Account Security

Shoke

Whiskey, boats and music
TL;DR: DON'T BE FUCKING STUPID AND SECURE YOUR SHIT!

For the past 2-3 years i have been putting a lot of attention into securing my accounts as good as i can. There have been too many major data breaches. You can easily find a massive compilation of E-mails, passwords, IPs etc on the darkweb or even just by going on some torrents website.

If you are interested to know more about those breaches, then here's an interesting article where you can read about a massive db compilation:

Even today, people are unaware (especially non-tech) and tend to use easy passwords for various websites. This is just how we humans work, we want the "easy way out" and not something complex. But this is technology and in technology everything has to be COMPLEX.

I also recommend to check this site out: https://haveibeenpwned.com/ Here you can enter your e-mail and check if your email was in a data breach.

That said, let's move onto the password manager.

There are many password managers out there, some free some paid. People tend to go with the "hype train" and what happens if you go with the "hype train"? Well you get F in the ass. Sooner or later. This is what happened with LastPass (if you used it, you will know what i'm talking about) I have personally never tried it but read an article recently about their new "changes". Due to these recent changes a lot of people stopped using lastpass and moved onto something better :)

Yk9mn2b.png

And.. here we are, bitwarden. This is my go-to password manager. I have been using bitwarden for a very long time (recently upgraded to premium, costs only 10$/year) Bitwarden is one of the last password managers that's free. The "free" plan has everything you need and want. You can create unlimited logins, install and use the app on multiple devices, you can use the built-in password gen and it's open source!

To start using bitwarden create an account on their website: Bitwarden Registration Link

NOTE: DON'T LOSE YOUR MASTER PASSWORD, BEST IS TO WRITE IT DOWN ON A PAPER!
If you lose your Masterpassword you will not be able to recover your account.


You can install bitwarden on your IOS/Android device, MacOS/Windows or obviously you can have it intergrated into the browser (addon).


OntNohR.jpg


You thought that was it? huh? 2fa? what is that?

Well, having unique complex passwords for each website is already a great step towards securing your credentials. But we can do even better. Here is where 2FA comes in to play.

Even if a hacker manages to get your password and tries login into your account, 2FA will prevent them to do so. 2FA generates unique 6 digits that rotate every 30 seconds. Without entering the correct digits in the login field you will be locked out of the account.

Just like with the PW manager, there are various apps for 2FA as well. But i would recommend to download Authy. In case you lose your device or the phone dies your codes will be backed up.

Are there any down sides? Yeah obviously, if you lose your codes you are fucked. Your account is gone forever, unless an admin (depends on the website you visit) is ok with deactivating your 2FA.

Also note: Not all websites provide 2FA but since this is 3D Forums: Fun fact did you know that Xenforo has built-in 2fa? I recommend you activate it. I have mine activated. Plus im sure esko is willing to deactivate it for you if you fuck something up.. hehe.
 
3D Forums: Fun fact did you know that Xenforo has built-in 2fa?
As a matter of fact, 2FA is enforced (in a way that they can’t continue to the forums if they don’t set it up) on for all staff members and has been so for ages now. That’s due to the reason they have a higher level of access.

nevertheless, a good post and password vault systems are a good solution. I personally also utilise iCloud’s password manager (creates safe passwords on your behalf)
 
this is good advice and more practical with people who have more than one account, but an important note can also be added which is not to use it on the phone, even if the phone has been stolen, destroyed or lost, until not do's danger on your accounts, and Thank you @Shoke
 
I personally find it unfortunate that BitWarden and even Authy are cloud-based. I like and use KeePassXC. It is cross platform, OSS and offline and am thus in full control of its database. On Android I use KeePassDX, which is compatible with its database and also open source. It also has support for hardware keys for 2FA, something I suppose Bitwarden also supports. Maybe you can elaborate more on that in your topic start post?

Oh and yes, it of course doesn't really matter what password manager you prefer or what you use, as long as you just use one. That should be the TLDR imo.
 
I personally find it unfortunate that BitWarden and even Authy are cloud-based. I like and use KeePassXC. It is cross platform, OSS and offline and am thus in full control of its database. On Android I use KeePassDX, which is compatible with its database and also open source. It also has support for hardware keys for 2FA, something I suppose Bitwarden also supports. Maybe you can elaborate more on that in your topic start post?

Oh and yes, it of course doesn't really matter what password manager you prefer or what you use, as long as you just use one. That should be the TLDR imo.

Agreed with cloud based. But remember Bitwarden is also open source, you can host it yourself == Full Control.

And yes bitwarden has 2fa implemented, this is a premium feature though. But with a price of just only 10 $ a year it's a steal.
 
Personally i've been using Keepersecurity for the past 2 years, they have a strict zeroknowledge policy which makes sure their employees cant access the database, never had issues with & been safe since i started using it.
 
So you're trying to tell me that google's password manager is not a secure option??? Maaan
 
my password "************************" all this is that good ? and there are numbers in it and like that, for anyone stupid doesn't try this "*" with my username xD
 
Back
Top