Showing posts with label Password Keeper. Show all posts
Showing posts with label Password Keeper. Show all posts

Tuesday, August 12, 2014

Nerd News: LastPass Back Up

LastPass has been down for a while, but according to LastPass and other reports it should be back up, though there may still be some issues.

Sounds like they only use 2 datacenters, or maybe even only single primary one with a "backup".
"Update: 1:28 pm EST

Though one of our data centers remains completely down, the service is generally stable and should be available to the majority of users (with the exception of login favicons). Some users may see connection errors but should still be able to access their data. We continue to work as quickly as possible to get the service back to 100%. "
       Source http://blog.lastpass.com/


"Aug 12, 2014 - One of LastPass' datacenters has been down since 3:57am EDT. The service is now running fully off one Herndon VA datacenter and we have been engaged with our provider all morning. Currently favicons/sprites are impacted. We are doing what we can to minimize the impact and apologize for the inconvenience. "

       Source https://lastpass.com/status.php


Also http://www.isitdownrightnow.com/lastpass.com.html 

For LastPass users that want an offline solution to prevent this type of problem in future consider LastPass Pocket

This is LastPass link specifically about offline access https://helpdesk.lastpass.com/password-manager-basics/your-lastpass-vault/offline-access-to-your-lastpass-vault/ 


Monday, May 13, 2013

Problems & Solutions for Apple ID 2 Step Verification (2 Factor Authentication)

Though I blogged about this when it first came out, http://cliffsesportcorner.blogspot.com/2013/03/apple-adds-2-step-verification-2-factor.html

I learned a couple of important tidbits today about it: 1) Verification does not follow when phone is replaced, 2) You need to type recovery key, not cut and paste it.

Thanks to Jeff Kibuule for tweeting about these issues https://twitter.com/jeffkibuule/status/333765576226914305

That is where I learned about these problems.

I agree with Jeff that Apple Store employees need to be aware of this issue when they suggest swapping phones for customers.

I hope this saves people from some headaches!

Also really suggest people that use this two step verification have more than one Trusted Device, and more than one hard copy of the Recovery Key securely stored, because even if you are trying to recover lost password, you will still need a minimum of two of the 3 following: 

  • Apple ID password
  • Trusted Device [ SMS capable phone OR iOS device with Find My iPhone enabled]
  • Recovery Key [14 digit Recovery Key Apple provides, they say print and keep in a safe place]


Reference Links:

Friday, March 22, 2013

Apple adds 2 Step Verification (2 Factor Authentication) for Apple ID

This is big Security News, Apple has finally followed Google and others in having a Two Step (I think of it as 2 Factor) Security option.

Note, this appears to be true Two Factor, even if you are trying to recover lost password, you will still need a minimum of two of the 3 following: 
  • Apple ID password
  • Trusted Device [ SMS capable phone OR iOS device with Find My iPhone enabled]
  • Recovery Key [14 digit Recovery Key Apple provides, they say print and keep in a safe place]


This has both a Pro, since it will be very hard for someone to Hack if your using strong a password.

As well as a Con, if you forget or lose 2 of those 3 things, you will be locked out of your Apple account forever, and would have to get a new one.

You can have multiple Trusted Devices though, and there is no reason you can't have a couple of hard copies of the Recovery Key in safe deposit box and home or office safe.

And if you use a good Password Keeper, also known as Password Manager, like LastPass https://lastpass.com/ you only need to remember one good password.

Reference Links:




Friday, January 11, 2013

More on Passwords & Password Keepers

 I may have mentioned Brian Kreb's password article before, http://krebsonsecurity.com/password-dos-and-donts/, but wanted to make sure I linked to this article http://krebsonsecurity.com/password-dos-and-donts/

He mentions three Password Keepers:  Roboform, Passwordsafe, & Keepass.

Keepass is the only one of those three I know a bit about, have a computer nerd friend that has used that for years.

It is good and free.

I am trying to provide a good selection of quality Password Keepers for people to chose from, not everyone's needs and wants are the same.

I prefer mSecure, partly because it has stronger encryption than many others, but it is also one of the most expensive consumer options.

Lot of my gamer friends though don't want to, or can't afford, to spend much on computer software.

Something to remember when using Password Keepers, is that you want to have that Data backed up VERY well.

You can use Dropbox or similar cloud storage, but you can also use Password Keepers on multiple devices (ie Smartphone, Tablet, & PC) I also like using a quality Flashdrive with hardware encryption.

I also like using written backup stored securely, I have physical items I have to keep secure, so I have ready storage for that.

I have written about Passwords & Password Keepers before, I specifically recommend reading Steve Gibson's Haystacks & Needles (Understanding Passwords) and "Lessons Learned from Cracking 2 Million LinkedIn Passwords."

For more posts click one of the these Labels:


Those Labels and more can be found at bottom left of Blog post, selected Labels can be found in Label Cloud at left side of blog, space limitations there, but I open to feedback for labels that should be added or removed from the Label Cloud.

Stay Safe,

Cliff



Friday, October 26, 2012

Security & Hacking: How to Crack WPA & WPA2

Good, though somewhat technical, article on cracking WiFi http://www.smallnetbuilder.com/wireless/wireless-howto/31914-how-to-crack-wpa-wpa2-2012

Though not mentioned in that article, related to strong passwords, I really think everyone should be using a good password keeper.

So the only password you need to remember is the one needed to unlock your password keeper, I would use Steve Gibson's advice for that password, blogged about here http://cliffsesportcorner.blogspot.com/2012/05/steve-gibsons-haystacks-needles.html

Then use random passwords, generated by the password keeper, for everything else.

There are many good password keepers out there, I like and recommend mSecure https://msevensoftware.com/

For free I believe Strip Lite is good, their website http://getstrip.com/ or iTunes.

Another free one I might suggest is KeePass, I have heard good things about it, and have a friend that uses it.


See Also:

Tuesday, August 28, 2012

Security & Hacking: "How I cracked my neighbor's WiFi password without breaking a sweat"

http://arstechnica.com/security/2012/08/wireless-password-easily-cracked/

Very good article, though written for average person, there is higher level information available in many of the Comments, it clearly shows how easy it is to hack many things average people think are secure.

Also, since the author of that Ars article was using online software services (ie software that ran on servers, not on author's computer) he didn't need much of a computer to do this.

For those new to Pen Testing and Password Strength (Security?) he was basically using a dictionary of words and common passwords.

The term "Dictionary" sometimes throws people, they don't mean Websters or OED, rather it is a list based on previously cracked passwords.

Millions of cracked passwords, so current Hacker's Dictionaries tend to be pretty representative of any password that a person picks out!

If you can remember it, it is a very bad password, you should be using some tiype of password keeper, and using the generate random password feature that all the good password keepers offer.

I plan to do a post in the near future on Password Keepers, but there are a lot of choices out there, many are free.

For similar Blog Posts, click on one of these labels:  Security, Hacking, Password Cracking, or Pen Testing.

Selected Labels can be found in label cloud at left side of blog, and every blog post has labels at bottom left of post.

Specific posts on Cliff's Esport Corner (aka Cliffs_esports_corner in some chat rooms) can be found best by using Google with query term and Cliff's Esport Corner in your Google search.