BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Password managers
- Subject: [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- Date: Wed, 6 May 2020 19:54:55 -0400
- In-reply-to: <CANiupv4cfVG5-tuhMdNCn-00gt4L-o54JRt30YuBB5gja_235A@mail.gmail.com>
- References: <9c4a5c7e-55aa-8ae1-da3b-4512cb2ae85c@gmail.com> <5eb1f81d.1c69fb81.80c8b.07ca@mx.google.com> <CANiupv686GBC5EZVsiEf831-b4i0E3NjZ3fnsDToM02z1zjUNg@mail.gmail.com> <5eb223cd.1c69fb81.6fa04.3ab5@mx.google.com> <0cbc8403-48a5-14bd-524c-a4eded6b64fa@borg.org> <e2be00f8-8de6-4645-e71b-a5d14f78ede7@borg.org> <5eb2d4b7.1c69fb81.c9540.9f0b@mx.google.com> <2fc76d5b-e5bd-2aa4-7002-7e7b65461d76@borg.org> <5eb2f4ba.1c69fb81.676b1.a824@mx.google.com> <CAHjm0ZGA3xca4384MqNqeiur93P4Tb=QccOiyStkr29QR2m=Bw@mail.gmail.com> <CANiupv4cfVG5-tuhMdNCn-00gt4L-o54JRt30YuBB5gja_235A@mail.gmail.com>
On 5/6/20 1:58 PM, Doug wrote: > I am not a security expert. I certainly would not notice the 2FA versus 2SV > although now I see it is a real thing. What really impressed me and got me > to take out the credit card after I read the article was that Google > required all employees to use a Yubikey to do their day-to-day jobs. Google is an extremely high value target. Google needs (and apparently has) better security than do most countries. If I were running Google security I would put a *lot* of effort into securing end points. That is, I would put effort into making sure no malware got onto employee computers. I would not let employees install whatever Chinese or Russian or American software they wanted, I would tell them to use their own computers for their own purposes. I would demand employees to treat their work security as if it were one of the most important things in their lives. I would do stuff (e.g., dedicated computer) that does not scale across the rest of employees' lives' security needs. Assembling that security would be a lot of work, I don't know the details, but it might well involve Yubikeys. But if it did, I doubt I would allow employees to commingle their Google Yubikey with personal use. It would easy to cargo-cult copy a few things visible from the outside, but very hard for others to duplicate in a real way. -kb
- References:
- [Discuss] Password managers
- From: j.natowitz at gmail.com (Jerry Natowitz)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: sweetser at alum.mit.edu (Doug)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: ajbennett at gmail.com (Jack Bennett)
- [Discuss] Password managers
- From: sweetser at alum.mit.edu (Doug)
- [Discuss] Password managers
- Prev by Date: [Discuss] Password managers
- Next by Date: [Discuss] Password managers
- Previous by thread: [Discuss] Password managers
- Next by thread: [Discuss] Password managers
- Index(es):