2023 Security Check-up Reminder

no, we tried and it was a nightmare. Minecraft is single-threaded and my dream of a 64 player hellserver was dashed by abysmal performance.
I still cannot believe in 2023 that Minecraft still isn't fucking multithreaded.

Remember the safest way to keep your computer unhackable is to delete sys32 files, these are a common hacking vector. It’s tough to get hacked without these files.
I mean you're right.
 
@Null

thoughts on KeePass? it seems solid as far as i can tell (except for the "Keep Ass" name lol) but i am not a cryptography expert
Far better than using an online service like LastPass that’s just going to get owned.

Keypass and other local managers are as good as your systems security. In cases with malware on your machine it certainly still has weaknesses, as your master password (if keylogged) and keypass db could be exported out.

If you’re super autistic or security conscious you could run QubesOS, Fedora distro where everything runs in its own VM and you can have offline vaults etc.
 
  • Like
Reactions: Generic Retard
All of this ^
I have no idea why people suck the long schlong of password managers so much. They are all a massive single point of failure and run antithetical to some of the primary tenants of operational security. You should be using naming schemes you can keep in your head and if you have to many accounts or accounts used less often then the credentials for those accounts should either be on a unplugged device for cold storage or stored outside of digital accessibility.
Because not everyone can spend all day memorizing bruteforce-proof passwords.

And keeping a notebook of your passwords on your desk (assuming you're a desk jockey and don't WFH/aren't a NEET) is like keeping cash under your mattress.
 
Last edited:
Because not everyone can spend all day memorizing bruteforce-proof passwords.

And keeping a notebook of your passwords on your desk (assuming you're a desk jockey and don't WFH/aren't a NEET) is like keeping cahs under your mattress.
I keep my passwords on a little sticky note that I move to a different place in my cubicle daily.
 
Oh and by the way, if you are managing an "important" server.
Don't use passwords at all FFS, just use smartcards or Yubikeys (keep a password in cold storage for emergencies).
Definitely disable root login over SSH (already a default), and password authentication too. Keys only!
And remember: If you are using unrestricted sudo for your main user: Your password for that better be as good as your emergency root pw!

Your hoster should also support a second factor to authenticate you before you can use your plaintext passwords to login through their KVM.

Make sure your dongle or smartcard locks on its own after a set amount of time, so you have to enter the PIN again to use your keys.
That way an attacker can not gain access, at least for the most important stuff.
 
They didn't actually get the passwords, right? I changed mine anyway, but all I see in the leak text is emails and usernames.
you have to assume they did, even if all they got was the usernames or usernames and hashes, they could try cracking the hashes and for all we know the passwords were in plaintext or someshit.

PREDICTION: chudbuds.lol expires on 2023-09-15T21:43:45.00Z and ten milliseconds after that, someone will buy it and setup a honeypot to catch more idiots
 
I tried to ask if there were any glaring holes in my approach, but apparently I angered the Android fanboys by using words they didn’t understand. FYI every Android Firmware has Facebook integration baked in to the OS, if you remove it, it breaks the firmware.
Unless the pihole is running through the vpn as well, it half negates the anonymisation factor of the vpn. Speaking of which, you probably don’t need one.
 
Far better than using an online service like LastPass that’s just going to get owned.

Keypass and other local managers are as good as your systems security. In cases with malware on your machine it certainly still has weaknesses, as your master password (if keylogged) and keypass db could be exported out.

If you’re super autistic or security conscious you could run QubesOS, Fedora distro where everything runs in its own VM and you can have offline vaults etc.
yeah if you get compromised to the point where someone is reading your keystrokes from inside your system then you're just completely boned no matter what other security measures you have in place
 
I'm just over here using Keepass. Been using it for 15ish years and I "sync" it with a USB cable and keep backups on a couple of USB drives. I have never, ever had a problem. Things like passwords don't need to be stored on any cloud service.

How difficult is it to have an IRL email address and a shitposting email address and keep them both separate?
jesus christ

Edit> and VPNs/Tor/masking IP - I honestly just don't give a shit. But I'm in a unique position to not give a shit so that will obviously not work for everyone.
 
Once again, a lot of discussion about password managers, but not about the core problem: Stop storing your passwords.

Any password manager that stores your password will be breached in a long enough timeline. Use tools that generate your passwords on-the-fly, and only store the tedious details that are required to create the password, such as login username, the URL, etc. These are called stateless password managers, I use:

But that is only because of inertia, I've used it for years. It's opensource, on Github. You can selfhost your own instance. There are browser extensions for it, though it won't paste the password for you.

There are others, and they might be better, too. Spectre was kown as Master Password, and is older than LessPass. pass can be configured to generate stateless output, for those autistic enough. I'm sure there's more out there.

Yes, there are drawbacks, as there is for everything. Do not forget your master password. Use multiple master passwords if you need to segment your life, as @mindlessobserver said. I keep a journal; if someone wants my passwords, I'm more likely to be hacked/phised/compromised versus physically entering my home.

Build your own threat model over time, it doesn't need to be detaild, but help you figure out what behaviors are best for you to cultivate.
 
"After all, why not? Why shouldn't I use the TND copypasta as a password?"
Edited because I'm a stupid phoneposter who doesn't read his posts before hitting send lol about it
 
66GB? is he a poorfag or something? these are rookie numbers.
still, one must never falter, one must never relax for your passwords and dox can be taken in a quick swoop.

some banks are demanding 12 characters minimum, more numbers and special characters as well with at least two capital letters, for a regular person to memorize that shit, it's a pain in the ass.

You’re telling me!

MF when I have to change from adolfhitlerismywaifu to adolfhitler!ismywaifu! and some goddamn homo website tells me I need to shove some numbers in there as well.

Being online is getting to be more and more of a hassle for each year.
 
Back