BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Password managers
- Subject: [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- Date: Wed, 6 May 2020 13:15:19 -0400
- In-reply-to: <CANiupv5AJPwvc4-z9Wp3PeK-Py51nRF2p87nHqs9xZERwQiCyg@mail.gmail.com>
- References: <9c4a5c7e-55aa-8ae1-da3b-4512cb2ae85c@gmail.com> <5eb1f81d.1c69fb81.80c8b.07ca@mx.google.com> <CANiupv686GBC5EZVsiEf831-b4i0E3NjZ3fnsDToM02z1zjUNg@mail.gmail.com> <5eb223cd.1c69fb81.6fa04.3ab5@mx.google.com> <0cbc8403-48a5-14bd-524c-a4eded6b64fa@borg.org> <e2be00f8-8de6-4645-e71b-a5d14f78ede7@borg.org> <5eb2d4b7.1c69fb81.c9540.9f0b@mx.google.com> <CANiupv5AJPwvc4-z9Wp3PeK-Py51nRF2p87nHqs9xZERwQiCyg@mail.gmail.com>
On 5/6/20 12:03 PM, Doug wrote: > Am I wrong to presume everyone here uses 2-factor authentication? Yubikey > is that, plus it has software that does try to figure out if the servers > being contacted are the right ones, and not ones that just look right to a > casual observer. You are wrong in the case of me. I am willing to consider trusting something like the old SecurID (was it called?). It has the virtue of being manual, so I know what it is doing and that it isn't automatically doing things without my knowing. The catch is even something that simple couldn't be trusted: RSA was an idiot organization and they had a systemic breach. Yubikey feels more "Isn't this cool!?" to me than it feels secure. Why should I trust it will only let me in? Why should I trust it *will* let me in? (What the hell do I do if I damage it? Exactly how screwed am I?) I do understand the the value of two-factor stuff to fight against compromised endpoints, but it doesn't solve, just hobbles them a little. Two-factor can be extremely valuable to protect high value stuff, but it does not scale well, and the other things needed to protect such high value targets is too burdensome for slightly normal people. -kb
- Follow-Ups:
- [Discuss] Password managers
- From: dbarrett at blazemonger.com (Daniel Barrett)
- [Discuss] Password managers
- References:
- [Discuss] Password managers
- From: j.natowitz at gmail.com (Jerry Natowitz)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: sweetser at alum.mit.edu (Doug)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: sweetser at alum.mit.edu (Doug)
- [Discuss] Password managers
- Prev by Date: [Discuss] Password managers
- Next by Date: [Discuss] Password managers
- Previous by thread: [Discuss] Password managers
- Next by thread: [Discuss] Password managers
- Index(es):