Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Wiggly Wayne DDS
Sep 11, 2010



Heresiarch posted:

False Intelligence Spreading Heuristic MECHanism

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007



Heresiarch posted:

False Intelligence Spreading Heuristic MECHanism

Finitely Intelligent Simulation of Human MECHanism

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

cheese-cube posted:

Finitely Intelligent Simulation of Human MECHanism

look at this tryhard.

we already have an emptyquote bandwagon, please just jump on board.

Pile Of Garbage
May 28, 2007



yeah that was pretty terrible (mlmp). apologies all round.

goodbye secfuck thread, doomed to banishment due to fishmech's poor opsec

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

Jabor posted:

remember that lastpass's "we don't know your passwords, honest :iamafag:" thing is because they do cryptocat-style js crypto in your browser. so it would be trivial for them, or anyone who can legally compel them, to get all your passwords if they really wanted them.

keepass or bust, basically.

seriously i don't get why you'd put :nsacloud: in charge of a trove of your sensitive passwords.

ultramiraculous fucked around with this message at 18:04 on Jul 15, 2014

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

Heresiarch posted:

False Intelligence Spreading Heuristic MECHanism

Luigi Thirty
Apr 30, 2006

Emergency confection port.

reidscones posted:





˙ ͜ʟ˙

I remember reading an article about this. second life is so dead these days that the only terrorists the NSA could find were FBI agents trying to recruit terrorists on second life

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

how i remotely sync my keepass to my iphone:

openvpn into home router, download kdbx over sftp using goodreader, open file with MiniKeePass

gonadic io
Feb 16, 2011

>>=

Perplx posted:

how i remotely sync my keepass to my iphone:

openvpn into home router, download kdbx over sftp using goodreader, open file with MiniKeePass

i use spideroak's app to keep the .kdbx up to date automatically

e: this keeps it sync'd between my computers too

EMILY BLUNTS
Jan 1, 2005

GCHQ project names are a lot more quaint and less random sounding like there is probably one called CORGIPOUNCE and it's about steganography in animal gifs

reading
Jul 27, 2013
It's still totally nuts to use a one-point-of-failure cloud-bullshit password manager.

I'll probably switch this year or next but until then I enjoy remembering dozens of unique passwords. It's fun (I tell myself).

duTrieux.
Oct 9, 2003

reading posted:

It's still totally nuts to use a one-point-of-failure cloud-bullshit password manager.

Bloody
Mar 3, 2013

keep rear end knuits my seeds

vOv
Feb 8, 2014

i only use lastpass for the dumb bullshit sites that i don't care about like the Something Awful Dot Com Internet Forums. stuff like my bank and amazon account are in keepass

Luigi Thirty
Apr 30, 2006

Emergency confection port.

i helped an old person install aol on their windows 8 computer. they have had an aol account since 1996.

their password was 4 characters long.

it was their birth year.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
We have multiple computers in our household, in addition to phones. I COULD use KeePass with some nerd poo poo to synchronize it, and have my wife ignore it and reuse literally the same 8 char letters only password for everything because it's "too hard", or I could use LastPass and the browsers all magically put in the passwords and generate good ones by clicking an icon.

I chose LastPass over inadvertently sharing my banking credentials with AO-loving-L (:negative:), with Yahoo, and with some loving astrology site.

The point is LastPass and KeePass target different market segments. I'm firmly in the "Married to the weak link in the authentication chain" segment. I'm willing to take the risk that a TLA will try to compromise my credentials.

Volmarias fucked around with this message at 19:47 on Jul 15, 2014

Maluco Marinero
Jan 18, 2001

Damn that's a
fine elephant.
Yeah, I feel like the key problem with KeePass is getting it to the point where password reuse and management is not a subtle drain on your time due to the lack of good browser/OS integration. I run dev on Ubuntu, plus I've recently gotten a Mac that I'm using for testing Safari/iOS, but am leaning towards using that as my non dev activities computer just so I can get more use out of it. Sort of feels like that makes sense as an approach anyway.

Right now I'm wondering whether to ditch my KeePass shanty town in favour of LastPass or something like it, that sports a much better browser integration which can save a ton of time in the long run. LastPass's integration is really REALLY nice, but as everyone says, there's the risk of handing over the keys to the castle in a way you have little control over.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
what's the yospinion on passwordsafe?

computer toucher
Jan 8, 2012

keepass is minimal trouble if you keep it synced over some cloudthing, there are legit cloud providers other than dropbox that are security-minded, like younited from F-Secure. it has "secure" right there in the name!

also use a key file and don't put that file in the cloud.

pseudorandom name
May 6, 2007

Progressive JPEG posted:

so you must fork twice (id assume without hitting the prng after the first fork to avoid the PID mismatch being detected), and the grandparent process needs to have exited so that the grandchild process has a chance of being given the same PID

seems pretty deep in corner case land tbh

tho on the plus side maybe this means the code is becoming sufficiently legible for outsiders to reasonably review it and catch this kind of thing

if only there were some way of registering a function to be called at fork time

vOv
Feb 8, 2014

i don't bother with keyfiles and i store my keep rear end database in dropbox but i also use a diceware password and use enough rounds of key stretching that it takes a second to decrypt

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Please Use Microsoft Sky(One)Drive

ChickenOfTomorrow
Nov 11, 2012

god damn it, you've got to be kind

is 1password déclassé now rufo cracked the licensing keygen

reidscones
Apr 5, 2007

:snoop: deserve got nothin to do with it :snoop:
lastpass premium+yubikey imo
12 bucks a year plus a 25$ 2fa nerdkey for peace of mind seems worth it to me
that vuln was def disconcerting tho

Pile Of Garbage
May 28, 2007



lmao if you have lastpass/onepass/asspass and keep the creds for your email account to which everything is tied to in it and you dont have 2fa

vOv
Feb 8, 2014

cheese-cube posted:

lmao if you have lastpass/onepass/asspass and keep the creds for your email account to which everything is tied to in it and you dont have 2fa

also yeah this

my e-mail account password isn't written down anywhere

Bloody
Mar 3, 2013

my email is 2fa'd so w/e @ t he passwordl ol

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug
i dont get why browser integration is such a big deal, i log in to a handful of sites regularly and it really isnt any trouble to open keepassx, double-click things and middle-click paste them into the right fields on websites

Number19
May 14, 2003

HOCKEY OWNS
FUCK YEAH


today's security fuckup is oracle. it's time for the quarterly java security update:

http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html#AppendixJAVA

20 exploits, all remotely exploitable without authentication, 8 of them 9.3 scores or higher

:thumbsup:

Pile Of Garbage
May 28, 2007



Number19 posted:

today's security fuckup is oracle. it's time for the quarterly java security update:

http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html#AppendixJAVA

20 exploits, all remotely exploitable without authentication, 8 of them 9.3 scores or higher

:thumbsup:

looking forward to reading qualys reports next week, a nightmare in pdf form

Luigi Thirty
Apr 30, 2006

Emergency confection port.

cheese-cube posted:

looking forward to doing quaaludes next week

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Lysidas posted:

i dont get why browser integration is such a big deal, i log in to a handful of sites regularly and it really isnt any trouble to open keepassx, double-cli-

Aaaaand you've lost the audience.

Pile Of Garbage
May 28, 2007




u know, at this point i really cant tell what is worse: taking narcotics or supporting jre

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

infernal machines posted:

what's the yospinion on passwordsafe?

I made myself a MacOS build of it (gently caress paying for the official version from the app store), successfully after enduring a serious degree of pain (like installing and setting up wxWindows), and it's vile garbage. works, but barely. broken UI, had to comment out a few asserts, correct some bugs to even get it to start. crashy crap I never keep running for long

but it works, and I have moved all of my passwords to it

hackbunny fucked around with this message at 22:56 on Jul 15, 2014

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

cheese-cube posted:

u know, at this point i really cant tell what is worse: taking narcotics or supporting jre

if you're supporting the jre then you're definitely doing the other

bobbilljim
May 29, 2013

this christmas feels like the very first christmas to me
:shittydog::shittydog::shittydog:

Lysidas posted:

i dont get why browser integration is such a big deal, i log in to a handful of sites regularly and it really isnt any trouble to open keepassx, double-click things and middle-click paste them into the right fields on websites

source your quotes

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

hackbunny posted:

I made myself a MacOS build of it (gently caress paying for the official version from the app store), successfully after enduring a serious degree of pain (like installing and setting up wxWindows), and it's vile garbage. works, but barely. broken UI, had to comment out a few asserts, correct some bugs to even get it to start. crashy crap I never keep running for long

but it works, and I have moved all of my passwords to it

grazie mille

i'm on win32 so it basically just worked out of the box. at some point we're going to use it with yubikey for 2fa

Nomnom Cookie
Aug 30, 2009



Number19 posted:

today's security fuckup is oracle. it's time for the quarterly java security update:

http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html#AppendixJAVA

20 exploits, all remotely exploitable without authentication, 8 of them 9.3 scores or higher

:thumbsup:

i think we need a new word for the java security model. sandboxing doesn't quite carry the right meaning. perhaps "soliciting", as in "java solicits malicious code"

Nomnom Cookie
Aug 30, 2009



i really like java but there oughta be a law against java plugin

Adbot
ADBOT LOVES YOU

EMILY BLUNTS
Jan 1, 2005

Catboxing would be a perfect term. no matter how many times you scoop there's more stinkers hiding away and you know it. and one day they'll be uncovered

And just like java the best approach is to throw all of it in the garbage and start fresh

  • Locked thread