Use the "passwords" feature to check if one of yours is compromised. If it shows up, never ever reuse those credentials. They'll be baked into thousands of botnets etc. and be forevermore part of automated break-in attempts until one randomly succeeds.

you are viewing a single comment's thread
view the rest of the comments
[–] 341 points 10 months ago (98 children)

Protip for the room: Use a password manager with a unique password for every service. Then when one leaks, it only affects that singular service, not large swaths of your digital life.

  • source
  • hideshow 98 child comments
  • [–] 101 points 10 months ago (10 children)
  • [–] 41 points 10 months ago (7 children)

    I hate how many places don't allow for + aliases. I want to know who leaked my email.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 22 points 10 months ago* (last edited 10 months ago)

    No + required. There are hundreds of companies offering aliases using their shared domain. You can also just generate a temporary email address if you don't require any ongoing communication and the account is not super important.

  • source
  • parent
  • [–] 21 points 10 months ago (2 children)

    At the same time, it is trivially easy to strip a + alias, so I'd not trust it to do anything much at all.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 6 points 10 months ago (1 child)

    If you use aliases for all services, it makes it slightly harder to automate trying one leaked email on another site, since the hacker needs to add the new alias on the other service.

    No one is going through of all these credentials manually, so any extra obscurity can actually bring you security in a pinch. Although if you have different passwords this shouldn't matter much...

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (2 replies)
  • [–] 59 points 10 months ago (4 children)

    Don't forget unique email addresses. I've had two spam emails in the last 6 months, I could trace them to exactly which company I gave that email address to (one data breach, one I'm pretty sure was the company selling my data). I can block those addresses and move on with my life.

    My old email address from before I started doing this still receives 10+ spam emails a day.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 10 points 10 months ago (3 children)

    I've started using {emailaddress}+{sitename}@gmail.com i.e. myemail+xyzCompany@gmail.com

    That way I can at least see who sold my info. I wish I would have started doing this long ago though. Some sites dont let you use the plus symbol even though it's valid though

  • source
  • parent
  • hideshow 3 child comments
  • [–] 36 points 10 months ago (2 children)

    This trick is common enough and trivial to reverse engineer. I can just purge my billion-email-address hacked list of all characters between a + and an @ and have a clean list that untraceable with your system.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 12 points 10 months ago (1 child)

    Right? Has this ever worked for anyone? I've never bothered because of how easy it is for spammers to bypass.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 18 points 10 months ago*

    Spammers go for the easiest targets. If you do stuff like this, they might redesign their system to make it LESS likely to send to you. Keep in mind theyre targetting the elederly, mentally handicapped, and the emotionally desperate. They specifically DO NOT want to target the educated, technologically literate, and those that will waste their time. By attempting to technologically limit them from their scams, you make it more difficult for them to target you and it makes it obvious theyre not worth your time.

    Its not about making yourself scam proof, its about making yourself an unappealing target.

    (This all applies to scam emails, dunno if it has any effect if the goal is phishing but i would imagine so. If they can phish 5 people in the time it takes to phish you, youre no longer their target.)

    Edit: this is why scam emails look obviously scammy, with misspelled words and grammarical errors. Its not a mistake, its an attempt to preemptively weed out people who want to waste their time

  • source
  • parent
  • [–] 9 points 10 months ago (8 children)

    Also, length is most of what matters. A full length sentence in lowercase with easy to type finger/key flow for pw manager master, and don't know a single other password. Can someone correct me if I'm wrong?

  • source
  • parent
  • hideshow 8 child comments
  • [–] 6 points 10 months ago* (2 children)

    I've found that there are a handful of passwords that you need to remember, the rest can go in the password manager. This includes the password for the password manager, of course, but also passwords for your computer/phone (since you need to log in before you can access the password manager), and your email (to be able to recover your password for the password manager).

    You are also correct that length is mostly what matters, but also throwing in a random capitalization, a number or two, and some special character will greatly increase the required search space. Also using uncommon words, or words in other languages than english can also greatly increase the resistance to dictionary attacks.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
  • load more comments (5 replies)
  • [–] 8 points 10 months ago (27 children)

    Which one works on all browsers including mobile safari and mobile Firefox?

  • source
  • parent
  • hideshow 27 child comments
  • [–] 56 points 10 months ago (8 children)

    Bitwarden has been good for me, but I actually don't know about safari...

  • source
  • parent
  • hideshow 8 child comments
  • [–] 23 points 10 months ago (7 children)

    It works with Safari. I use both Bitwarden and mobile/desktop Safari.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 13 points 10 months ago

    Keepass does a pretty decent job. I have keepassXC on my Windows, Debian and Android devices. On Android it's integrated into the phone(and the autofill service if actual 2fa isn't supported on the app) so it works on every application. With IOS though I know they can be a stickler on anything remotely technical so I'm not sure if something similar exists with it. I also use syncthing as the service to make sure the same copy of the database is on each device to prevent having to use a password manager that requires a subscription for a cloud service, this also minimizes my risk factor of a cloud service being compromised.

  • source
  • parent
  • [–] 6 points 10 months ago (2 children)

    For mobile safari Bitwarden (and I think a number of others, but Bitwarden's the only one I can speak to) ties into Apple's password management system for autofill and password generation. Still have to use the app or webpage (either Bitwarden's official site or self-hosted vaultwarden) for more in depth management.

    For mobile Firefox, on iOS it's the same as Safari. On Android you can either use the Bitwarden add-on or use it with the app and Android's built-in password management system just like on iOS.

    Since you mentioned "all browsers" for chrome/chromium based browsers there is also on add-on for both mobile and desktop. For Internet Explorer and pre-chrome Edge I don't believe there's an add-on but it can still work, it'll just be more of a pain since you autofill either won't work or will be spotty. You'll probably be relying on the standalone desktop app.

    On MacOS it integrates with Apple's password management, so no need for an add-on on desktop safari.

    For other browsers, you'll probably have to use the desktop app and manually copy/paste just like for IE.

    I also remember seeing some third-party integration for the windows terminal app and various Linux terminals, but I can't really speak to their quality or functionality since I haven't used them. But that would probably cover your needs for terminal based browsers like Lynx.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
  • load more comments (12 replies)
  • [–] 5 points 10 months ago* (2 children)

    I was thinking about this earlier. The password manager browser plugin I use (Proton Pass) defaults to staying unlocked for the entire browser session. If someone physically gained access to my PC while my password manager was unlocked, they'd be able to access absolutely every password I have. I changed the behavior to auto-lock and ask for a 6-digit PIN, but I'm guessing it wouldn't take an impractical amount of time to brute-force a 6-digit PIN.

    Before I started use a password manager, I'd use maybe 3-4 passwords for different "risks," (bank, email, shopping, stupid shit that made me sign up, etc). Not really sure if a password manager is better (guess it depends on the "threat" you're worried about).

    Edit: Also on my phone, it just unlocks with a fingerprint, and I think law enforcement are allowed to force you to biometrically unlock stuff (or can unlock with fingerprints they have on file).

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (1 reply)
  • load more comments (41 replies)