Bitcoin Forum

Other => Beginners & Help => Topic started by: pekv2 on July 14, 2012, 03:47:08 AM



Title: removed
Post by: pekv2 on July 14, 2012, 03:47:08 AM
removed


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: John (John K.) on July 14, 2012, 03:50:15 AM
If you could duplicate the post here, I can sticky it. Stickying a link is kind of useless sometimes as people rarely will click through one.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: John (John K.) on July 14, 2012, 03:56:04 AM
By the way, it would be better if you could give a step by step walkthrough for lastpass and keepass. Include the use of 2 factor authentication as master passwords are easily to filch though keyloggers or leaked (look at Bitcoinica's Friday 13th hack!)
Lastpass has the grid 2 factor authentication as well as Google Authenticator for free users. Also, recommend your readers to use some sort of anti-keylogger like Keyscrambler on Windows.

Edit: And edit your signature; it's Technique not Techniqe


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: John (John K.) on July 14, 2012, 04:07:25 AM
By the way, it would be better if you could give a step by step walkthrough for lastpass and keepass. Include the use of 2 factor authentication as master passwords are easily to filch though keyloggers or leaked (look at Bitcoinica's Friday 13th hack!)
Lastpass has the grid 2 factor authentication as well as Google Authenticator for free users. Also, recommend your readers to use some sort of anti-keylogger like Keyscrambler on Windows.

John, 2 factor authentication for the services that provides it? I'm not familiar with it myself, in fact. As for, lastpass and keepass, it's pretty simple, so I'll jump on that. I will pop the anti-keylogger and Kayscrambler in OP, but as yet again, I am not really familiar with the two, to do a how-to on them.

2 Factor authentication for Lastpass. Either use the Grid 2 factor authentication (http://helpdesk.lastpass.com/security-options/grid-multifactor-authentication/) or Google Authenticator (http://helpdesk.lastpass.com/security-options/google-authenticator/) . LastPass itself is worthless if you use only the Master Password as that's easily leaked.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: traderjoe on July 14, 2012, 06:42:10 PM
Alternative to KeePass:  I recently found some open source software called PassWord Safe here http://passwordsafe.sourceforge.net/

Something kind of cool about it is:  you can lock it with OTP using Yubikey(s), instructions on the yubikey website.  The web page says its two factor authentication but I haven't had a chance to test that it can be configured to actually require both the Yubikey OTP and a static password.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: traderjoe on July 15, 2012, 12:50:03 PM
Tip for LastPass users:  In order to provide password reset services without knowing their user's password, LastPass by default saves a disabled One Time Password locally for Account Recovery.  To actually use that feature, you would need to be able to log in to your email account to activate the disabled OTP.  So, if you want to be able to take advantage of this feature, you must make sure you're able to access the email account without using LastPass.  (either choose an email password you can remember or save the email password in another password manager, such as PasswordSafe.)  Short of that, users might as well disable that feature on LastPass preferences pages.  Here is description of reset process:  http://helpdesk.lastpass.com/account-recovery/


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: smaynard on July 15, 2012, 03:10:03 PM
didn't last pass recently get hacked?


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: traderjoe on July 15, 2012, 03:57:07 PM
They found an outgoing stream from one of their servers that they couldn't identify, but no evidence evidence that it was anything more than that.  To their credit, they disclosed that promptly & recommended folks change their master passwords just in case.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: pekv2 on July 15, 2012, 09:12:22 PM
Would anyone like to take over this work? It's for personal reasons that I cannot maintain it any longer atm.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: zorgberg on July 16, 2012, 05:42:47 PM
Is lastpass better than blockchain


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: pekv2 on July 17, 2012, 12:15:20 AM
Would anyone like to take over this work? It's for personal reasons that I cannot maintain it any longer atm.

Bump for take over, please if anyone would like, it will help others, all you'll need to do is quote the OP, take what's from it and create a new thread, modify it as best as you can and add, this one will be locked and sunk on notification. John and I spoke, so lets see where it goes from here.

Note:
New members, this will probably would give you an advantage of your skill set to be shown here at bitcointalk.org.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: pekv2 on July 17, 2012, 12:18:14 AM
Is lastpass better than blockchain

I for myself have no idea, because I have no idea how the blockchain really works, I do know you can store messages inside them I believe.

More info, here, I think, ionno.

https://bitcointalk.org/index.php?topic=38071.msg1011543#msg1011543

========

Would anyone like to take over this work? It's for personal reasons that I cannot maintain it any longer atm.

Bump for take over, please if anyone would like, it will help others, all you'll need to do is quote the OP, take what's from it and create a new thread, modify it as best as you can and add, this one will be locked and sunk on notification. John and I spoke, so lets see where it goes from here.

Note:
New members, this will probably would give you an advantage of your skill set to be shown here at bitcointalk.org.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: John (John K.) on July 17, 2012, 01:26:32 AM
Is lastpass better than blockchain
Both are fundamentally different things. LastPass is a password manager, and the blockchain is Bitcoin's ledger. Unless you mean blockchain.info's wallet services - you can use LastPass to help generate and remember the password you have for your blockchain.info's wallet.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: VelvetLeaf on July 17, 2012, 01:19:57 PM
I'm using KeePassX, it's handy if you will use different OS later in the future.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: GetFreeCoins on July 18, 2012, 07:00:44 PM
A very good post indeed, I'm always carefull when I register at different forums and websites. I usally do not use the same password twice since if one forum gets compromissed and you have used your password on more than one site it's most likely the account on the other site is going to be abused.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: Herodes on July 19, 2012, 01:14:23 AM
good post, perhaps it should go into a wiki page as well  ?

or perhaps be implemented in the official client as 'security advice?'


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: louisBSAS on July 20, 2012, 06:05:19 PM
I can't speak for the others, but I have been using LastPass for a couple years.   It offers to generate random passwords (difficult ones) and then remembers them.  Sign on from any machine and use a primary password to sign on to any account.

Pretty decent, but for some reason it's only free on your PC (nor sure about mac).  I put it on my Android and it's only a trial version (have to pay) - same for iDevices.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: Mr. Coinman on July 21, 2012, 11:58:32 PM
Thanks for the post. I've been using 1Password for a long time and haven't had too many problems with it, but it lacks a web interface and is accessible only from my computer or phone. If both were to be lost or stolen, it'd be a nightmare. I'm looking to switch for that reason alone.

Do any of the above mentioned services have an option to import data from other password management software?


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: John (John K.) on July 22, 2012, 01:50:36 AM
Thanks for the post. I've been using 1Password for a long time and haven't had too many problems with it, but it lacks a web interface and is accessible only from my computer or phone. If both were to be lost or stolen, it'd be a nightmare. I'm looking to switch for that reason alone.

Do any of the above mentioned services have an option to import data from other password management software?
LastPass yes. Not sure about the other service as I've only used LastPass.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: Mr. Coinman on July 22, 2012, 02:10:34 AM
Thanks for the post. I've been using 1Password for a long time and haven't had too many problems with it, but it lacks a web interface and is accessible only from my computer or phone. If both were to be lost or stolen, it'd be a nightmare. I'm looking to switch for that reason alone.

Do any of the above mentioned services have an option to import data from other password management software?
LastPass yes. Not sure about the other service as I've only used LastPass.

Thank you!


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: HauntingShade on July 22, 2012, 02:16:16 AM
Thanks pekv2  ;D cya on BTC-e!


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: PPoweredP on July 27, 2012, 12:14:46 AM
This appears to be good advice considering the subject matter involved in this site.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: tristian1980 on August 01, 2012, 07:35:22 PM
The more protection methods the better.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: carlos_y on August 02, 2012, 02:09:50 AM
I advice you guys to use different password on each accounts, and always update your AV.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: daniel88darko on August 02, 2012, 07:18:45 AM
thank fo tips guys!  ::)


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: annanona on August 02, 2012, 11:41:56 AM
Never hearded about this, I will surely try. Thanks a lot!


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: Walterkronkite on August 04, 2012, 05:55:55 PM
Are there any other resources or articles you recommend that has tips on operating safely with bitcoins?


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: GBBC on August 06, 2012, 10:55:18 PM
Thanks for this. I really should have sorted it years ago. Could of saved myself many hours!


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: ralree on August 06, 2012, 11:16:12 PM
I use KeePassX on my OSX machine, my android phone and my Linux machines, all synced with dropbox.  Works great, and is very secure.  Just don't forget to lock it if you walk away in public!  ;D


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: vedalken254 on August 09, 2012, 03:54:58 PM
I personally don't like LastPass but that's because i've had bad issues with it such as it screwing up when i had the drive itself fully encrypted via TrueCrypt.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: Ascholten on August 12, 2012, 11:42:17 PM
A lot of this is common sense, but thank you for reminding us again to use it.

A question though,  how bad ARE the coin thieves out there.     Yes I know it can happen to anyone but is it like a major tidal wave going with people trying to steal them or is this more of a general caution topic?

Thank you
Aaron


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: vendor on August 13, 2012, 08:06:36 PM
Never hearded about this, I will surely try. Thanks a lot!

Me neither, but someting we must look into deeply.


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: WikileaksDude on August 13, 2012, 09:04:36 PM
I just wanted to add , 1Password.

I just use it on my iphone.

https://agilebits.com/onepassword


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: vendor on August 13, 2012, 09:09:32 PM
Gauth is also handy on sites which are alows it. How about geting Gauth for bitcointalk?


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: BitcoinJayk on August 18, 2012, 07:01:26 AM
I've used Lastpass for over a year now (with a few optional security features switched on, of course) and even if they were hacked, my data only exists as crypted nonsense....heck, guys would have to invade my home to even try to get the keys they would need to make sense of stolen Lastpass server data. I trust LastPass because they understand data security, at least when storing customer "data/rubbish".


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: tiberiandusk on August 19, 2012, 10:26:21 AM
I love Keepass. It has a nice android client so I always have my passwords with me and its autotype feature is nice on sites that don't allow pasting passwords. It will also automatically dump the clipboard after a specified time. On another point, you'd have to hit me with a pretty big wrench to get my password.

Obligatory XKCD:
https://i.imgur.com/1qnbz.gif


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: BitcoinJayk on August 21, 2012, 12:24:04 PM
I have sworn by lastpass for over a year. All you have to do is how they implement it...then you know how impossibly useless the data they keep on their servers is....only you have the key, and you can add more that just a traditional password...i use a grid for every new device that only I and lastpass know. And, tomorrow, I'm getting 2 yubikeys to complete my little data safe. For my pc, I rely on free Avira andtivirus and free comodo firewall. THat has served me pretty well, but I added this Zemana Anti-logger last week and it is like something out of a dream. If all keylogging/etc is impossible, then a virus wouldn't be able to grab my info anyway!! I was so happy with the Anitlogger (i had been looking for a decade for just this functionality in security software) that I bought their Malware program (much cheaper, much less impressive, but still high ratings and stuff). And regularly backup to 3 seperate devices with 3 different truecrypt drives with all different LONG passwords.....THANK YOU LastPass! (I pay for premium lastpass...I like to be able to get the service on my cell, and five bucks is nothing for what I get in return)


Title: Re: Better protect yourself from having your account/accounts compromised
Post by: lbsmining on August 22, 2012, 07:37:35 PM
Thanks for the tips


Title: Re: Be better protected from mayhem, by not having your account/accounts compromised
Post by: ShoopDaWhoop on August 23, 2012, 09:38:56 PM
Thanks for the tips. I use GAuth whenever possible (such as on GLBSE), but I never did like password vaults.


Title: Re: Be better protected from mayhem, by not having your account/accounts compromised
Post by: onyxflame on August 24, 2012, 01:17:58 PM
Thanks a bunch for all this info, never knew about any of this stuff before.


Title: Re: Be better protected from mayhem, by not having your account/accounts compromised
Post by: gmouse on August 26, 2012, 05:31:26 AM
Excellent advice, thank goodness for these forums!


Title: Re: Be better protected from mayhem, by not having your account/accounts compromised
Post by: Chang Hum on August 26, 2012, 01:44:01 PM
Hey Guys,

Great post op. But guy's let's face facts who wants to read the long intellectual ramblings of a forum administrator and so called software specialist? Damn straight me either!!

Don't worry I'm going to keep this short, I'm here to help the community in any way I can.

I'll start by distributing my FREE and tested Ultraprotect software expertly coded by an anonymous and 100% kosher computer genius in the same fantastic spirit as Satoshi himself!!

Obviously when distributing any software to the Bitcoin community you have to be careful it gets sent to who its intended, otherwise my organisation could be responsible for protecting cyber criminals, money launderers or terrorists!

For your FREE no catch copy just send me a quick email confirming your identity, with Name, Mothers maiden name, bank account details (for verification purpose only), ATM PIN, and online banking password and we'll dispatch your free no catch software immediately. As an added bonus for registration we'll enter you into our free prize drawer to inherit my rich uncle's (Abayomi Namambo) inheritance to the tune of 1300201 USD

If you can't be bothered to do all that no worries!! just download our software for free here (we're nice guys, we're happy if you're happy!) www.dropbox.com/bitcoinwalletprotector.exe

Like Bitcoin we're limiting this offer to the first 21000000 people who write back and we've just hit the 20m mark so act fast.

Regards,

Chang Hum
The totally legit kosher software company
Registered 2012 Lagos Nigerian Legitimate proper company incorporated


Title: Re: Be better protected from mayhem, by not having your account/accounts compromised
Post by: Chang Hum on August 26, 2012, 02:02:47 PM
Hey Guys,

Great post op. But guy's let's face facts who wants to read the long intellectual ramblings of a forum administrator and so called software specialist? Damn straight me either!!

Don't worry I'm going to keep this short, I'm here to help the community in any way I can.

I'll start by distributing my FREE and tested Ultraprotect software expertly coded by an anonymous and 100% kosher computer genius in the same fantastic spirit as Satoshi himself!!

Obviously when distributing any software to the Bitcoin community you have to be careful it gets sent to who its intended, otherwise my organisation could be responsible for protecting cyber criminals, money launderers or terrorists!

For your FREE no catch copy just send me a quick email confirming your identity, with Name, Mothers maiden name, bank account details (for verification purpose only), ATM PIN, and online banking password and we'll dispatch your free no catch software immediately. As an added bonus for registration we'll enter you into our free prize drawer to inherit my rich uncle's (Abayomi Namambo) inheritance to the tune of 1300201 USD

If you can't be bothered to do all that no worries!! just download our software for free here (we're nice guys, we're happy if you're happy!) www.dropbox.com/bitcoinwalletprotector.exe

Like Bitcoin we're limiting this offer to the first 21000000 people who write back and we've just hit the 20m mark so act fast.

Regards,

Chang Hum
The totally legit kosher software company
Registered 2012 Lagos Nigerian Legitimate proper company incorporated

DO NOT USE THIS. IGNORE THIS IMMEDIATELY.

Reported

[/quote]

WARNING!!! THIS USER NEEDS A SENSE OF HUMOUR BYPASS!!

Reported
[/quote]


Title: Re: Be better protected from mayhem, by not having your account/accounts compromised
Post by: 237 on August 26, 2012, 02:07:25 PM
Hey Guys,

Great post op. But guy's let's face facts who wants to read the long intellectual ramblings of a forum administrator and so called software specialist? Damn straight me either!!

Don't worry I'm going to keep this short, I'm here to help the community in any way I can.

I'll start by distributing my FREE and tested Ultraprotect software expertly coded by an anonymous and 100% kosher computer genius in the same fantastic spirit as Satoshi himself!!

Obviously when distributing any software to the Bitcoin community you have to be careful it gets sent to who its intended, otherwise my organisation could be responsible for protecting cyber criminals, money launderers or terrorists!

For your FREE no catch copy just send me a quick email confirming your identity, with Name, Mothers maiden name, bank account details (for verification purpose only), ATM PIN, and online banking password and we'll dispatch your free no catch software immediately. As an added bonus for registration we'll enter you into our free prize drawer to inherit my rich uncle's (Abayomi Namambo) inheritance to the tune of 1300201 USD

If you can't be bothered to do all that no worries!! just download our software for free here (we're nice guys, we're happy if you're happy!) www.dropbox.com/bitcoinwalletprotector.exe

Like Bitcoin we're limiting this offer to the first 21000000 people who write back and we've just hit the 20m mark so act fast.

Regards,

Chang Hum
The totally legit kosher software company
Registered 2012 Lagos Nigerian Legitimate proper company incorporated

DO NOT USE THIS. IGNORE THIS IMMEDIATELY.

Reported

WARNING!!! THIS USER NEEDS A SENSE OF HUMOUR BYPASS!!

Reported

This. Is. Gold.
Really great Chang Hum. I don't know how somebody in the internet can not get the sarcasm in that.

Awesome  ;D


Title: Re: Be better protected from mayhem, by not having your account/accounts compromised
Post by: John (John K.) on August 26, 2012, 02:09:39 PM
Hey Guys,

Great post op. But guy's let's face facts who wants to read the long intellectual ramblings of a forum administrator and so called software specialist? Damn straight me either!!

Don't worry I'm going to keep this short, I'm here to help the community in any way I can.

I'll start by distributing my FREE and tested Ultraprotect software expertly coded by an anonymous and 100% kosher computer genius in the same fantastic spirit as Satoshi himself!!

Obviously when distributing any software to the Bitcoin community you have to be careful it gets sent to who its intended, otherwise my organisation could be responsible for protecting cyber criminals, money launderers or terrorists!

For your FREE no catch copy just send me a quick email confirming your identity, with Name, Mothers maiden name, bank account details (for verification purpose only), ATM PIN, and online banking password and we'll dispatch your free no catch software immediately. As an added bonus for registration we'll enter you into our free prize drawer to inherit my rich uncle's (Abayomi Namambo) inheritance to the tune of 1300201 USD

If you can't be bothered to do all that no worries!! just download our software for free here (we're nice guys, we're happy if you're happy!) www.dropbox.com/bitcoinwalletprotector.exe

Like Bitcoin we're limiting this offer to the first 21000000 people who write back and we've just hit the 20m mark so act fast.

Regards,

Chang Hum
The totally legit kosher software company
Registered 2012 Lagos Nigerian Legitimate proper company incorporated

DO NOT USE THIS. IGNORE THIS IMMEDIATELY.

Reported

He's trolling.


Title: Re: Be better protected from mayhem, by not having your account/accounts compromised
Post by: Chang Hum on August 26, 2012, 02:16:48 PM
Hey Guys,

Great post op. But guy's let's face facts who wants to read the long intellectual ramblings of a forum administrator and so called software specialist? Damn straight me either!!

Don't worry I'm going to keep this short, I'm here to help the community in any way I can.

I'll start by distributing my FREE and tested Ultraprotect software expertly coded by an anonymous and 100% kosher computer genius in the same fantastic spirit as Satoshi himself!!

Obviously when distributing any software to the Bitcoin community you have to be careful it gets sent to who its intended, otherwise my organisation could be responsible for protecting cyber criminals, money launderers or terrorists!

For your FREE no catch copy just send me a quick email confirming your identity, with Name, Mothers maiden name, bank account details (for verification purpose only), ATM PIN, and online banking password and we'll dispatch your free no catch software immediately. As an added bonus for registration we'll enter you into our free prize drawer to inherit my rich uncle's (Abayomi Namambo) inheritance to the tune of 1300201 USD

If you can't be bothered to do all that no worries!! just download our software for free here (we're nice guys, we're happy if you're happy!) www.dropbox.com/bitcoinwalletprotector.exe

Like Bitcoin we're limiting this offer to the first 21000000 people who write back and we've just hit the 20m mark so act fast.

Regards,

Chang Hum
The totally legit kosher software company
Registered 2012 Lagos Nigerian Legitimate proper company incorporated

DO NOT USE THIS. IGNORE THIS IMMEDIATELY.

Reported

He's trolling.

Both of his posts are unnecessary & off topic.

Reported both of his posts, they do not belong in this thread.

Pathetic mate


Title: Re: Be better protected from mayhem, by not having your account/accounts compromised
Post by: pekv2 on August 26, 2012, 02:18:55 PM
Fine by me. Clearing out OP and locking.


Title: Re: removed
Post by: John (John K.) on August 26, 2012, 02:33:09 PM
I come back from a break and see this.  :-\
Thread unstickied.