0xD

joined 1 year ago
[–] [email protected] 5 points 1 year ago (4 children)

I'm not sure I follow you - if someone can compromise the key material on my phone that is protected by a different factor, then it doesn't matter whether the 2FA is server-side or not, it's compromised either way.

[–] [email protected] 2 points 1 year ago (2 children)

But you don't?

Password managers really are not hard to use. Also there's stuff like the password manager built into iOS, for example, which you don't even have to think about.

My comment about threat modelling was that you do not seem to understand the purpose of password managers. A way bigger problem for the average person online is password reuse, not targeted attacks against password vaults. That is the problem they solve.

[–] [email protected] 22 points 1 year ago (3 children)

Marketing™️ I guess? :P

But probably because YOU don't have to fuck around with servers, for you it's just an upload of a function.

[–] [email protected] 29 points 1 year ago* (last edited 1 year ago) (5 children)

Instead of spinning up a classical server like Apache or IIS for what you need, you just write a single function that you can bind to an endpoint and just host that - the rest is abstracted away from you.

[–] [email protected] 2 points 1 year ago* (last edited 1 year ago) (1 children)

They are, just use a normal one (I use bitwarden) that you can access from everywhere and protect it with 2FA.

The goal is to have varied, secure passwords across everything.

[–] [email protected] 9 points 1 year ago* (last edited 1 year ago) (5 children)

Okay and now let's get into threat modelling and risk management.

What is the purpose of a password manager? What are the possible threats against them, and what are those against singular passwords for services? What is the risk of each of those?

[–] [email protected] 4 points 1 year ago

Click the link and you'll find out.

[–] [email protected] 2 points 1 year ago

The internal IT at that hellhole is a nightmare as well.

[–] [email protected] 6 points 1 year ago* (last edited 1 year ago) (1 children)

Since the other people don't seem too helpful to you, we can gladly setup a meeting and see where it goes :) I don't have exeprience in all these software like TrueNAS you're using but I have a lot of experience in a lot of other things, so I'm sure I'll be able to help!

[–] [email protected] 3 points 1 year ago (1 children)

Do you know what they do? I seriously cannot imagine anything where at least a tablet wouldn't be much better and more efficient.

[–] [email protected] 7 points 1 year ago (3 children)

I don't really think phones have a real use (yet?) for productivity aside from as a marketing gimmick. Only for looking stuff up.

[–] [email protected] 31 points 1 year ago

To jerk himself off about being a genius businessman.

view more: ‹ prev next ›