Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
CLAM DOWN
Feb 13, 2007




The Aphasian posted:

Sorry. I meant they will want something with the ability to follow different threads/posts/conversations in a format that allows a moderator to add and remove people as needed.

I honestly don't know how discord or slack compare because I'm ignorant. I am probably overthinking it. Ive been editing a podcast for an immigration lawyer, and the stories and cases they discuss probably just made me depressed and paranoid.

Hmmm. WhatsApp definitely fits that bill for those features but obviously that won't work for that level of paranoia. Maybe download and try Telegram, I haven't used it in ages but it's very possible they added that functionality.

Adbot
ADBOT LOVES YOU

susan b buffering
Nov 14, 2016

Telegram can definitely do group chats with mods, but I’m unsure about threading because I haven’t been on in a while.

SlowBloke
Aug 14, 2017
Telegram doesn’t do full encrypted moderated channels, just 1-to-1 chats. You get encrypted transport but not encrypted content like signal/WhatsApp/keybase

PBS
Sep 21, 2015
You could take a look at zulip chat.

Defenestrategy
Oct 24, 2010

Or you can get a set of one time pads, exchange them in person, and use what ever communication protocol you like. :smug:

Arsenic Lupin
Apr 12, 2012

This particularly rapid💨 unintelligible 😖patter💁 isn't generally heard🧏‍♂️, and if it is🤔, it doesn't matter💁.


CLAM DOWN posted:

What makes you think Discord or Slack are somehow anymore secure or safe than Facebook? Maybe use Telegram or something I dunno, not sure what you mean by "fb group setup" and this seems pretty paranoid.
Discord is IIRC especially bad because they never delete anything. (On the server side.) Also closely tied into the Chinese government.

The Fool
Oct 16, 2003


I'm going to suggest something that sounds like a joke, but if signal/telegram are non-starters, this is a real option.

Microsoft Teams

Only one person would need to have o365, everyone else can be added as guests.

Data is encrypted on the servers and in transit.

It has threaded conversations, owners have strong membership controls, and robust built-in file sharing and collaboration features.

SlowBloke
Aug 14, 2017

The Fool posted:

I'm going to suggest something that sounds like a joke, but if signal/telegram are non-starters, this is a real option.

Microsoft Teams

Only one person would need to have o365, everyone else can be added as guests.

Data is encrypted on the servers and in transit.

It has threaded conversations, owners have strong membership controls, and robust built-in file sharing and collaboration features.

If any of the team admins users is compromised and gets its mitts on the ediscovery roles all data is compromised tho, caveat emptor

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Arsenic Lupin posted:

Discord is IIRC especially bad because they never delete anything. (On the server side.) Also closely tied into the Chinese government.

They claim otherwise. Try reporting a message that is then deleted from the server and they'll claim they have no way to recover it and can't do anything.

Arsenic Lupin
Apr 12, 2012

This particularly rapid💨 unintelligible 😖patter💁 isn't generally heard🧏‍♂️, and if it is🤔, it doesn't matter💁.


Glad to be wrong!

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Cup Runneth Over posted:

They claim otherwise. Try reporting a message that is then deleted from the server and they'll claim they have no way to recover it and can't do anything.

What they say they can't do and what they can actually do are two very completely different things.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


EVIL Gibson posted:

What they say they can't do and what they can actually do are two very completely different things.

Hence why I said "they claim"

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Cup Runneth Over posted:

Hence why I said "they claim"

arsenic took it as fact which was could cause issues.

Impotence
Nov 8, 2010
Lipstick Apathy

Cup Runneth Over posted:

They claim otherwise. Try reporting a message that is then deleted from the server and they'll claim they have no way to recover it and can't do anything.

This seems hilariously counter to them suspending/terminating your server if you don't delete spam content and keep it moderated
Anecdotally, one of my friends requested their account be deleted with any contents associated with it, I still see a DM with them with everything including file uploads there, and the server they own still exists with no ownership changes.

I found this slightly strange. Like they just renamed their usertag to 'deleted' and nothing else

The Aphasian posted:

What's the best option for a group of u.s. immigration lawyers looking to move off of Facebook? I'm suggesting Signal, but I think they want something more like the fb group setup. Tech skills vary too much for anything extremely niche, and they are using phones, macs, and pcs.

I've lurked in the thread on and off for years, but am not skilled or qualified, just looking to give a group of good people doing good work good advice. I'm not sure what options exist that are secure against both bad actors and, potentially, state actors :tinfoil:. Is discord/slack probably fine? I don't want to be too paranoid, but, you know, America.

If you actually want something against major bad + state actors, you WILL have to give them very serious lessons and education on how to change and improve their skills.

Impotence fucked around with this message at 19:10 on Aug 11, 2019

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Biowarfare posted:

Anecdotally, one of my friends requested their account be deleted with any contents associated with it, I still see a DM with them with everything including file uploads there, and the server they own still exists with no ownership changes.

I found this slightly strange. Like they just renamed their usertag to 'deleted' and nothing else.

This is probably exactly what they do

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Cup Runneth Over posted:

This is probably exactly what they do

If you do a proxy examination of the traffic that comes over when listing the user, you could probably find that the UserID is still the original userid.

vanity slug
Jul 20, 2010

That's not very GDPR compliant.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Brian Krebs won't stop being Brian Krebs:

https://twitter.com/blackroomsec/status/1160945544115707904?s=20

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Unless you end up in the kind of niche weirdo social networking via Tor, it might be a bit of an tough one. You might want to drop in an EFF office in person and ask if they have any suggestions aside from Signal. Slack and Discord 100% won't protect you from state actors who can just NSL them.

Terrorforge
Dec 22, 2013

More of a furnace, really
This may be a bit babytown for this thread, but I'm sick to death of needing 40 passwords, using six and forgetting which one I used every time I get logged out of something. Any recommendations for good, cheap (free?) password managers that I can use on multiple devices?

Docjowles
Apr 9, 2009

Terrorforge posted:

This may be a bit babytown for this thread, but I'm sick to death of needing 40 passwords, using six and forgetting which one I used every time I get logged out of something. Any recommendations for good, cheap (free?) password managers that I can use on multiple devices?

If you scroll back through the thread this is a recurring topic like every 5 pages.

You're about to get blasted with takes though, so buckle up!

Docjowles fucked around with this message at 20:00 on Aug 12, 2019

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Terrorforge posted:

This may be a bit babytown for this thread, but I'm sick to death of needing 40 passwords, using six and forgetting which one I used every time I get logged out of something. Any recommendations for good, cheap (free?) password managers that I can use on multiple devices?

Keepass for local DB. I like Keepass.

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost



What?

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:

Terrorforge posted:

This may be a bit babytown for this thread, but I'm sick to death of needing 40 passwords, using six and forgetting which one I used every time I get logged out of something. Any recommendations for good, cheap (free?) password managers that I can use on multiple devices?

1password is inexpensive and easy to use and consistently gets high marks from everyone. I particularly like it's implementation of shared vaults, which lets me share stuff like an Amazon Prime login or NYT account with family. The browser extension makes it trivial to add logins and you can put your data in a local cake vault for privacy and security.

It also doesn't have the poor history of other password managers like LastPass. There are other free options folks can speak to, but it works great for me.

The Fool
Oct 16, 2003


Docjowles posted:

You're about to get blasted with takes though, so buckle up!

1pass or KeePass, depending on needs and cloud aversion level.

vanity slug
Jul 20, 2010

Terrorforge posted:

This may be a bit babytown for this thread, but I'm sick to death of needing 40 passwords, using six and forgetting which one I used every time I get logged out of something. Any recommendations for good, cheap (free?) password managers that I can use on multiple devices?

1Password is pretty good. LastPass is really bad.

tango alpha delta
Sep 9, 2011

Ask me about my wealthy lifestyle and passive income! I love bragging about my wealth to my lessers! My opinions are more valid because I have more money than you! Stealing the fruits of the labor of the working class is okay, so long as you don't do it using crypto. More money = better than!

The Fool posted:

1pass or KeePass, depending on needs and cloud aversion level.

And Operating System. If you want to use Keepass with IOS devices, good luck with that.

Keepass does work beautifully in the cloud with Windows and Android, though.

If you are going to go cloud, always use two factor authentication.

If you want to spend a cubic rear end load of money, there's always CyberArk. It's a little overkill though, lol.

tango alpha delta fucked around with this message at 21:03 on Aug 12, 2019

The Fool
Oct 16, 2003


I just assume that anyone with apple stuff is using the keychain and they are fine.

Kassad
Nov 12, 2005

It's about time.
How does Bitwarden compare to 1password (I'm already using Keepass)?

Terrorforge
Dec 22, 2013

More of a furnace, really
I should have specified that when I said "use on multiple devices" I meant "I want to access it on my Android", so some form of cloud capability is mandatory

Docjowles posted:

If you scroll back through the thread this is a recurring topic like every 5 pages.

You're about to get blasted with takes though, so buckle up!

I straight up fuckin' forgot you can search threads.


The Iron Rose posted:

1password is inexpensive and easy to use and consistently gets high marks from everyone. I particularly like it's implementation of shared vaults, which lets me share stuff like an Amazon Prime login or NYT account with family. The browser extension makes it trivial to add logins and you can put your data in a local cake vault for privacy and security.

It also doesn't have the poor history of other password managers like LastPass. There are other free options folks can speak to, but it works great for me.

You say "other free options". Just to be clear, you mean "other options, which are free", yes? 1pass itself is a paid subscription service with a free trial?


tango alpha delta posted:

And Operating System. If you want to use Keepass with IOS devices, good luck with that.

Keepass does work beautifully in the cloud with Windows and Android, though.

If you are going to go cloud, always use two factor authentication.

If you want to spend a cubic rear end load of money, there's always CyberArk. It's a little overkill though, lol.

How do I go cloud with KeePass? Just throw the database up on Dropbox or..?

Sir Bobert Fishbone
Jan 16, 2006

Beebort

Terrorforge posted:


How do I go cloud with KeePass? Just throw the database up on Dropbox or..?

Yep, literally just that. Works seamlessly for me; I've been super happy with it.

Klyith
Aug 3, 2007

GBS Pledge Week

Terrorforge posted:

How do I go cloud with KeePass? Just throw the database up on Dropbox or..?

The android app has integration with the native android gdrive so if you use that it's totally transparent.


Kassad posted:

How does Bitwarden compare to 1password (I'm already using Keepass)?

It's always seemed to me like bitwarden has the best of all feature lists -- free tier, cloud + local, open source, easy UI -- but they haven't been around that long. They did do a 3rd party security audit last year. But the lack of track record would make me wonder about not just the security but the business model. Are they gonna be around for the next ten years, is giving away the free service sustainable?

Absurd Alhazred
Mar 27, 2010

by Athanatos
I'm glad NIST lets companies contest their findings

quote:

NOTE: the vendor disputes the significance of this finding; the discoverer was reportedly told that the Steam threat model excludes "Attacks that require physical access to the user's device" and "Attacks that require the ability to drop files in arbitrary locations on the user's filesystem" (which might apply to the attacker's ability to create links under HKLM\SOFTWARE\Wow6432Node\Valve\Steam\Apps).

:jerkbag:

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Brian Krebs got angry about a guy who proved spamhaus was blocking scanners, then started doxxing the guy because he put a bad review on Kreb's book on Amazon.

apseudonym
Feb 25, 2011


To be fair good luck being a windows program and defending against either of those short of killing yourself.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

apseudonym posted:

To be fair good luck being a windows program and defending against either of those short of killing yourself.

Yeah, if someone can put a DLL in the path you don’t expect, good night

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

CommieGIR posted:

Brian Krebs got angry about a guy who proved spamhaus was blocking scanners, then started doxxing the guy because he put a bad review on Kreb's book on Amazon.

Think this was two separate incidents. Doxed notdan over spamhaus and also some other person who left a bad review

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Rufus Ping posted:

Think this was two separate incidents. Doxed notdan over spamhaus and also some other person who left a bad review

Ah, okay. Also he doxxed the wrong guy thinking he was notdan.

BlankSystemDaemon
Mar 13, 2009



Maybe doxxing people is a bad idea no matter why/who/where/what? :thunk:

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Mmm, please dox nazis all day, every day.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply