ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Miscellaneous Tech News

    Scheduled Pinned Locked Moved News
    7.4k Posts 83 Posters 3.8m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender @DustinB3403
      last edited by

      @DustinB3403 said in Miscellaneous Tech News:

      New Windows 10 build silences Cortana, brings passwordless accounts

      The latest Insider build of Windows 10, 18309, expands the use of a thing that Microsoft has recently introduced: passwordless Microsoft accounts. It's now possible to create a Microsoft account that uses a one-time code delivered over SMS as its primary authenticator, rather than a conventional password.

      yeah - now it's evey easier to hack people.

      And apparently the NIST has been bought off to reduce their stance on SMS 2FA
      https://blog.vasco.com/authentication/sms-authentication/

      DustinB3403D 1 Reply Last reply Reply Quote 0
      • DustinB3403D
        DustinB3403 @Dashrender
        last edited by

        @Dashrender no one said it was a stepped improvement. They also have biometrics (face, fingerprint) as well as pin options.

        They are working to remove the password complexity requirement and put something else in place of it.

        password_strength.png

        1 Reply Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403
          last edited by

          Which ideally if they could come up with a Correct Horse Shoe Battery Staple algorithm and generate random passwords based on dictionary words they likely would be better off.

          But how can one trust that the computer and ISO isn't compromised at installation time or to make sure that algorithm hasn't been cracked. . .

          JaredBuschJ 1 Reply Last reply Reply Quote 0
          • JaredBuschJ
            JaredBusch @DustinB3403
            last edited by

            @DustinB3403 said in Miscellaneous Tech News:

            Which ideally if they could come up with a Correct Horse Shoe Battery Staple algorithm and generate random passwords based on dictionary words they likely would be better off.

            But how can one trust that the computer and ISO isn't compromised at installation time or to make sure that algorithm hasn't been cracked. . .

            Secure boot and hash verification.

            DustinB3403D 1 Reply Last reply Reply Quote 0
            • DustinB3403D
              DustinB3403 @JaredBusch
              last edited by

              @JaredBusch said in Miscellaneous Tech News:

              @DustinB3403 said in Miscellaneous Tech News:

              Which ideally if they could come up with a Correct Horse Shoe Battery Staple algorithm and generate random passwords based on dictionary words they likely would be better off.

              But how can one trust that the computer and ISO isn't compromised at installation time or to make sure that algorithm hasn't been cracked. . .

              Secure boot and hash verification.

              That was my point, the solution already exists. But no one has implemented said algorithm in their systems.

              1 Reply Last reply Reply Quote 0
              • DashrenderD
                Dashrender
                last edited by

                People don't want to use generated passwords if they can avoid it.

                The push OTP is an awesome idea - my only criticism was they pushing to SMS, and not the app.

                DustinB3403D 1 Reply Last reply Reply Quote 1
                • DustinB3403D
                  DustinB3403 @Dashrender
                  last edited by

                  @Dashrender said in Miscellaneous Tech News:

                  People don't want to use generated passwords if they can avoid it.

                  The push OTP is an awesome idea - my only criticism was they pushing to SMS, and not the app.

                  Well the issue is that a password generated by a person generally just sucks. If the process of passwords were to be changed, one such option would be to use randomly generated passwords like CHSBS.

                  DashrenderD 1 Reply Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @DustinB3403
                    last edited by

                    @DustinB3403 said in Miscellaneous Tech News:

                    @Dashrender said in Miscellaneous Tech News:

                    People don't want to use generated passwords if they can avoid it.

                    The push OTP is an awesome idea - my only criticism was they pushing to SMS, and not the app.

                    Well the issue is that a password generated by a person generally just sucks. If the process of passwords were to be changed, one such option would be to use randomly generated passwords like CHSBS.

                    That's great - I suppose you could force people to use the passwords that systems make for them - not allowing them to change them to something that the user themself's want. That just means they'll write it down and potentially write it directly on the computer - I guess the hackers can't read it at least. 😛

                    DustinB3403D 1 Reply Last reply Reply Quote 0
                    • DustinB3403D
                      DustinB3403 @Dashrender
                      last edited by

                      @Dashrender and to that same point, how many times has a user changed their password only to forget it and need it changed again. Or write it down when they change it and have arbitrary requirements like in the CHSBS example?

                      DashrenderD 1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @DustinB3403
                        last edited by

                        @DustinB3403 said in Miscellaneous Tech News:

                        @Dashrender and to that same point, how many times has a user changed their password only to forget it and need it changed again. Or write it down when they change it and have arbitrary requirements like in the CHSBS example?

                        I'm all for getting rid of passwords - just don't use SMS as a part of the fix.

                        ObsolesceO 1 Reply Last reply Reply Quote 0
                        • ObsolesceO
                          Obsolesce @Dashrender
                          last edited by

                          @Dashrender said in Miscellaneous Tech News:

                          @DustinB3403 said in Miscellaneous Tech News:

                          @Dashrender and to that same point, how many times has a user changed their password only to forget it and need it changed again. Or write it down when they change it and have arbitrary requirements like in the CHSBS example?

                          I'm all for getting rid of passwords - just don't use SMS as a part of the fix.

                          I like using Chrome's built-in password manager and generator. So long as you can use Chrome, you don't need to know the password. If you need to know it, you can always go in and check.

                          1 Reply Last reply Reply Quote 0
                          • DonahueD
                            Donahue
                            last edited by

                            I use lastpass for almost everything. It's nice for things like websites, but it would be a pain for things like computer logins.

                            DashrenderD DustinB3403D 2 Replies Last reply Reply Quote 0
                            • DashrenderD
                              Dashrender @Donahue
                              last edited by

                              @Donahue said in Miscellaneous Tech News:

                              I use lastpass for almost everything. It's nice for things like websites, but it would be a pain for things like computer logins.

                              As far as I know, nothing works for computers logins - at least regarding an automated way to enter the information.

                              Pulling the info out of Lastpass is generally easy enough though - I get it on my phone when I'm not at my own computer.

                              B 1 Reply Last reply Reply Quote 0
                              • DustinB3403D
                                DustinB3403 @Donahue
                                last edited by

                                @Donahue said in Miscellaneous Tech News:

                                I use lastpass for almost everything. It's nice for things like websites, but it would be a pain for things like computer logins.

                                I use KeePass for personal stuff and LastPass at work. For work, it's fine and has functionality which is great for work. But personally I couldn't use it as it's solely accessible from a browser.

                                KeePass I can access from my phone, desktop, laptop tablet and pretty much everything else.

                                DashrenderD 1 Reply Last reply Reply Quote 1
                                • DashrenderD
                                  Dashrender @DustinB3403
                                  last edited by

                                  @DustinB3403 said in Miscellaneous Tech News:

                                  @Donahue said in Miscellaneous Tech News:

                                  I use lastpass for almost everything. It's nice for things like websites, but it would be a pain for things like computer logins.

                                  I use KeePass for personal stuff and LastPass at work. For work, it's fine and has functionality which is great for work. But personally I couldn't use it as it's solely accessible from a browser.

                                  KeePass I can access from my phone, desktop, laptop tablet and pretty much everything else.

                                  I use Lastpass from my phone - there's an app.

                                  Assuming you're in a GUI on your desktop - what do you care if you're using the browser or a native app?

                                  DustinB3403D 1 Reply Last reply Reply Quote 0
                                  • DustinB3403D
                                    DustinB3403 @Dashrender
                                    last edited by

                                    @Dashrender said in Miscellaneous Tech News:

                                    @DustinB3403 said in Miscellaneous Tech News:

                                    @Donahue said in Miscellaneous Tech News:

                                    I use lastpass for almost everything. It's nice for things like websites, but it would be a pain for things like computer logins.

                                    I use KeePass for personal stuff and LastPass at work. For work, it's fine and has functionality which is great for work. But personally I couldn't use it as it's solely accessible from a browser.

                                    KeePass I can access from my phone, desktop, laptop tablet and pretty much everything else.

                                    I use Lastpass from my phone - there's an app.

                                    Assuming you're in a GUI on your desktop - what do you care if you're using the browser or a native app?

                                    Just functionality wise it feels like it's lacking.

                                    1 Reply Last reply Reply Quote 0
                                    • DonahueD
                                      Donahue
                                      last edited by

                                      I also use the lastpass app on my phone, I can use my fingerprint to open it so I dont have to type in my super long master password.

                                      1 Reply Last reply Reply Quote 0
                                      • B
                                        bnrstnr @Dashrender
                                        last edited by

                                        @Dashrender said in Miscellaneous Tech News:

                                        As far as I know, nothing works for computers logins - at least regarding an automated way to enter the information.

                                        I believe automated logins are becoming more popular with the Windows Hello feature. I think Yubikey's can log you into Windows now.

                                        Have Yubikey's ever come up here? I don't recall reading much about them.

                                        1 Reply Last reply Reply Quote 0
                                        • mlnewsM
                                          mlnews
                                          last edited by

                                          Samsung sticks Nvidia RTX 2080 GPU inside new Odyssey gaming notebook

                                          Yet another competitor for Acer, Alienware, Razer, and others to watch.

                                          Samsung is making news at CES 2019—but not for an obvious reason. The Korean manufacturer announced its first new gaming laptop in quite some time: the Samsung Notebook Odyssey. While Samsung has made gaming devices with the Odyssey name, this new notebook appears to compete with similarly powerful and portable gaming PCs from the likes of Acer, Alienware, and Razer.

                                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @mlnews
                                            last edited by

                                            @mlnews wow, that's a nice card!

                                            1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 5
                                            • 6
                                            • 7
                                            • 8
                                            • 9
                                            • 372
                                            • 373
                                            • 7 / 373
                                            • First post
                                              Last post