:

our sophos license renewal is coming up, the sales rep has this in his email signature



you know there were like 10 meetings about that image. makes me want to see the mockups that were rejected.

flakeloaf
Feb 26, 2003

Still better than android clock

anthonypants posted:

our sophos license renewal is coming up, the sales rep has this in his email signature



river city ransomware

cinci zoo sniper
Mar 15, 2013




anthonypants posted:

our sophos license renewal is coming up, the sales rep has this in his email signature



thE EnD oF rAnSOmWarE

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

flakeloaf posted:

river city ransomware

are you a bad enough dude to demand 2 btc from a slovenian grandma

Midjack
Dec 24, 2007



flakeloaf posted:

river city ransomware



cis autodrag posted:

are you a bad enough dude to demand 2 btc from a slovenian grandma

haveblue
Aug 15, 2005



Toilet Rascal

cis autodrag posted:

are you a bad enough dude to demand 2 btc from the NHS

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe
wannabarf

flakeloaf
Feb 26, 2003

Still better than android clock

to unlock your account send 3 bitcoins to

qBh3Dds9'3aZ
hfHb8f7pbf7
7'Hi9k3xsXn

Truga
May 4, 2014
Lipstick Apathy

cis autodrag posted:

are you a bad enough dude to demand 2 btc from a slovenian grandma

please don't doxx my grandma

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

You should put this as your signature when you reply:

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

Optimus_Rhyme posted:

You should put this as your signature when you reply:



holy poo poo yes please do this

maybe you'll be able to negotiate a discount and embezzle the money

AARP LARPer
Feb 19, 2005

THE DARK SIDE OF SCIENCE BREEDS A WEAPON OF WAR

Buglord
isn't 1password good? though the sync via dropbox seems like a weak link

flakeloaf
Feb 26, 2003

Still better than android clock

WAR DOGS OF SOCHI posted:

isn't 1password good? though the sync via dropbox seems like a weak link

the browser plugin gives some people uncomfortable feelings

i think sync via dropbox is gone and it's now 'sync via our server for as long as you subscribe' or something

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

WAR DOGS OF SOCHI posted:

isn't 1password good? though the sync via dropbox seems like a weak link
it's not a great experience if you're a windows user. and strictly speaking, if you're worried about security you shouldn't enable any sort of password autofill

El Mero Mero
Oct 13, 2001

I feel like the wheel has yet to stop on dashlane, but so long as it hasn't yet I'm going to feel like a superior decision maker wrt butt-managers

LET ME HAVE THIS OKAY

Zil
Jun 4, 2011

Satanically Summoned Citrus


El Mero Mero posted:

I feel like the wheel has yet to stop on dashlane, but so long as it hasn't yet I'm going to feel like a superior decision maker wrt butt-managers

LET ME HAVE THIS OKAY

nothing can escape the gaze of Tavis, he will come for your program soon.

Raere
Dec 13, 2007

El Mero Mero posted:

I feel like the wheel has yet to stop on dashlane, but so long as it hasn't yet I'm going to feel like a superior decision maker wrt butt-managers

LET ME HAVE THIS OKAY


Dashlane got popped by tavis last year
https://twitter.com/taviso/status/773218040758448128?lang=en

quote:

This results in a universal XSS, allowing any site to XSS any other site - and therefore access cookies and user data, steal passwords and credentials for any website, etc, etc. Something like this should work:
...
I'm going to list this as critical severity even though it's not a remote code execution, because the sole intent of the product is to protect website passwords and this effectively allows you to steal all password.

Last Chance
Dec 31, 2004

Anyone ever hear of Dashlane?

El Mero Mero
Oct 13, 2001


god damnit :sigh:

endlessmonotony
Nov 4, 2009

by Fritz the Horse

I really started to wonder if this person was actually this stupid or just sarcastic.

I found no answer.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

endlessmonotony posted:

I really started to wonder if this person was actually this stupid or just sarcastic.

I found no answer.
:yossame:

Gul Banana
Nov 28, 2003

lastpass doesn't solve the problem of "my passwords aren't secure". it solves the problem "i have to keep entering all these passwords"

hifi
Jul 25, 2012

the keepass autotype thing scares me because so much poo poo can pop up on a computer in 1-5 seconds and steal focus

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Jewel posted:

keepass

why do people keep asking and not learning

especially since it has a funy name "keep rear end"

spankmeister
Jun 15, 2008






Keep rear end, the funy passowrd manager

N.Z.'s Champion
Jun 8, 2003

Yam Slacker
next.js is a really nice react.js framework with server side rendering integration but they didn't reliably filter paths that include ".." so...

https://github.com/zeit/next.js/releases/tag/2.4.1

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
like i said earlier, i was on vacation and got some email from kohl's thanking me for creating an account with them; obviously someone just using my email address.
so i got home today and did the old reset password to lock the idiot out. saw that i could edit the account info, and figured i'd just change the email to something else:



i'm dyin'

Shifty Pony
Dec 28, 2004

Up ta somethin'


Gul Banana posted:

lastpass doesn't solve the problem of "my passwords aren't secure". it solves the problem "i have to keep entering all these passwords"

and it keeps "if I use the same password everywhere I won't forget it" from being the easiest solution to dealing with all the passwords you need these days.

I've been using 1Password to keep track of my logins but I don't use autofill and generally pull up the password on my iphone while I type it in using my computer keyboard. it basically makes it a glorified password notebook with Dropbox backup in case my house burns down or something and I figure it is good enough.


is bitcoin drama considered too much of a low hanging fruit for the tread? I hope not because this guy losing $8k in 15 minutes is just stuffed full of fun fuckups.

first you have yet another example of how using SMS is no good because the attacker simply convinced Verizon to transfer the number to a new SIM, allowing them to reset his Gmail password.

Verizon did send him a text to let him know someone was on the phone with Verizon making changes to the account, but the "not you? call us immediately" number is only staffed weekdays 8am-11PM.

then you have Coinbase allowing a password reset, new device activation, and complete emptying out of all funds within four minutes.

this might be my favorite comment "solution":

quote:

consider switching to a non-traditional phone company like Google Project Fi.. can’t socially engineer them because you can’t even contact them

featurenotabug!

Adbot
ADBOT LOVES YOU

bobfather
Sep 20, 2001

I will analyze your nervous system for beer money
I can't wholeheartedly endorse 1Password anymore, because I don't agree with their recent decisions to remove external cloud sync and local vault capability and move to a subscription-only model, BUT they're basically the only password manager aside from Keepass that hasn't been sabered open by Tavis like a cheap bottle of Brut.

Edit: to express my displeasure with AgileBits, here's an effortpost to use 1Password for free with Windows with Dropbox sync intact:

1. Uninstall 1Password6 if you have any version installed past 6.4.377

2. Download version 6.3.359 directly from AgileBits and install it.

3. Set up sync with at least one vault via Dropbox, OneDrive, or whatever you want to use.

4. Download version 6.4.377 directly from AgileBits and upgrade your previous install.

5. Never upgrade past that, and you'll maintain DropBox sync. Automatic sync is non-existent or unreliable, so you have to manually trigger a sync through options. Also, you can't edit or add vault entries. But if you sync multiple vaults it's nicer than 1Password 4, and the interface is consistent with the rest of the 1Password ecosystem.

Also, AgileBits alleges that they dropped Dropbox support because DropBox will be changing APIs soon (or, they already have). Time will tell if this method continues to work, but I have a feeling they're full of poo poo and dropped external cloud support to pimp their own product. They're so evasive about it on their forums it must be true.

bobfather fucked around with this message at 15:14 on Jun 2, 2017

  • Locked thread