Тёмный

How Secure Is Your Password Manager? 

Mental Outlaw
Подписаться 647 тыс.
Просмотров 172 тыс.
50% 1

In this video I discuss security considerations when storing passwords yourself in an offline password manager like Keepass.
My merch is available at
based.win/
Subscribe to me on Odysee.com
odysee.com/@AlphaNerd:8
₿💰💵💲Help Support the Channel by Donating Crypto💲💵💰₿
Monero
45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436
Bitcoin
3MMKHXPQrGHEsmdHaAGD59FWhKFGeUsAxV
Ethereum
0xeA4DA3F9BAb091Eb86921CA6E41712438f4E5079
Litecoin
MBfrxLJMuw26hbVi2MjCVDFkkExz8rYvUF

Наука

Опубликовано:

 

31 июл 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 847   
@Adomas_B
@Adomas_B 9 месяцев назад
I reckon my notepad document can do the job
@smasher.
@smasher. 9 месяцев назад
Frfr
@TENNOM
@TENNOM 9 месяцев назад
best comment lol
@adamk.7177
@adamk.7177 9 месяцев назад
@KGBMajorValeriP what if someone hits you in the head really hard tho, you need a backup just in case. This comment is sponsored by helmets
@E57det7I
@E57det7I 9 месяцев назад
I mean have you really delved into password management until you have Veracrypted a txt document?
@maxscott3349
@maxscott3349 9 месяцев назад
I just wait until the junk mail I use as a mouse pad gets a hole worn into it and then write it on that and tape it to the wall next to my pc
@samsawesomeminecraft
@samsawesomeminecraft 9 месяцев назад
My threat model is mostly me forgetting my own master password to the password manager. Everything else is a lesser threat.
@phillipanselmo8540
@phillipanselmo8540 9 месяцев назад
think of your favorite animal, lookup its scientific name and use that as your password. Now, any time you forget your password you just have to search up your favorite animal.
@5371W
@5371W 9 месяцев назад
​@@phillipanselmo8540​maybe your mpw should be a bit stronger than something that falls to a dictionary attack. Better add 123 to the end just to be safe.
@Suicidekings_
@Suicidekings_ 9 месяцев назад
Sentences work best as passwords. Easier recall, less likely on a master list, harder to brute force.
@eitantal726
@eitantal726 9 месяцев назад
correct horse battery staple
@Suicidekings_
@Suicidekings_ 9 месяцев назад
@@eitantal726 nooooo!! Dr Mike Pound said NOT to use that one.
@FrogsRghey
@FrogsRghey 9 месяцев назад
Can't lose your password if you never knew them 😎
@FrogsRghey
@FrogsRghey 9 месяцев назад
@@cold_static the logic is flawless really
@YTInnovativeSolution
@YTInnovativeSolution 9 месяцев назад
​@@FrogsRgheyI use the same logic as a mechanic. Can't have a coolant leak if there is no coolant.
@HiberNAT
@HiberNAT 9 месяцев назад
I'm a Chad forget your password ? clicker for login everytime sending proof of life everytime in a 48h+ process with their enterprise helpdesk
@yosutzuhruoj
@yosutzuhruoj 9 месяцев назад
Ah, the old loop of resetting password everytime Solid choice
@TheDevouredEagle
@TheDevouredEagle 9 месяцев назад
Smart Chad move 👌
@Jeal0usJelly
@Jeal0usJelly 9 месяцев назад
I store my passwords in quantum superposition, I either remember them or not and I don't know if I do until I need to use them 😎
@handleneeds3charactersormore
@handleneeds3charactersormore 9 месяцев назад
Schrodinger's Jelly
@svampebob007
@svampebob007 9 месяцев назад
But if you don't that means a parallel universe you do.... what if he's working with the pigs snitching on YOU, or what if he was the hacker all along? can't hack me if there's nothing to hack, can't break an enter if there's nothing to break, can't steal if there's nothing to steal. I'm poor, pretty sure they would offer to pay me for a new identity.
@WoolyCow
@WoolyCow 9 месяцев назад
oh nice me too! i just updated to v.20.1 do u also have that weird bug where sometimes another evil version of you comes from a parallel universe to attack your family? i thought the devs patched it...shame
@fuckshit8208
@fuckshit8208 8 месяцев назад
Best comment here lmao
@jackstrawful
@jackstrawful 8 месяцев назад
I loved it in Battlestar Galactica when they would make such a big deal about the fact that none of their systems were networked to each other - and the one time they did need to run a network, they treated it like the most batshit insane idea anyone could possibly have and as the most dire situation they could possibly be in. If there’s one benefit to nearly being genocided by A.I., it’s that you sure do learn to respect OpSec right quick.
@Enthrall2006
@Enthrall2006 9 месяцев назад
I love that even keepass can store documents and images too. I use it for my lease papers, student loan and IRS documents.
@Avruthlelbh
@Avruthlelbh 9 месяцев назад
I see...
@monkemode8128
@monkemode8128 9 месяцев назад
Cool what password do you use?
@everypizza
@everypizza 9 месяцев назад
​@@monkemode8128Using the advice from the comments C001P@$$w0rd🇺🇦
@CRK1918
@CRK1918 8 месяцев назад
Yes, you can do that, but I don't think it's recommended because your database gets big very quickly, if you're going to store a lot of documents, using something like VeraCrypt might be a better choice.
@glass6582
@glass6582 3 месяца назад
i know
@7rich79
@7rich79 8 месяцев назад
In my opinion, it's best to educate on "good enough" or "reasonable " security. The best in class security which works well for high value targets is not necessarily the most appropriate for the average citizen. Additionally, no matter how good your password practices are, you are still vulnerable to attacks on the services you use, like a credit rating agency, online tax submission, insurance services, any business or utility that stores your credit card or has direct debit capabilities. Many of these services are difficult to avoid using too. Perhaps we can teach people more about context however. Like don't keep your passwords for work in the same password manager as the one you use privately. There is also the balance between security and convenience. Being logged out automatically from your bank after 5 minutes of inactivity is good, but perhaps you would be annoyed if your social media accounts did the same. The same perhaps also with multifactor authentication. All that being said, this video does have very good points :)
@nef36
@nef36 5 месяцев назад
Buying physical gift cards with cash is a good way to keep your debit cards off databases
@kallu6250
@kallu6250 9 месяцев назад
I write my passwords in a notebook. This is literally air-gapped level security and highly effective against cyber threats .
@richardlyman2961
@richardlyman2961 9 месяцев назад
What about when policia come to your door
@ra2enjoyer708
@ra2enjoyer708 9 месяцев назад
@@richardlyman2961They will demand you to hand over the passwords and bin you for terrorism if you refuse.
@Visquint
@Visquint 9 месяцев назад
burn burn burn@@richardlyman2961
@techguydilan
@techguydilan 8 месяцев назад
Keyloggers are practically the only cyber threat you have to look out for with handwritten passwords. Make sure to have up to date AV or keep root access pw protected if you're on Linux, and look out for any physical ones by inspecting where your keyboard plugs in occasionally and every time you use a public/lab computer.
@barlauch9292
@barlauch9292 8 месяцев назад
How often do you change your passwords? And are they long enough?
@angrypixelhunter
@angrypixelhunter 9 месяцев назад
On keepass, if you have a secured printer, you can actually print out your passwords very neatly and organized if you fancy having a physical backup.
@SosseHD
@SosseHD 9 месяцев назад
Ur printer and its software trustable?
9 месяцев назад
​@@SosseHD>even doe i can just firewall it...
@omicronx94
@omicronx94 9 месяцев назад
"a secured printer" you guys are delusional. no one has hacked your printer.
@tfr
@tfr 9 месяцев назад
@@omicronx94adding to this, ensuring it is not publicly wireless. turning off its wi-fi direct or embedded networks and preferably linking it over ethernet to your network rather than wifi is more secure. also, some printers have this “email to printer” function but obviously that goes through the internet. best bet for paranoid people is to have a vlan between the printer and the device where they can communicate but cannot access the internet. then after this step you burn your printer and send it into space aimed at the sun
@transience4172
@transience4172 9 месяцев назад
@@omicronx94 you made me laugh)
@Byzantine-Revolt
@Byzantine-Revolt 9 месяцев назад
I store my passwords on the tablets God gave Moses so I think I am good
@vadon8993
@vadon8993 9 месяцев назад
Are the tablets encrypted? Asking for Aaron
@nobodytrulyimportant
@nobodytrulyimportant 9 месяцев назад
I see you're a TempleOS fan.
@ayanami-rei-san
@ayanami-rei-san 9 месяцев назад
I'm adding 10 commandments to my hash cracking dictionary, thank you!
@adamk.7177
@adamk.7177 9 месяцев назад
@@nobodytrulyimportant comedy
@TENNOM
@TENNOM 9 месяцев назад
based
@sethbingo
@sethbingo 9 месяцев назад
keeping them written down on a piece of paper is more secure than many password managers, assuming you don't lose it
@huckleberryfinn8795
@huckleberryfinn8795 9 месяцев назад
Yeap, my passwords NEVER end up on a digital device, ever.
@lockdown727
@lockdown727 9 месяцев назад
That's what I'd do honestly and it haven't failed yet.
@entcraft44
@entcraft44 9 месяцев назад
A) It depends on your situation a bit. Do you carry it on you? Then it could easily get stolen. Do you keep it in your house? Could still get stolen in a robbery, or abused by a family member or whoever else you live with. Most people can trust their family members, but not all. A fire-proof safe is a good idea, that will certainly be enough for 99% of people. If it is a good safe and not cheap junk. B) Writing passwords down encourages the use of shorter, easier to type passwords than a solution involving copy and paste. But depending on your personal threat model, a paper list could be a viable option.
@lyndog
@lyndog 9 месяцев назад
Good points! I will say that the robbery thing is less of a threat than many think. If your little password book is non-obvious it's not going to be stolen. And in an in person robbery they'll generally be after immediate items that can be sold or used quickly.
@joaomaria2398
@joaomaria2398 9 месяцев назад
I have hundreds passwords, whenever possible going from 30 to 50 chars long. It is simply impractical to write it down.
@JRLarsen
@JRLarsen 9 месяцев назад
Another thing to take in consideration is malicious browser extensions, both ones that present themselves as a password manager or connect to your password manager
@KeithBoehler
@KeithBoehler 9 месяцев назад
Also worth adding the Ukrainian and Taiwan flag emoji to your passwords. This keeps you safe from the Russian and Chinese hackers who won't have them out of principle.
@cyphersurf890
@cyphersurf890 9 месяцев назад
That's very comical but it might actually be true!
@LaughingMan44
@LaughingMan44 9 месяцев назад
That sounds like some.made up soy-infused bs from reddit
@271kochu
@271kochu 9 месяцев назад
...you have emoji on your keeb?
@slavic_commonwealth
@slavic_commonwealth 9 месяцев назад
and then add Russia and China flag emoji next to 'em so Ukrainian and American hackers won't get you
@sellers737
@sellers737 9 месяцев назад
@@slavic_commonwealthmight as well add a bullseye emote then cause that how you'll look to the CIA / FBI
@katehikes1645
@katehikes1645 9 месяцев назад
jokes on you I write my passwords in my walls
@mgord9518
@mgord9518 9 месяцев назад
I also write my passwords in your walls
@the1necromancer
@the1necromancer 9 месяцев назад
@@mgord9518 So _you're_ who that second set of passwords belongs to. That scraping gets very annoying in here.
@quidquopro1185
@quidquopro1185 9 месяцев назад
Been using pass since 2013 and do not think I will stop any day soon. Simplicity always triumph!
9 месяцев назад
Which can easily add two-factor authentication by using a smartcard.
@quidquopro1185
@quidquopro1185 9 месяцев назад
@ Honestly never heard about that, I just use a private key.
9 месяцев назад
It's a private key on separate card like a simcard but bigger. You can also use something like a yubikey that contains also a openpgp card. @@quidquopro1185
@xybersurfer
@xybersurfer 8 месяцев назад
what is pass?
@GarfieldtheDestroyer
@GarfieldtheDestroyer 8 месяцев назад
Ah yes, the well known program "pass" E: the standard unix password manager?
@carljung4733
@carljung4733 9 месяцев назад
Great to see that Jason Tatum is so knowledgeable about this stuff
@ClickClack_Bam
@ClickClack_Bam 7 месяцев назад
Dude looks & sounds like Vegan Gains 10x more than that guy.
@isaacqadri
@isaacqadri 9 месяцев назад
Man I gotta say this. But when I see your face and hear voice there's just something pops up inside of my heart ❤. Love you so much.
@3NTR4PT4
@3NTR4PT4 9 месяцев назад
My favorite password manager is the combo-locked journal that never leaves my backpack, with cryptic riddles and secrets that need to be used for translating the passwords
@creative.money_eu
@creative.money_eu 9 месяцев назад
your videos have gotten a lot better over the years! gg!
@TheBicPen
@TheBicPen 9 месяцев назад
I like the convenience of cloud-based solutions. Tbh i dont have a problem with them if the client is open-source and I can verify that it sends and retrieves nothing that isnt encrypted locally.
@marzeqpog
@marzeqpog 8 месяцев назад
thats why i use bitwarden. the client(s) and the server are open source, but they host their own publicly available instance. all my passwords are randomly generated so even bitwarden they get breached, im pretty confident the attackers won't reverse the hash
@andrescorrea125
@andrescorrea125 9 месяцев назад
Hey Mental Outlaw , do you have plans of discussing security on self hosted services ? ...
@pureheroin9902
@pureheroin9902 9 месяцев назад
Id like to see this. I used to keep my keepass file on Google Drive then thought its probably NOT a good idea. Id much rather self host.
@nutelhere
@nutelhere 9 месяцев назад
​@@pureheroin9902why is it a bad idea?
@itsme7570
@itsme7570 9 месяцев назад
There's a lot of self hosting channels out there. Just search hardening whatever you're self hosting
@Maleko48
@Maleko48 9 месяцев назад
​@@pureheroin9902resilio sync it to yourself, or syncthing
@danielnanski838
@danielnanski838 9 месяцев назад
Same. The only thing is I dont trust myself to properly secure my system.
@blacklamb8393
@blacklamb8393 9 месяцев назад
bitwarden is the goat of password managers
@webrevolution.
@webrevolution. 9 месяцев назад
First time I actually see in one of your videos a vuln that I have used to complete a HTB machine, specifically one called Keeper. It was so satisfying to see that and be like "oh, oh I know that one, I've already used it to hack stuff".
@rithvik
@rithvik 9 месяцев назад
my exp rates go up 10% every time mental outlaw uploads.
@pepealasquid6005
@pepealasquid6005 9 месяцев назад
MY LIFE IS LIKE A VIDEO GAME
@Bagginsess
@Bagginsess 9 месяцев назад
My paper notebook has 3 defenses: a locked door, a dog, and a gun. Hack that glowie. ATF grabs the gas
@deleted_handle
@deleted_handle 3 месяца назад
Doors can be unlocked without a the key. A dog can be killed or bribed with food. You aren't always going to have your gun on hand. what if u leave ur notebook at home when ure not there?
@Bagginsess
@Bagginsess 3 месяца назад
@@deleted_handle all of that would apply to a computer too... except paper can't be remotely hacked...
@kevinklien90
@kevinklien90 3 месяца назад
@@deleted_handle stash that piece of paper in a crusty sock under the bed
@MrMakkymakk
@MrMakkymakk 9 месяцев назад
Every time I see Keepass I always read it as "keep ass"
@Artorias920
@Artorias920 9 месяцев назад
great video as always
@brunoabad1027
@brunoabad1027 9 месяцев назад
I actually remeber all my DIFERENT passwords as my insane brain is the safest software I know of
@UngovernableU
@UngovernableU 9 месяцев назад
Based
@boyproO19
@boyproO19 2 месяца назад
For me the way to remember my password is to follow a format. Yeah if one gets compromised the same format can be used to access my other accounts but I use different nicks I my password for it.
@henrygreen2096
@henrygreen2096 9 месяцев назад
Very informative, thank you. I don't know why I never considered that there could potentially be a program that reads keyboard inputs. Having something like that sending info back is wild.
@gethinfiltrator6700
@gethinfiltrator6700 9 месяцев назад
Cloud based has a purpose. It's to build and update someone's dictionary db.
@cyphersurf890
@cyphersurf890 9 месяцев назад
TRUE! it gives ammo to our enemies
@backajeno
@backajeno 9 месяцев назад
This video wasn't what I expected and it's useless for my needs❤
@Pawlash
@Pawlash 9 месяцев назад
thanks for valuable content :D
@mohitk9001
@mohitk9001 9 месяцев назад
This is good content!!
@benglick7850
@benglick7850 9 месяцев назад
RU-vid keeps unsubscribing me from you, why, this is one of my favorite channels on youtube, youtube stahp
@whatsGyall
@whatsGyall 9 месяцев назад
Text editor does wonderfully for me
@anon_y_mousse
@anon_y_mousse 9 месяцев назад
I'm sure others use the same technique, but I've learned to type in a certain way so that I could just remember a phrase as my password for any given login and then type it quickly while the end result looks nothing like the phrase I memorize.
@bestrenderings796
@bestrenderings796 12 дней назад
LOL! Love the Cheeto dead bolt!
@lavavex
@lavavex 9 месяцев назад
I love my password manager, aka my arduino that emulates a keyboard and typed the same password every time it’s plugged in
@profile-locked
@profile-locked 9 месяцев назад
A video about how to securely use your android phone or overwrite it like with tails for example etc would be handy.
@Simone-uu8ne
@Simone-uu8ne 9 месяцев назад
buy a phone that supports any other version of Android, install the OS, use it. That's quite simple. Oh, and remember that Android (as much as iOS) is not secure by design. There might be some software that tries to encrypt some data, but it's hardly possible to have more privileges than the OS itself.
@handleneeds3charactersormore
@handleneeds3charactersormore 9 месяцев назад
@@Simone-uu8ne so, Android is one (if not THE most) of the most secure OSes according to some dude that works on either tails, qubes or whonix, he's done some deep dives on this on dread (could be a glownie tho). Apparently since the beginning of Android every app has been compartmentalized into an isolated VM (makes sense, I remember the whole dalvik VM fiasco) and nowadays all phones starting from Android 8 have full disk encryption Wether your manufacturer pozzed the ROM/encryption or not that's a whole different thing, but if you run AOSP there is nothing pozzed there. Also sorry for the vagueness it's been around half a year or so since I read the info, it's not fresh in my mind
@uuu12343
@uuu12343 8 месяцев назад
I trust these hands more than the cloud
@aschelocke5287
@aschelocke5287 9 месяцев назад
You can roll back your database with gdrive. Did it a couple of months ago when it became corrupted
@kH-ul4hk
@kH-ul4hk 9 месяцев назад
What is your opinion of the trend of moving to passkeys?
@Two-Checks
@Two-Checks 9 месяцев назад
How's notepad in a veracrypt container?
@MacroAcc
@MacroAcc 5 месяцев назад
Good. Just don't store the password in an unencrypted place. Keep it in the (encrypted) container.
@knightrider585
@knightrider585 9 месяцев назад
If someone somehow changed your keepassxc database password, or corrupted it, or whatever, you could just restore from your backups couldn't you? If you are managing your own password database your have backups, right?
@madisonhanberry6019
@madisonhanberry6019 9 месяцев назад
I like your club penguin shirt
@jpdlpokedigi10
@jpdlpokedigi10 9 месяцев назад
Keepass ftw
@travis5732
@travis5732 9 месяцев назад
A self hosted password manager is doing the trick for me.
@newmonengineering
@newmonengineering 9 месяцев назад
I use passport, it comes with Gryphin Router. It's a block chain storage container
@logginglogs
@logginglogs 9 месяцев назад
good video
@ffwast
@ffwast 9 месяцев назад
Very secure (notebook on my desk requires physical access)
@Vigaberno
@Vigaberno 9 месяцев назад
I’ll wait for the people warning you about burglaries, house fires or evil people disguised as friends.
@llamingo
@llamingo 9 месяцев назад
I use both Bitwarden and Proton pass manager. 👍
@azahid1aza751
@azahid1aza751 6 месяцев назад
I was wondering, what about bitwarden? Sure it's cloud, but it's FOSS
@YannMetalhead
@YannMetalhead 9 месяцев назад
Good video.
@Vemu
@Vemu 9 месяцев назад
What do you think of Bitwarden?
@ST-actual
@ST-actual 8 месяцев назад
Not watching but the trick is to have a password you use for everything. You’ll use that as your second half. The first half can be stored in a password keeper. This way when you autocomplete your password there’s still a bit of manual work to do to get logged in.
@Nickname863
@Nickname863 9 месяцев назад
Doesn't that vurnability also mean that if i get compromised via Software, that this software can change my password and then steal my vault?
@Frontman15G
@Frontman15G 9 месяцев назад
is it problematic when you still use apples built in password app?
@markarca6360
@markarca6360 9 месяцев назад
Jason Donenfield? Yes, this is the same man behind Wireguard!
@Zeioth
@Zeioth 9 месяцев назад
In my last company we were considering a cloud password manager. We decided not to. 5 Months or so after said service was hacked.
@coldnessinmyheart.
@coldnessinmyheart. 6 месяцев назад
Lastpass moment
@NobodyisAnybody
@NobodyisAnybody 9 месяцев назад
0:26 Flamin’ hot security
@simp-
@simp- 8 месяцев назад
I just create other password for every website and then when I login in, I try 30 of them before guessing right. Works? Works.
@yippyo
@yippyo 9 месяцев назад
Friendly reminder to backup your keepass files to the cloud/NAS (preferably in a encrypted 7z folder)
@HunterKiotori
@HunterKiotori 9 месяцев назад
Can keepass read and edit the file inside the 7z? Or do you have to take it out every time
@W4nn3
@W4nn3 9 месяцев назад
The database is already encrypted with your master password. No need to encrypt it again.
@tfr
@tfr 9 месяцев назад
@@W4nn3furthermore if your nas supports SED, use that. makes your drives encrypted on the fly so even if the nas is physically stolen, nobody can even see what files are on it to begin with so they won’t know you’ve got a keepass database
@handleneeds3charactersormore
@handleneeds3charactersormore 9 месяцев назад
@@W4nn3 nothing wrong with multi layer encryption, also super useful for compartmentalized databases
@schetenwapper6591
@schetenwapper6591 9 месяцев назад
you dawg I heard you like encryption so I put an encrypted vault in an encrypted vault so you can decrypt while you decrypt. Eh, idk. This meme has better uses.
@gitgudchannel
@gitgudchannel 9 месяцев назад
vaultwarden goated
@jessicamann684
@jessicamann684 21 день назад
Is there a password manager that also hase asymetrical encryption? this is to, for example, back up recovery keys for hard drive encryption that should not be easily accessable and rarely if ever used. the private key could then be kept somewhere very safe for a rainy day.
@Ataraxia_Atom
@Ataraxia_Atom 9 месяцев назад
I use bitwarden with the anticipation that ill self host at some point.
@inithinx
@inithinx 9 месяцев назад
Selfhosted Vaultearden, syncing only when im in the local network. Kinda works like a pseudo-sync.
@Jordan-hz1wr
@Jordan-hz1wr 9 месяцев назад
I’d rather be responsible for 1 single .kdbx file than need to self host an entire backend server infrastructure.
@inithinx
@inithinx 9 месяцев назад
@@Jordan-hz1wr while that's true, I maintain a password manager for like 15 people, and have a local dns, local mail server and everything. vaultwarden makes selfhosting super simple (literally a docker container)
@slavic_commonwealth
@slavic_commonwealth 9 месяцев назад
you're not schizo enough, then. @@Jordan-hz1wr
@Chaunton
@Chaunton 8 месяцев назад
How do you feel about self hosted vaultwarden?
@sfzndo
@sfzndo 8 месяцев назад
never thought I'd see jayson tatum telling me about password managers but here we are
@Lulxec
@Lulxec 9 месяцев назад
I made my own terminal based password manager with 256AES encryption that requires a specific usb to run
@dnizamovv
@dnizamovv 9 месяцев назад
What would you say of something like Bitwarden, which is open source, but still cloud based
@NuchiAsaki
@NuchiAsaki 9 месяцев назад
It's still someone else's computer.
@NuchiAsaki
@NuchiAsaki 4 месяца назад
@@kaper-sd9qx If it's on the internet it's a target. If they turn off their PC, you lose access. You don't know them, you shouldn't trust them.
@Sandeep6
@Sandeep6 9 месяцев назад
I save passwords on notepad and i change 1 or 2 letters in a password and i remember it. So even someone looks into it. It's not completely a correct password
@erik-001-
@erik-001- 9 месяцев назад
I use iCloud Keychain, what’s your opinion on it Mental?
@CaptZenPetabyte
@CaptZenPetabyte 8 месяцев назад
I have a manual / offline password management that uses an algorithm thats easy to remember on top of that combined and is kept in my wallet (and other locations, in a 3/2/1 backup style) and even if people get hold of the 'card' they cant decrypt because they dont have the memorised algorithm ... if *any* part of the system is compromised (any 1 of the 3 parts) it takes literally *minutes* to re-create a new 'system' and change all passwords and the old 'parts' are made useless.
@RylanTech
@RylanTech 9 месяцев назад
I'm a web dev and my next project is a open source, web based password manager. It's probably not going to be amazing but It my data on my software on my hardware on my network.
@Voidkitty_
@Voidkitty_ 9 месяцев назад
I store all my passwords in a notebook, what do you think of this practice (no my passwords aren't dumb things like password123)
@olamidehimself
@olamidehimself 9 месяцев назад
I dont know why I ever thought you a white man in his early 40s who has been in the IT space since 2005😀. Keep up the goood work, man. love the videos
@zbdfhg
@zbdfhg 9 месяцев назад
Title reminds me of, "What color is your Bugatti?"
@motionthings
@motionthings 9 месяцев назад
Self hosted Vaultwarden here :)
@spacewad8745
@spacewad8745 9 месяцев назад
nice runescape skin luke
@marcusfleuti2672
@marcusfleuti2672 9 месяцев назад
If you work with like Linux Mint, it will keep your Keepass up-to-date automatically via integrated package manager ;)
@chbrules
@chbrules 9 месяцев назад
Keepass and Veracrypt FTW
@thebitter6262
@thebitter6262 9 месяцев назад
I have been using a Kingston DataTraveler USB stick and KeePass portable for about 10 years.
@capitolia
@capitolia 2 месяца назад
…and for the mobile phone?
@thebitter6262
@thebitter6262 2 месяца назад
​@@capitolia The only passwords saved on my phone are for Discord, Brilliant and Disney+. Yes, a long time ago I had to type them in manually. My approach is to keep important things as far away from my phone as possible.
@ruffywhite
@ruffywhite 9 месяцев назад
i got a text file in a locked zip folder. like that I can also copy the list on USB sticks
@Chan-minion
@Chan-minion 9 месяцев назад
The most secure is the simple ones, remember it or put it in a physical lock on a piece of paper
@IvanToshkov
@IvanToshkov 7 месяцев назад
I haven't read the CVE thing, so I might be talking about a different thing. I think there's a scenario that it might be worse than just corrupting the DB: the attacker can change the master password and then copy the database file. This way, they can unlock the DB file later and gain access to your passwords. If they create a backup copy of the file beforehand and then restore it, one might not even be aware of this happening. A way to mitigate this would be to require the current master password when there's a request to change it, even if the DB is unlocked at that time.
@BillAnt
@BillAnt 4 месяца назад
A simple user defined timeout feature could mitigate the database being left open for a length of time. They can corrupt it all they want, as long as you have a couple of backups in different places.
@IvanToshkov
@IvanToshkov 4 месяца назад
@@BillAnt And what would be a sensible timeout that on the one hand mitigates the problem and on the other doesn't make the UX unbearable?
@BillAnt
@BillAnt 4 месяца назад
@@IvanToshkov- That's why I wrote "a user defined timeout". Anywhere from a minute to an hour, whatever you feel comfortable with.
@YouMe-mf7ed
@YouMe-mf7ed 9 месяцев назад
Mental outlaw. I know you talked about other companies that seem to do a very good job protecting passwords that you have used. I just have a question about Kaspersky password protection? Has there been any leakages you know about or data sharing? Ik its a russian company but online I can't seem to find a genuine article talking about data breaches other that redditors going dumb and scaring others using "I have heard statements than facts" in password manager. Would love an insight or video on this topic, please 🙏
@Unmixable404
@Unmixable404 9 месяцев назад
I find it interesting how no one mentions bitwarden. Is it bad or something?
@imsaragde
@imsaragde 9 месяцев назад
Great vid. Curious about your opinion on passkeys
@tfr
@tfr 9 месяцев назад
honestly i don’t like passkeys. i prefer security keys. passkeys use your FIDO key as a 1fa method to log in security keys add your FIDO key as a 2fa method to log in Having both a password and FIDO key is much better IMO If someone steals your key, they also need the password.
@chinoto1
@chinoto1 9 месяцев назад
I started using buttercup after seeing an article about a new open source password manager. If it weren't for that article, I might have stuck with a plain-text file.
@NumberOneBlackGuy
@NumberOneBlackGuy 2 дня назад
JT doing side quests
@savelleanthony6264
@savelleanthony6264 9 месяцев назад
What chair is that?
@AstroSamDev
@AstroSamDev 9 месяцев назад
I just wrote my own password manager, it is really quite simple to do if you understand using simple encryption libraries (just wait until those become vulnerabilities ). It stores all passwords in an encrypted file, which you unlock with a master password, and can also encrypt each entry a second time with a different password. You can also store other files, and just plain text in this encrypted database, and you can generate new totally random new passwords when you need to change (as you should regularly do). Really is quite useful.
@adamk.7177
@adamk.7177 9 месяцев назад
Keepass has most of the same features, so I say you did a good job, bravo on the storing other files part. I don't think you can do that in KeePass actually.
@RADIUM108
@RADIUM108 9 месяцев назад
​@@adamk.7177you can store other files in keepass if I remember correctly
@tablettablete186
@tablettablete186 9 месяцев назад
But did you implement any process isolation features? Things like running in a secure desktop and with a different SID
@user-zn3zx6fk7u
@user-zn3zx6fk7u 9 месяцев назад
>I just wrote my own password manager i did it too lol, but dont use it since i fear it bugging and im not a good developer
@hipersonic999
@hipersonic999 9 месяцев назад
@@adamk.7177 , I think you can, actually, at least in the android version, I recall having something like that.
@shala6889
@shala6889 9 месяцев назад
yet to watch the video but my only password manager is a piece of paper that I keep hidden (and I do use 16 random character passwords). let's see if this changes my mind
@cruiserkumano
@cruiserkumano 8 месяцев назад
Well, you could write down your passwords and store it in a safe deposit box as a backup.
@jmtradbr
@jmtradbr 9 месяцев назад
Before i knew about password managers in early 2010s i used to write everything in a txt document and compact with password in a .rar file.
@boyproO19
@boyproO19 2 месяца назад
And where did you store those rar passes?another txt file?
@thisisnotok2100
@thisisnotok2100 9 месяцев назад
I self host passbolt, shit rocks
@TheStiepen
@TheStiepen 8 месяцев назад
This video doesn't really talk about the other side: end user compatibility. A regular user does not know how IT Security works nor should they need to know. If we want those people to use password managers they need to be easy to use. This includes being able to securely sync them between devices without having to configure anything and without having to set up own server infrastructure. A keepass file on a Dropbox share is reasonably good. But it also needs to integrate with your browser (unsure if keepass supports this). And honestly, even a proprietary password manager is better than reusing the same password for every website, which a lot of people actually do.
@techguydilan
@techguydilan 8 месяцев назад
I personally like Bitwarden because I feel its the best of both worlds. Its code is available and auditable by anyone who wishes to look at it. In that way their zero-knowledge approach can be verified. As we're learning each and every month it seems that with LastPass, sometimes zero-knowledge doesn't mean the same thing to proprietary platforms. As I obfuscate my usernames for some things too, it was very alarming to me to learn that attackers had access to all of them and explained why my bank account kept getting locked out due to password guesses despite my username being a combo of my initials and a string of random numbers.
@banaantje0456
@banaantje0456 8 месяцев назад
Browser integration is not really needed for keepass if you set up autotype correctly. The approach of keepass and remote storage is amazing as a tradeoff between usability and security. I do that as well but instead of cloud storage i have it on a host on my local network accessible with a vpn.
@TheStiepen
@TheStiepen 8 месяцев назад
@@banaantje0456 that works well for someone like you or me. It doesn't work well at all for someone like my mother who doesn't even have a clue what autotype is, let alone how to set it up. Also proper browser integration is great protection against phishing, because it won't let you use the password on the wrong website.
@nathanoneiric
@nathanoneiric 8 месяцев назад
KeepassXC has great browser integration
@firebadnofire9768
@firebadnofire9768 9 месяцев назад
My personal favorite password manager: The 5gb LUKS partition on my server
@ner0718
@ner0718 5 месяцев назад
I am using a password manager with propitiatory cloud saves, to sync passwords between devices. But I am not storing any passwords there I cannot afford to lose.
@RedstoneHair
@RedstoneHair 9 месяцев назад
I use next cloud passwords app, is that bad? Should I make it more secure somehow? I have 2FA 😁
@XavierHyena
@XavierHyena 9 месяцев назад
"Old Man Yells at Cloud"
Далее
How Strong Should Your Passwords Be
13:46
Просмотров 199 тыс.
The Anti-Virus Tier List
9:38
Просмотров 1 млн
Вопрос Ребром - Субо
49:41
Просмотров 1,6 млн
I Tested 7 Password Managers: the BEST of 2024 is…
5:48
Bad OPSEC - How The Feds Traced a Monero User
13:55
Просмотров 511 тыс.
Why PassKEYS are Replacing PassWORDS
3:55
Просмотров 198 тыс.
The LastPass Hack Was Worse Than We Thought
9:46
Просмотров 390 тыс.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
Просмотров 409 тыс.
Stop Using Tor With VPNs
11:41
Просмотров 802 тыс.
#samsung #retrophone #nostalgia #x100
0:14
Просмотров 13 млн
Battery  low 🔋 🪫
0:10
Просмотров 13 млн
📱магазин техники в 2014 vs 2024
0:41