- Joined
- Jun 30, 2021
Virgin moron who boasts about his 66GB porn collection under his real name responds to this thread and comments on KF's opsec


more about him on his thread


more about him on his thread
Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
Yeah I have a major mental block when it comes to password managers. I know Josh always recommends them but I feel like I am;handing my passwords to a service I have no reason to trust.Possible Woman Moment, but I refuse to have any passwords available online, including a password manager, saved via browser, etc. Got a notebook with a lock on it and a hidden key. If someone’s breaking into my house, I have more problems than my Protonmail account getting hacked.
You could spend a pretty chunk of change installing security and alarms for your new car— or, you could buy a $40 steering wheel lock, 1970s style. Sometimes what always worked, still works.
To a degree, yeah. But if you're an irrelevant, low-profile person and every online account you use has a unique password that will take hundreds of centuries to crack, you don't have that much to worry about, short of being keylogged.It's a never-ending arms race. Nobody can afford to be complacent.
TL;DR They have weak key derivation mechanisms for a lot of older accounts still in place since forever, but claim no one was at risk because the attacker would not be able to decrypt the gathered data. Which is also not true because URLs for services were apparently not being encrypted, because they were regarded as "not sensitive".I'm also ditching LastPass. Had an IT vendor at work today tell us that it's not safe anymore.
I tried to ask if there were any glaring holes in my approach, but apparently I angered the Android fanboys by using words they didn’t understand. FYI every Android Firmware has Facebook integration baked in to the OS, if you remove it, it breaks the firmware.Care to review my OpSec?
- Hide My Email disposable emails (single use)
- generated passwords (single use)
- 2FA (locked with FaceID)
- Nord VPN
- local Pi-hole (blocking telemetry & ads)
- Private Relay (when using Mobile network)
- AdGuard Pro (when using Mobile network)
- encrypted iPhone (FaceID)
- encrypted backup iPhone (TouchID) for locating, locking, or erasing main iPhone.
(Example email address, not actually in use)
Pi-hole statistics to show how much unnecessary traffic can be blocked.
AdGuard Pro blocklists, not as extensive as Pi-hole.
You want a different email for every website, or at least the ones you don't want to be linked together. You could use mail forwarding like Null mentioned.I use a unique password for/to every login(nothing shares as pw) i have that is the maximum characters the system/site allows that is randomized upper case characters, lower case characters, numbers, allowed symbols for the system/site, and unicode ascii if possible.
Am I doing it correctly?
You can have burner gmails if you know what you're doing with them.I refuse to believe people were not using burner emails for a site like that.
Let me open the leak text file with all the addresses and search gmail and...
View attachment 4730212
![]()
I don't trust Nord, personally. Mullvad and ProtonVPN are alternatives I like.I tried to ask if there were any glaring holes in my approach, but apparently I angered the Android fanboys by using words they didn’t understand. FYI every Android Firmware has Facebook integration baked in to the OS, if you remove it, it breaks the firmware.
password managers are better than using the same password everywhere, because they protect YOU from a site leak like thisYeah I have a major mental block when it comes to password managers. I know Josh always recommends them but I feel like I am;handing my passwords to a service I have no reason to trust.
@Null you know a lot about this stuff; could you explain to me why I am mistaken about password managers?
You can have burner gmails if you know what you're doing with them.
I'm pretty sure Keepass obfuscates itself in memory because of that reason. Probably not unbreakable (see Denuvo) but still at least something.If anyone with that degree of sophistication has that level of access to your computer, you're pretty well fucked no matter what.
I've never regretted keeping it old-fashioned with my passwordsJust a reminder: Lastpass had two security breaches recently.