all these password managers have been breached in the last few years , so choosing 1 over the other is a waste.There is a list of +-4 well known products.Iam busy looking into azure key vault and see how it compares to these other products.
South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
Until the dongle is gone / stolen / dies.Veracrypt + Axcrypt + Dongle = Sorted.
Weren't you the oke going on about perfect being the enemy of good.Until the dongle is gone / stolen / dies.
Weird that there's people saying that this is no biggy.
Point of entry was a developer account that was compromised...
I have no clue why we're giving any benefit of the doubt here.Developers (usually) don't have access to production systems. Reads like the hacker got some git creds and downloaded some source code.
I have no clue why we're giving any benefit of the doubt here.
LastPass have brought in a third-party company specialising in security to audit their systems due to this. I guess we should just handwave that away as well?
On top of that, the only reason LastPass is opening their mouth now was because tech journos caught onto it from an anonymous insider...A WEEK AGO, and asked for comment a few days ago.
While I'm a huge fan of open source (And run mostly open source software) , it's a myth that open source is more secure. With open source you are relying on the community to hunt through thousands or millions of lines of code looking for issues. How many people do you know with the skills and time to do this?This is why I use Bitwarden. Opensource, anyone can see the code already.
Exactly. I really wish people would stop saying this.it's a myth that open source is more secure
They went through a round of audits then multiple vulnerabilites were found in their drivers. Just after that they closed shop.Exactly. I really wish people would stop saying this.
What happened to TrueCrypt? Googling just says that they were audited in 2015(?) and it was fine?
Well the way I see it, you have the people going through the code, who can spot bugs if they come across them, and then you have regular audits like the closed source code also has.While I'm a huge fan of open source (And run mostly open source software) , it's a myth that open source is more secure. With open source you are relying on the community to hunt through thousands or millions of lines of code looking for issues. How many people do you know with the skills and time to do this?
Look at what happened to TrueCrypt after they hired a 3rd party to audit their code.
I have backup o_0Until the dongle is gone / stolen / dies.
I have backup o_0
Snap, I just recently moved to bitwarden but had a lastpass account as backup. Officially nuked LP now.
That's actually not true. The audit only found 4 vulnerabilities the worst was using a windows interface to generate random data. You'd still need access to the physical machine to exploit any of them and Truecrypt maintained throughout that their focus wasn't on placebo measures as with physical access an attacker would choose much simpler means than try to hack the program. The cryptography at rest was still secure and overall the results were described as surprisingly good. Truecrypt was in trouble due to other reasons way before the audit and eventually the project was forked to Veracrypt.While I'm a huge fan of open source (And run mostly open source software) , it's a myth that open source is more secure. With open source you are relying on the community to hunt through thousands or millions of lines of code looking for issues. How many people do you know with the skills and time to do this?
Look at what happened to TrueCrypt after they hired a 3rd party to audit their code.
Me storing password in my brain, works well.
Here is the long and the short....
Websites and software cannot be secured. Unfortunately just not possible. The hackers probably have all the required keys now to decrypt any or all record.
You deal online, you are open to hackers. Easy as that. No matter which website you use. No matter what bank you use. They are all open to hacking and nothing can be done to prevent it.
If there was indeed a way to secure any website or software program, companies would have been all over it already and hacking would not have existed today.