social.coop is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Fediverse instance for people interested in cooperative and collective projects. If you are interested in joining our community, please apply at https://join.social.coop/registration-form.html.

Administered by:

Server stats:

489
active users

#diceware

0 posts0 participants0 posts today

Need help generating a #secure #password? #password #dotcom got you down? Out of #correct #horses to #battery #staple? Don't worry! Here at #typeslut #four #point #zero #point #zero, we have just the thing for you: the #official #typeslut #diceware #password #generator #for #use #with #at #least #one #d6! Simply #roll your d6, and watch as your password forms:

INSTRUCTIONS: Simply roll the dice and pick out the corresponding number! Each roll adds at least bits of security!

1: Brian Thompson
2: Brian Griffin
3: Brian.... Heffner?
4: Bri Bri
6: Brian Th0mpson

@mailbox_org Sorry Mailbox but after being your customer for 6 years I have to say something honestly and directly.

Your security understanding sucks!
You don't allow me to use TOTP, U2F with my own Yubikey.
And don't accept my 8 word bzillion bit #diceware password because it does not have special, capital letters and numbers.

This is not how you should be doing, not at the end of the 21st century's first quarter is about to end!

Debunking Cybersecurity Myths

Cybersecurity expert Eva Galperin — @evacide — helps debunk some common myths about cybersecurity.

☑️​ Is the government watching you through your computer camera?

☑️​ Does Google read all your Gmail?

☑️​ Does a strong password protect you from hackers?

☑️​ Will encryption keep my data safe?

☑️​ Are all hackers bad people?

Eva answers all these questions and much more using clear language that's easy to understand.

Eva Galperin is the Director of Cybersecurity at the Electronic Frontier Foundation — @eff

Rather read than listen? A helpful transcript is available.

wired.com/video/watch/expert-d

#Infosec #Cybersecurity #BeCyberSmart
#MoreThanAPassword #InfosecTraining
#DiceWare #Encryption #Passwords
#PasswordManagers #PublicWiFi #VPN
#EFF #ElectronicFrontierFoundation

Replied to Icho Tolot

@IchoTolot While I don't use #diceware myself, it is actually not bad.

I prefer tied-together, long and ridiculously weird looking chemical formulas that I'm actually able to memorize easily.

Just don't ask me to remember names of persons. More often than not I recognize someone, but can't remember their name... I hate that.

The US treasurydirect.gov site is finally getting rid of their shitty virtual keyboard. Right now you have to click an on-screen keyboard to enter your password, which is unfortunately *less* secure since it discourages people from using a more secure Diceware-style passphrase or more complex passwords. Progress! #security #diceware

Happy #WorldPasswordDay!

I've cracked billions of #passwords from tens of thousands of #data #breaches in the past 12+ years, and because of this, I likely know at least one #password for 90% of people on the Internet. And I'm not alone! While I primarily crack breached passwords for research purposes and the thrill of the sport, others are selling your breached passwords to criminals who leverage them in #AccountTakeover and #CredentialStuffing attacks.

How can you keep your accounts safe?

- Use a #PasswordManager! I recommend @bitwarden and @1password

- Use a #Diceware style #passphrase - four or more words selected at random - for passwords you have to commit to memory, like your master password!

- Enable MFA for important online accounts, including cloud-based password managers!

- Harden your master password by tweaking your password manager's KDF settings! For #Bitwarden, use Argon2id with 64MB memory, 3 iterations, 4 parallelism. For #1Password and other PBKDF2 based password managers, set the iteration count to at least 600,000.

- Use unique, randomly generated passwords for all your accounts! Use your password manager to generate random 14-16 character passwords for everything. Modern password cracking is heavily optimized for human-generated passwords, because humans are highly predictable. Randomness defeats this and forces attackers to resort to incremental brute force! There's no trick you can do to make a secure, uncrackable password on your own - your meat glob will only betray you.

- Use an ad blocker like #uBlock Origin to keep you safe from password-stealing #malware and other browser based threats!

- Don't fall for #phishing attacks and other social engineering attacks! Browser-based password managers help defend against phishing attacks because they'll never autofill your passwords on fake login pages. Think before you click, and never give your passwords to anyone, not even if they offer you chocolate or weed.

- #Enterprises: require ad blockers, invest in an enterprise password management solution, audit password manager logs to ensure employes aren't sharing passwords outside the org, implement a Fine Grained Password Policy that requires a minimum of 20 characters to encourage the use of long passphrases, implement a password filter to block commonly used password patterns and compromised passwords, disable #NTLM authentication and disable RC4 for #Kerberos, disable legacy broadcast protocols like LLMNR and NBT-NS, require mandatory #SMB signing, use Group Managed Service Accounts instead of shared passwords, monitor public data breaches for employee credentials, and crack your own passwords to audit the effectiveness of your password policy and user training!

How did I end up making calculations in a spreadsheet instead of studying now?

I just quickliy wanted to check what the picture about password security, that is currently shared a lot means for the security of #passphrase / #diceware.

Ehm, the Internet in the train was shitty, so I couldn't study! Let's use that as excuse. (He says, hours after exiting the train.)

Debunking Cybersecurity Myths

Cybersecurity expert Eva Galperin -- @evacide -- helps debunk some common myths about cybersecurity.

☑️​ Is the government watching you through your computer camera?

☑️​ Does Google read all your Gmail?

☑️​ Does a strong password protect you from hackers?

☑️​ Will encryption keep my data safe?

☑️​ Are all hackers bad people?

Eva answers all these questions and much more using clear language that's easy to understand.

Eva Galperin is the Director of Cybersecurity at the Electronic Frontier Foundation -- @eff

Rather read than listen? A helpful transcript is available.

wired.com/video/watch/expert-d

#Infosec #Cybersecurity #BeCyberSmart
#MoreThanAPassword #InfosecTraining
#DiceWare #Encryption #Passwords
#PasswordManagers #PublicWiFi #VPN
#EFF #ElectronicFrontierFoundation

Is it REAL or is it FAKE?

Did you know that the skills you need to recognize a real word are completely different from the skills you use to recognize a fake word?

How well would you do? Which one of your word-recognition superpowers is naturally stronger?

The Center for Reading Research provides an online Word Test to measure:

➡️​ How large your vocabulary is.

➡️​ How well you can distinguish between a FAKE word and a REAL word.

With this test you get a valid estimate of your English vocabulary size within 4 minutes and you help scientific research by advancing word knowledge.

You can enter profile information about yourself if you like, or not enter any personal info.

These are the same folks at Ghent University in Belgium who conducted the readability research which led to major improvements in DiceWare. These improvements mean DiceWare is now ready for a larger audience, and could provide an "on ramp" to engage more members of the public in cybersecurity.

vocabulary.ugent.be/

#RealOrFake
#WordTest
#DiceWare