Bitcoin Forum

Other => Beginners & Help => Topic started by: escrow.ms on March 27, 2013, 09:44:05 AM



Title: Stay safe.
Post by: escrow.ms on March 27, 2013, 09:44:05 AM
I am making this thread for ones to protect themselves from being compromised. You may add this to your sig to spread the knowledge for ones to protect themselves from being compromised.

============================================================================================

Note: A) Lastpass is freeware, but for some stuff you can pay, but the general use of lastpass is freeware. LastPass Password Manager is closed source, though many of the extensions can be run in a non-binary mode where the source is available, but LastPass maintains all rights.
Note: B) Keepass is freeware. KeePass is an open source password manager.
Note: C) Password Safe is freeware & opensource. (Courtesy of traderjoe)

A) https://lastpass.com/
B) http://keepass.info/
C) http://passwordsafe.sourceforge.net/

============================================================================================

Create an account with lastpass, use a strong master password. Don't ever forget your master password, as you are the only one that has it.

You may download Lastpass as an Application or as a browser addon for, Firefox, Chrome, IE, etc.

Lastpass application. Download, install, input email that you used to register with lastpass and the master password you created. Get familiar with the program.

Lastpass addons. Install the Lastpass addon that is appropriate for your browser. Once done, you see a Lastpass icon somewhere in one of your toolbars of your browser, input the email you used to register with Lastpass, into the Email section of the login area then following by your master password that you created.


============================================================================================

Keepass, is all saved encrypted with one master password on your pc. No cloud servers or nothing. If you use keepass, backup your file in a truecrypt container file on a cloud server like dropbox or as wuala encrypts data on your pc before it gets sent to wuala servers.

Here is a How-to for Keepass. http://keepass.info/help/base/firststeps.html

============================================================================================

Quote

(Courtesy of traderjoe) About Password Safe & Yubikey(s)

Something kind of cool about Password Safe is:  you can lock it with OTP using Yubikey(s), instructions on the yubikey website.  The web page says its two factor authentication but I haven't had a chance to test that it can be configured to actually require both the Yubikey OTP and a static password.


============================================================================================

I recommend to use a strong Master Password and never use the same password for 2 or more accounts. Never give out your master password. Never use words from a dictionary.

Lastpass encrypts all your data on your pc or mobile device before lastpast sends off it off to their servers and you only hold the key "master password" to all your saved passwords, notes and etc. I find this addon - application the best imo.

Quote
(Courtesy of RandmomQ)
Do not use a Password Generator that is hosted Online unless it uses SSL this may be OK for a normal user.
Do not repeat chars IE "AAA" "BBB" "111"
Use a Special Char if allowed "!@#$%%$^^*&()"
Never use the same password twice
Change password regularly

Additional Notes:
With the latest LastPass as of the moment 3.1.0, and you have a system strong computer system you may up the PW iterations. Raise in increments of 100 or 1000. Anything high might be bad for mobile devices or slow computers. I set mine at 200000 Not recommended if you do not know what you're doing..
https://helpdesk.lastpass.com/security-options/password-iterations-pbkdf2/

============================================================================================

Quote
(Courtesy of RandomQ)

lastpass also supports google auth so you even if you master password is stolen via keylogger, they most likely won't  get all your passwords because google auth codes are only good for ~30 secs.
Lastpass Introduced Support for Google Authenticator for Mobile Devices (http://blog.lastpass.com/2011/11/introducing-support-for-google.html)

Quote
Courtesy of (John (johnthedong))

LastPass itself is worthless if you use only the Master Password as that's easily leaked.


Setting Up LastPass with Google Authenticator (http://helpdesk.lastpass.com/security-options/google-authenticator/)

Grid Multifactor Authentication (http://helpdesk.lastpass.com/security-options/grid-multifactor-authentication/)

============================================================================================

Quote
Note: KeyScrambler is not freeware.
Note: Anti-Keylogger is trial-freeware and pay for.

KeyScrambler (http://www.qfxsoftware.com/)
Anti-Keylogger (http://www.anti-keyloggers.com/)

Courtesy of (John (johnthedong))

Use an Anti-Keylogger like Keyscrambler.


============================================================================================

Explanation of PGP Encryption

Courtesy of CypherPunk

Quote from: CypherPunk
PGP is strong encryption software. Think military grade encryption. It allows you to encrypt emails and files in such a way that they are theorhetically unbreakable. It uses the concept of a private and a public key. You give your public key to everyone so they can encrypt stuff to you but whatever is encrypted to you can only be decrypted by your private key (which you protect with a passphrase and your freaking life!)

There is an open source version of PGP canned GnuPG (or GPG for short). It functions the same as PGP and can even read PGP generated files (and vice versa).

Advice: if you are serious about security, do not use ANY program that relates to security and is not open source. You simply can't know what it's doing and it may compromise your security.

HTH,
CypherPunk


pgp tutorial for newbies gpg4win (http://www.deepdotweb.com/2013/11/11/pgp-tutorial-for-newbs-gpg4win/)


By GoldenWings91

Proper way to Create & verify GPG Signature using Kleopatra on Windows (https://bitcointalk.org/index.php?topic=297434.msg3202050#msg3202050)

============================================================================================


============================================================================================
Android Security

TIP #1 Don't store bitcoins on a rooted cellphone.
Rooting your device increases the security exposure to malicious applications and potential application flaws, thus any malware can steal your wallet/keys stored in a protected directory.
Malware on a rooted phone can also access other applications like google authenticator and read/write phone logs,sms etc which are needed for verification process in many websites/apps.

TIP #2 – Don’t install apps from untrusted third party apps stores.
TIP #3 – Use an anti-virus app for an extra layer of protection.

APK scanners:
http://apkscan.nviso.be/
http://mobilesandbox.org/
http://virustotal.com/
http://scan.netqin.com/en/
https://anubis.iseclab.org/

============================================================================================

These are technique everyone should exercise.

============================================================================================

Here are a few examples why one should use these techniques.

https://bitcointalk.org/index.php?topic=92471.msg1020087#msg1020087
https://bitcointalk.org/index.php?topic=91701.msg1009976#msg1009976

============================================================================================

Block unencrypted content on encrypted sites with Firefox or a browser equivalent to Firefox.

With the latest Firefox ESR or latest release of firefox, you may block mixed content at about:config. I don't know about earlier versions of FF.

Code:
security.mixed_content.block_display_content : true
security.mixed_content.block_active_content : true

Also two addons add two buttons to easily disable or enable these settings.
https://addons.mozilla.org/en-US/firefox/addon/toggle-mixed-active-content/
https://addons.mozilla.org/en-US/firefox/addon/toggle-mixed-display-content/

Block unencrypted content on encrypted sites with adblockplus.

Steps to produce:

Step 1:  -- Click on AblockPlus icon, Click filter preferences.
Step 2:  -- Click Custom Filters Tab.
Step 3:  -- Click add filter group., name it Blocking HTTP Content on HTTPS Enabled Sites
Step 4:  -- Click Add Filter.
Step 5:  -- Add for example, for bitcointalk.org, add
Code:
|http://*$domain=bitcointalk.org
Step 6:  -- For other sites that use https, like google.com, add
Code:
|http://*$domain=google.com

Note: Just replace the domain name with the one you prefer. E.G. |http://*$domain=example.com

To force HTTP to HTTPS.

Step 1: Install Noscript addon.
Step 2: Click Noscript icon, click options, click advance tab, under advance tab is https tab, click https tab, under https tab is a behavior tab, click it.
Step 3: Drop the menu down to
Code:
 Forbid active web content unless it becomes from a secure (HTTPS) connections
to Never.
Step 4: Add the domain name you prefer to
Code:
 Force the following sites to use secure (HTTPS) connections
Window.
Note: Example: google.com youtube.com www.youtube.com

============================================================================================

Block bad stuff with Hosts file by MVPS

Quote
Also, I would and no doubt this has saved me from a lot of bad stuff, recommend MVPS hosts file.

You can use this on linux, rooted phones and Windows, and probably other stuff that use hosts file.

http://winhelp2002.mvps.org/hosts.htm

mvps now supplies the hosts file with 0.0.0.0's. Below no longer needed. Scratched out.
If you get notepad++, you can ctrl-f 127.0.0.1, click replace all with 0.0.0.0 .

Example.
Code:
127.0.0.1  fr.a2dfp.net > 0.0.0.0  fr.a2dfp.net

By doing this, you save a lot of space.

And you leave
Code:
127.0.0.1  localhost
alone.

============================================================================================

By Tomatocage

[EDU] How to spot a scammer (Read this before doing any transactions!) (https://bitcointalk.org/index.php?topic=137288.0)

============================================================================================

By escrow.ms

Clickable link - Keep your system updated and stay secure. Tips to avoid viruses trojans (https://bitcointalk.org/index.php?topic=203876.0)

============================================================================================

Avoid Link-Scammers

Avoid Link-Scammers (https://bitcointalk.org/index.php?topic=336505.msg3692526#msg3692526)

============================================================================================

An option too up your google account security.

The security question for google, allows you to change it to a custom question.
I took with my lastpass addon and generated a character password with Show advance options ticked, everything ticked to make your password the strongest. Copy generated password, paste as security question.

Go back to generate a new password and generate a new password with highest strength possible, copy and paste for the answer.
Save/update google settings.

Open a secure note for lastpass and keep these two generated password stored under its title question/answer, which is protected by your masterpassword for lastpass.

It's just a blockade against a security question attack on your google account or any other account that has this security question feature.


============================================================================================

As always, comments and suggestions are always welcomed to better these techniques as I will do my best to fill them.

If you have enough character count in your signature please represent this in your signature.
Code:
[url=https://bitcointalk.org/index.php?topic=159424.msg1685280#msg1685280][size=8pt]Stay Safe.[/size][/url]

============================================================================================


Title: Re: Stay safe.
Post by: crazyfingers on March 27, 2013, 10:35:01 AM
Thank you for all the information. I will put it to use.

BTW, can you give a simple explanation of what PGP is and how to use it? And do you have any recommendations for related freeware? Thanks.


Title: Re: Stay safe.
Post by: MaraC on March 27, 2013, 12:36:07 PM
Great info thanks!!

I have so many passwords now, that it's insane!

Thanks!


Title: Re: Stay safe.
Post by: pekv2 on March 27, 2013, 02:28:14 PM
Thank you for all the information. I will put it to use.

BTW, can you give a simple explanation of what PGP is and how to use it? And do you have any recommendations for related freeware? Thanks.

I do not, I did at one time read up on pgp, my best guess is to check out the wikipedia. As to recommendations I have no idea.

Yup, np.

Great info thanks!!

I have so many passwords now, that it's insane!

Thanks!

Yup, np.



Title: Re: Stay safe.
Post by: CypherPunk on March 31, 2013, 01:19:53 AM
Thank you for all the information. I will put it to use.

BTW, can you give a simple explanation of what PGP is and how to use it? And do you have any recommendations for related freeware? Thanks.

PGP is strong encryption software. Think military grade encryption. It allows you to encrypt emails and files in such a way that they are theoretically unbreakable. It uses the concept of a private and a public key. You give your public key to everyone so they can encrypt stuff to you but whatever is encrypted to you can only be decrypted by your private key (which you protect with a passphrase and your freaking life!)

There is an open source version of PGP canned GnuPG (or GPG for short). It functions the same as PGP and can even read PGP generated files (and vice versa).

Related software you should look into is Keepass (open source, secure password storage), Tor (open source, anonymity software), TrueCrypt (open source, drive or file encryption).

Advice: if you are serious about security, do not use ANY program that relates to security and is not open source. You simply can't know what it's doing and it may compromise your security.

HTH,
CypherPunk


Title: Re: Stay safe.
Post by: pekv2 on March 31, 2013, 01:34:52 AM

OP updated, thanks!


Title: Re: Stay safe.
Post by: Exocyst on April 02, 2013, 05:11:23 PM
Are there any tools for command line?  I would love a MySQL database of my encrypted passwords, info with some kind of link to an encryption/decryption library like libmcrypt or gnupg.


Title: Re: Stay safe.
Post by: pekv2 on April 07, 2013, 12:16:37 AM
Keepass 2.22 was released on the 5th.


Title: Re: Stay safe.
Post by: Keimoasd on April 08, 2013, 12:01:42 PM
Thank you for this information!


Title: Re: Stay safe.
Post by: Riddar on April 08, 2013, 12:04:42 PM
Solid advice.


Title: Re: Stay safe.
Post by: tomnavratil on April 08, 2013, 12:19:02 PM
Regarding security and protection - hardware options are relatively a good choice as well. For example Yubikey, which can be linked to MtGox, which is still used by many. Affordable and acts as an extra layer of protection.


Title: Re: Stay safe.
Post by: pekv2 on April 11, 2013, 02:55:17 PM
I've updated the end of the OP:

Quote

Block unencrypted content on encrypted sites with adblockplus.

Steps to produce:

Step 1:  -- Click on AblockPlus icon, Click filter preferences.
Step 2:  -- Click Custom Filters Tab.
Step 3:  -- Click add filter group., name it Blocking HTTP Content on HTTPS Enabled Sites
Step 4:  -- Click Add Filter.
Step 5:  -- Add for example, for bitcointalk.org, add
Code:
|http://*$domain=bitcointalk.org
Step 6:  -- For other sites that use https, like google.com, add
Code:
|http://*$domain=google.com

Note: Just replace the domain name with the one you prefer. E.G. |http://*$domain=example.com

To force HTTP to HTTPS.

Step 1: Install Noscript addon.
Step 2: Click Noscript icon, click options, click advance tab, under advance tab is https tab, click https tab, under https tab is a behavior tab, click it.
Step 3: Drop the menu down to
Code:
 Forbid active web content unless it becomes from a secure (HTTPS) connections
to Never.
Step 4: Add the domain name you prefer to
Code:
 Force the following sites to use secure (HTTPS) connections
Window.
Note: Example: google.com youtube.com www.youtube.com


Title: Re: Stay safe.
Post by: proper_pizza on April 12, 2013, 10:49:43 PM
Please stay safe


Title: Re: Stay safe.
Post by: Gabi on April 12, 2013, 11:04:56 PM
About HTTPS this is the addon i use https://www.eff.org/https-everywhere

Of course you can have https only if the website support it  ;)


Title: Re: Stay safe.
Post by: ripple on April 12, 2013, 11:22:02 PM
Very helpful information. I think the fact that these programs are open source is a good guarantee that they are free of malware which is very important when it comes to password protection.


Title: Re: Stay safe.
Post by: Teg_men on April 15, 2013, 09:03:57 AM
Thank you for information.


Title: Re: Stay safe.
Post by: jt7382 on April 19, 2013, 07:48:32 PM
This is amazing. Bookmarked, thank you for it.


Title: Re: Stay safe.
Post by: myrkul on April 20, 2013, 07:07:12 PM
Sticky this thread NAO.

Too good to let get smothered in the Newbie sewage.


Title: Re: Stay safe.
Post by: digicoins on April 20, 2013, 07:16:38 PM
Better safe than sorry! May get a Yubikey, heard good things about it and widely used on exchanges


Title: Re: Stay safe.
Post by: GGuyZ on April 20, 2013, 07:35:52 PM
Great thread, thanks :).


Title: Re: Stay safe.
Post by: pekv2 on April 20, 2013, 07:55:24 PM
Sticky this thread NAO.

Too good to let get smothered in the Newbie sewage.

A like thread like this, well, exactly this info but not this thread was once stickied, until a goober pissed me off, I did something I should have not, I took it down, it got unstickied. Then some admins were against it being stickied i believe in the first place. But we can go forth and see if it may get stickied again, I use medication now that keeps me calm. This is the reason I never asked for it to be stickied again because I once lost my temper, and might have thought that had ruined me asking for it to be stickied again. We'll see how it goes and if it can get stickied again, if they be so kind.


Title: Re: Stay safe.
Post by: paoui on April 20, 2013, 07:57:13 PM
very helpful. THANKS. I was already using Keypass for a while but will take a look at ur other suggestions too


Title: Re: Stay safe.
Post by: bitcoinblueprint on April 22, 2013, 04:29:40 PM
Thank you pekv2, great tutorial! :)


Title: Re: Stay safe.
Post by: bitjay on April 24, 2013, 04:13:07 PM
Excellent advice.


Title: Re: Stay safe.
Post by: bitleif on April 25, 2013, 03:54:00 PM
Don't keep all your money in one place.


Title: Re: Stay safe.
Post by: madsurgeon on April 26, 2013, 03:48:53 PM
I would never trust a closed source password manager!


Title: Re: Stay safe.
Post by: pekv2 on April 26, 2013, 05:31:23 PM
I would never trust a closed source password manager!

Who is closed source?

Edit:
I see, lastpass is closed source in a certain way.

LastPass Password Manager is closed source, though many of the extensions can be run in a non-binary mode where the source is available, but LastPass maintains all rights.

https://en.wikipedia.org/wiki/LastPass_Password_Manager


Title: Re: Stay safe.
Post by: pekv2 on April 26, 2013, 05:36:16 PM
I would never trust a closed source password manager!

Who is closed source?

Edit:
I see, lastpass is closed source in a certain way.

LastPass Password Manager is closed source, though many of the extensions can be run in a non-binary mode where the source is available, but LastPass maintains all rights.

https://en.wikipedia.org/wiki/LastPass_Password_Manager

I've updated the OP with this information. I've also updated the OP of keepass is opensource.


Title: Re: Stay safe.
Post by: takeyourhatoff on April 29, 2013, 08:52:59 PM
I recommend https everywhere by eff. it does exactly what you think it does.


Title: Re: Stay safe.
Post by: J.Jade on April 29, 2013, 09:19:58 PM
Very helpful information.

Thank you for pointing me to these programs!


Title: Re: Stay safe.
Post by: pieomy on April 29, 2013, 09:34:46 PM
Those are some cool programs. Now which one to try? keepass or lastpass?


Title: Re: Stay safe.
Post by: miningdude on April 29, 2013, 10:54:09 PM
Going forward I see multi-factor authentication gaining traction for most online accounts (ie password + code sent via sms to phone, etc). This eliminates the very real threat of keystroke logging malware and other forms of authentication theft which lastpass et al is not immune to. The recent AP Twitter hack made the case for this and Twitter was very quick to add it as an option for authenticating their users. http://www.usatoday.com/story/tech/2013/04/23/ap-twitter-hack-was-trivial/2107427/


Title: Re: Stay safe.
Post by: Dpx008 on April 29, 2013, 11:04:03 PM
Wow, didn't know about these sites. Thanks!


Title: Re: Stay safe.
Post by: elux on April 29, 2013, 11:08:48 PM
Sticky this thread NAO.

http://cdn.memegenerator.net/instances/400x/28242260.jpg

PS: +1


Title: Re: Stay safe.
Post by: Newar on April 30, 2013, 02:56:29 PM
+1 for HTTPS everywhere https://www.eff.org/https-everywhere

Very interesting article on SSL "security": https://www.grc.com/fingerprints.htm


Title: Re: Stay safe.
Post by: nango on April 30, 2013, 03:42:11 PM
Thanks for the Keepass recommendation for the masses.

There is also Keepassx [1] w/ cross-platform support (ex: Linux, OSX) and it works quite nicely w/ minimal memory usage compared to Keepass2 & .Net. I use both in different scenarios - Keepass2 for by main accounts / etc where I typically access via powerful PC and Keepassx when I have to work on a not-so-powerful PC w/ more protected accounts.


1: https://www.keepassx.org


Title: Re: Stay safe.
Post by: cclambie on May 01, 2013, 05:08:30 AM
I have been using LastPass Premium for about 3 years now.
It is a stunning program, keeping my 400-500 passwords neat and secure.
I also love the fact that I can share a password with someone, and then rescind access.

Their latest additional security feature is great too, whenever you login to a site with a poor or duplicate password, they notify you via the browser plugin.
This I find very helpful in reminding me to update passwords on sites I don't access very often, making my life more secure every day.

Thanks for the post, keeps my eyes open to other options


Title: Re: Stay safe.
Post by: nii236 on May 10, 2013, 02:14:37 PM
I love Keepass! I just made the switch for everything into Keepass and its good not having to repeat passwords between websites!

All this Bitcoin stuff made me a lot more interested in cryptography. But it makes me think... how often do people get their CC and passwords stolen online? Its never happened to me or anyone I know.


Title: Re: Stay safe.
Post by: mehmet on May 10, 2013, 09:02:26 PM
excellent advice


Title: Re: Stay safe.
Post by: rudrigorc3 on May 10, 2013, 09:34:24 PM
great tutorial


Title: Re: Stay safe.
Post by: ZeRo108 on May 10, 2013, 09:49:57 PM
thanks


Title: Re: Stay safe.
Post by: slcbuyer on May 10, 2013, 10:15:39 PM
yes safe is good


Title: Re: Stay safe.
Post by: pekv2 on May 17, 2013, 04:08:05 PM
I suppose I can squish this in the topic. The hosts part. Also, Keep your system updated and stay secure. Tips to avoid viruses trojans (https://bitcointalk.org/index.php?topic=203876.0)

I would recommend Comodo free firewall, which comes with a sandbox and defense+.

Also, I would and no doubt this has saved me from a lot of bad stuff, recommend MVPS hosts file.

You can use this on linux, rooted phones and Windows, and probably other stuff that use hosts file.

http://winhelp2002.mvps.org/hosts.htm

If you get notepad++, you can ctrl-f 127.0.0.1, click replace all with 0.0.0.0 .

Example.
Code:
127.0.0.1  fr.a2dfp.net > 0.0.0.0  fr.a2dfp.net

By doing this, you save a lot of space.

And you leave
Code:
127.0.0.1  localhost
alone.


Title: Re: Stay safe.
Post by: pekv2 on May 17, 2013, 04:19:38 PM
OP updated.


Title: Re: Stay safe.
Post by: John122 on May 17, 2013, 04:48:36 PM
Thanks! Really useful post!


Title: Re: Stay safe.
Post by: pietpatat on May 17, 2013, 05:28:16 PM
Thanks for all the good info!


Title: Re: Stay safe.
Post by: pekv2 on May 19, 2013, 10:09:48 PM
I've added

By Tomatocage

[EDU] How to spot a scammer (Read this before doing any transactions!) (https://bitcointalk.org/index.php?topic=137288.0)

Code:
[url=https://bitcointalk.org/index.php?topic=137288.0][EDU] How to spot a scammer (Read this before doing any transactions!)[/url]

to the OP.


Title: Re: Stay safe.
Post by: Tomatocage on May 19, 2013, 10:13:55 PM
I've added

By Tomatocage

[EDU] How to spot a scammer (Read this before doing any transactions!) (https://bitcointalk.org/index.php?topic=137288.0)

Code:
[url=https://bitcointalk.org/index.php?topic=137288.0][EDU] How to spot a scammer (Read this before doing any transactions!)[/url]

to the OP.

Cool, thanks man. Donated :)


Title: Re: Stay safe.
Post by: pekv2 on May 19, 2013, 10:18:16 PM
Cool, thanks man. Donated :)

wow, thank you as well.


Title: Re: Stay safe.
Post by: GhanaGamboy on May 19, 2013, 10:33:02 PM
Thank you for this nice guide. Much more secure that I using now...


Title: Re: Stay safe.
Post by: pumi on May 20, 2013, 08:03:36 AM
Thank you for information.


Title: Re: Stay safe.
Post by: ghibly79 on May 20, 2013, 06:08:30 PM
Good info, thx.


Title: Re: Stay safe.
Post by: pcmc5 on May 20, 2013, 07:08:39 PM
Great info!
Thanks!


Title: Re: Stay safe.
Post by: dj213 on May 20, 2013, 07:43:43 PM
I wanna also thanks the people that have already done the most critical work for the system to be working and have the ability to saw us the path!


Title: Re: Stay safe.
Post by: mhm83 on May 20, 2013, 07:59:29 PM
wow, thank you for the write up.


Title: Re: Stay safe.
Post by: kodo on May 20, 2013, 09:03:26 PM
Good thread


Title: Re: Stay safe.
Post by: vintosalgos223 on May 20, 2013, 09:31:28 PM
Great information, thanks for posting.


Title: Re: Stay safe.
Post by: sathvikv on May 23, 2013, 09:23:46 AM
thank you for great info


Title: Re: Stay safe.
Post by: Dexter44 on May 23, 2013, 09:27:31 AM
Thankx


Title: Re: Stay safe.
Post by: bitcoinpreneur on May 24, 2013, 01:32:41 PM
Great tips thanks for sharing. I didn't realise LastPass was Google Authenticator enabled, might be time to switch from the 1Password!


Title: Re: Stay safe.
Post by: pekv2 on May 24, 2013, 02:10:02 PM
Great tips thanks for sharing. I didn't realise LastPass was Google Authenticator enabled, might be time to switch from the 1Password!

Not only if I were you, switch to lastpass. 1Password is 30 day trial or pay $49.99. 1Password is also closed source. I wouldn't use it.


Title: Re: Stay safe.
Post by: iram9061 on May 29, 2013, 05:45:15 PM
thanks!


Title: Re: Stay safe.
Post by: fr0st99 on June 01, 2013, 09:28:53 PM
Thanks for the guide !


Title: Re: Stay safe.
Post by: Zuminest on June 03, 2013, 09:57:23 AM
wow! So much info thanks! :) I'll look into Yubi keys


Title: Re: Stay safe.
Post by: coinotran on June 08, 2013, 11:38:30 PM
Great info that everyone should follow in order to stay safe.


Title: Re: Stay safe.
Post by: I am a number on July 05, 2013, 01:24:23 PM
Have used 1password for years now its one of the best Apps out there.
closed source .. maybe... but highly trusted by all its users.


Title: Re: Stay safe.
Post by: Mr.Dreamanonym on July 05, 2013, 02:32:46 PM
Than you very much !  ::)


Title: Re: Stay safe.
Post by: Pastelarts on July 05, 2013, 02:33:41 PM
Yeah great ! nice info


Title: Re: Stay safe.
Post by: naphto on July 05, 2013, 02:34:19 PM
I am safe :(


Title: Re: Stay safe.
Post by: Stickdoxn on July 05, 2013, 02:34:41 PM
I love it !  ;D


Title: Re: Stay safe.
Post by: ParadisehellBTC on July 05, 2013, 02:37:28 PM
Hmmmm ! Thank you ! but i'm safe ! :B


Title: Re: Stay safe.
Post by: canderoi on July 09, 2013, 12:46:54 PM
Thank you. It was very helpfull for me.


Title: Re: Stay safe.
Post by: ropegut on July 23, 2013, 01:11:02 AM
thanks for the advice. good read.


Title: Re: Stay safe.
Post by: btcton on July 23, 2013, 04:23:48 AM
Does any of these password managers sync your passwords with other devices?


Title: Re: Stay safe.
Post by: pekv2 on July 23, 2013, 02:03:42 PM
Does any of these password managers sync your passwords with other devices?

I know lastpass syncs period. If you create a new username and password for some new site on your pc machine, login to lastpass say like on android or touchpad, that newly created username and password for that new site from the pc machine will be there on your android, touch, laptop ect. Basically yes, lastpass does. Or same as if you have three different browsers, which ever one you change/add will sync your other browsers or devices once you login with them. Imo, very handy.


Title: Re: Stay safe.
Post by: Moogy on July 23, 2013, 02:18:02 PM
Saaaafety!!  I experienced a password compromise just recently and thus have had to open new accounts.  Annoying!!! But better than compromising my goodies  ;)

Cheers for an informative post!!


Title: Re: Stay safe.
Post by: ekim_dl on July 30, 2013, 10:57:26 PM
The section concerning
Quote
Block bad stuff with Hosts file by MVPS
is awesome.

I had no idea such a simple yet powerful technique exists!!!

Thanks!


Title: Re: Stay safe.
Post by: pekv2 on July 31, 2013, 01:01:31 PM
The section concerning
Quote
Block bad stuff with Hosts file by MVPS
is awesome.

I had no idea such a simple yet powerful technique exists!!!

Thanks!

It's what I love about PC, it's so versatile, it's yours, nothing like a gaming console and such a like.


Title: Re: Stay safe.
Post by: Newar on August 04, 2013, 09:17:28 AM
Maybe add that Android apps (and I guess iPhones apps too) should not be run on rooted phones, as this opens the door to malware to read sensible information (at least that's how I understand it).


Title: Re: Stay safe.
Post by: pekv2 on November 15, 2013, 03:58:04 AM
Stay safe. Just a reminder.


Title: Re: Stay safe.
Post by: coreli on November 15, 2013, 05:33:56 AM
Stay safe. Just a reminder.

Your thread should be stickied in the newbies section.


Title: Re: Stay safe.
Post by: marcotheminer on November 15, 2013, 06:20:50 AM
Awesome thread, Im going through it now and im gonna do some of it!
Thanks


Title: Re: Stay safe.
Post by: pekv2 on November 24, 2013, 03:15:12 AM
I've added something to the OP that might save someone much trouble if practiced.

Added to the OP:

Avoid Link-Scammers

Avoid Link-Scammers (https://bitcointalk.org/index.php?topic=336505.msg3692526#msg3692526)


Title: Re: Stay safe.
Post by: nipponese on November 25, 2013, 04:16:31 PM
Is there not a way to require 2-factor Google Authenticator keys for login?


Title: Re: Stay safe.
Post by: reaxion on November 25, 2013, 05:45:19 PM
great advice thanks


Title: Re: Stay safe.
Post by: 420smokz on November 25, 2013, 05:51:46 PM
This is great! Thanks!


Title: Re: Stay safe.
Post by: pekv2 on November 25, 2013, 09:13:08 PM
np, guys.

Is there not a way to require 2-factor Google Authenticator keys for login?

For? I do not fully understand your question.


Title: Re: Stay safe.
Post by: SirBitsalot on December 03, 2013, 04:43:13 AM
Wow GREAT article especially for a new guy! Thanks :)


Title: Re: Stay safe.
Post by: AlliumPorrum on December 06, 2013, 04:32:17 PM
If using Windows, would it be a good idea from security point of view to handle all wallets by running a virtualized Linux on top of Windows? This way I wouldn't need to start the computer to Linux with CD everytime I need to handle wallets, but are the any risks from security point of view?

They are still on the same computer and using the same memory, but I would think that if the Windows is affected by some malware, it shouldn't be possible to address Linux applications anyhow.


Title: Re: Stay safe.
Post by: cerulean on December 06, 2013, 05:58:55 PM
Interesting. I have tried all before I read this thread though but it's a good one for newbies, especially for those who just can't stay "safe".


Title: Re: Stay safe.
Post by: AlliumPorrum on December 07, 2013, 09:16:18 AM
By "not staying safe", are you referring to using Windows over all..?   ???

My wife uses this PC also, so unfortunately there really isn't any option for Windows.

Thinking more about this Linux virtualization; theoretically if there where some key tracking malware on Windows, it could read all keys pressed when using the Linux wallet. But I'm not sure if this could cause any problems or not?

How about the wallet file; is it safe when using virtualized Linux? Where exactly would it be stored, and could it be possile that some Windows malware could access it?


Title: Re: Stay safe.
Post by: pekv2 on December 24, 2013, 06:00:41 PM
Block bad stuff with Hosts file by MVPS < Has been edited.

MVPS is now supplying their hosts file with 0.0.0.0 rather 127.0.0.1.

Good move on mvps's part. Saves them space as well.

Edit:
I suppose if you want to be hardcore secure, linux is the route. No windows>linux virtual stuff. No windows period.


Title: Re: Stay safe.
Post by: Taint on January 02, 2014, 08:41:28 PM
This is a good safety guide, I'd like to throw in a vote for Password Safe.

I'd also like to suggest you check out TrueCrypt, an Open Source solution for encrypted file storage. It's portable and works under Linux, Windows and Mac.

Finally, I have to wish more sites were willing to use Google's OTP 'Authenticator'. It's one of the reasons I like Slush's pool.

-Edited for spelling


Title: Re: Stay safe.
Post by: stbot on January 04, 2014, 09:17:41 PM
keepass has addons which allow sftp of the database file to a selected server. This is a good option to back up you password database.

http://keepass.info/plugins.html#ioprotocolext for sftp addon KeePass 2.x


Title: Re: Stay safe.
Post by: xbtitman on January 10, 2014, 04:12:05 AM
Great site.  Thanks for the info.

Do you recommend getting the Xmarks bundle package with LastPass premium?

Cheers,
James


Title: UPDATE: Re: Stay safe.
Post by: pekv2 on February 23, 2014, 05:04:29 AM
Edited and added

Quote
Additional Notes:
With the latest LastPass as of the moment 3.1.0, and you have a system strong computer system you may up the PW iterations. Raise in increments of 100 or 1000. Anything high might be bad for mobile devices or slow computers. I set mine at 200000 Not recommended if you do not know what you're doing..
https://helpdesk.lastpass.com/security-options/password-iterations-pbkdf2/

Quote
Block unencrypted content on encrypted sites with Firefox or a browser equivalent to Firefox.

With the latest Firefox ESR or latest release of firefox, you may block mixed content at about:config. I don't know about earlier versions of FF.

Code:
security.mixed_content.block_display_content : true
security.mixed_content.block_active_content : true

Also two addons add two buttons to easily disable or enable these settings.
https://addons.mozilla.org/en-US/firefox/addon/toggle-mixed-active-content/
https://addons.mozilla.org/en-US/firefox/addon/toggle-mixed-display-content/


Quote
An option too up your google account security.

The security question for google, allows you to change it to a custom question.
I took with my lastpass addon and generated a character password with Show advance options ticked, everything ticked to make your password the strongest. Copy generated password, paste as security question.

Go back to generate a new password and generate a new password with highest strength possible, copy and paste for the answer.
Save/update google settings.

Open a secure note for lastpass and keep these two generated password stored under its title question/answer, which is protected by your masterpassword for lastpass.

It's just a blockade against a security question attack on your google account or any other account that has this security question feature.


Title: Re: Stay safe.
Post by: bitGun on February 23, 2014, 12:21:20 PM
great information, thanks!
about the software, what about PASSWORD SAFE?
it's open source and it's  free!


Title: Re: Stay safe.
Post by: apsvinet on February 23, 2014, 04:24:20 PM
Me gusta this thread.
Thanks for the advice op, bookmarked this thread.


Title: Re: Stay safe.
Post by: khalilhimura on March 09, 2014, 05:40:02 PM
Thanks OP for the great info. Was looking for tips on security. PGP was on my to do list :)


Title: Re: Stay safe.
Post by: LuckyBtc on March 09, 2014, 05:45:49 PM
Thanks for sharing this usefull info :)


Title: Re: Stay safe.
Post by: pekv2 on April 12, 2014, 09:42:21 AM
Heartbleed bug. List of site reported that was effected.

http://mashable.com/2014/04/09/heartbleed-bug-websites-affected/

Lastpass was the last on the list. Fixed and patched.



Title: Re: Stay safe.
Post by: Equate on April 12, 2014, 09:43:12 AM
Great thread , thanks for valuable info.


Title: Re: Stay safe.
Post by: sanjoea on April 12, 2014, 10:11:26 AM
Useful information for all


Title: Re: Stay safe.
Post by: escrow.ms on April 12, 2014, 06:15:39 PM
This thread should be stickied.


Title: Re: Stay safe.
Post by: pekv2 on April 12, 2014, 06:52:51 PM
This thread should be stickied.

It once was, then trolls got to me, I took everything in the thread out [Im a to fast of a thinker and what I did was wrong so I very much doubtfully it will be stickied again.] it got unstickied so now it is located through https://bitcointalk.org/index.php?topic=177133.0

I feel I broke the freedom of speech when I removed the thread and betrayed us all by doing it :/, It's something I learned from.


Title: Re: Stay safe.
Post by: pekv2 on April 14, 2014, 09:03:16 PM
Check out your sites.

https://lastpass.com/heartbleed/

Neat little web program.


Title: Re: Stay safe.
Post by: counter on April 14, 2014, 09:37:48 PM
Always concerned for my security especially with all the news coming out these days.. thanks alot for sharing the information with the rest of us.


Title: Re: Stay safe.
Post by: apsvinet on April 15, 2014, 04:23:33 PM
Why can't they just sticky this again? Shouldn't be hard, and would be really appreciated.


Title: Re: Stay safe.
Post by: Simon8x on April 15, 2014, 04:40:20 PM
Why can't they just sticky this again? Shouldn't be hard, and would be really appreciated.

This.

At the very least, a link to this thread could be placed somewhere in the newbie readme.


Title: Re: Stay safe.
Post by: apsvinet on April 15, 2014, 04:57:13 PM
Why can't they just sticky this again? Shouldn't be hard, and would be really appreciated.

This.

At the very least, a link to this thread could be placed somewhere in the newbie readme.
That could work too, however it's not only for newbies, so rather a sticky where -everyone- can see it.


Title: Re: Stay safe.
Post by: pekv2 on April 15, 2014, 05:22:36 PM
It's a matter of against theymos's advice to be stickied and a trust thing against me I am guessing.

Edit:
I also try to bump it here n there.


Title: Re: Stay safe.
Post by: apsvinet on April 15, 2014, 09:43:02 PM
It's a matter of against theymos's advice to be stickied and a trust thing against me I am guessing.

Edit:
I also try to bump it here n there.
That's good. And I suppose you're right, might be odd if he stickied it.


Title: Re: Stay safe.
Post by: pekv2 on April 18, 2014, 06:41:23 PM
Maybe add that Android apps (and I guess iPhones apps too) should not be run on rooted phones, as this opens the door to malware to read sensible information (at least that's how I understand it).

I never knew this.

Care to explain? Only if you can. In detail why and how it is very bad. I'll add it.

I was running a rooted android but nothing to real connected to sensitive data, separated email account, used it as a 2ndary pc for when I had problems or doing technical work with pc off, I need a laptop.


Title: Re: Stay safe.
Post by: pekv2 on April 18, 2014, 06:57:13 PM
great information, thanks!
about the software, what about PASSWORD SAFE?
it's open source and it's  free!

Its in the op. added it a while back long time ago.


Title: Re: Stay safe.
Post by: pekv2 on April 18, 2014, 08:27:30 PM
I am retiring from this thread. I will be giving permission to escrow.ms for the new OP.

Thank you all for your generous help.

https://bitcointalk.org/index.php?topic=576036.msg6285515#msg6285515


Title: Re: Stay safe.
Post by: apsvinet on April 19, 2014, 12:03:22 AM
I am retiring from this thread. I will be giving permission to escrow.ms for the new OP.

Thank you all for your generous help.

https://bitcointalk.org/index.php?topic=576036.msg6285515#msg6285515
Thanks for everything you've done here, it's been really useful information spread and I'm sure lots of people have benefited from it.

Thanks again! :)


Title: Re: Stay safe.
Post by: jodybay on April 19, 2014, 02:40:11 AM
this is a very good information and very helpfull speacialy to those people who is new to bitcoin this will help them to be safe keep it up escrow ms


Title: Re: Stay safe.
Post by: escrow.ms on April 19, 2014, 05:12:13 PM
this is a very good information and very helpfull speacialy to those people who is new to bitcoin this will help them to be safe keep it up escrow ms

It's actually pekv2's thread. He transferred this thread to me yesterday. I'll update it with more info soon.


Title: Re: Stay safe.
Post by: escrow.ms on April 20, 2014, 09:35:44 PM
I have added a new thread about IPO investments. I hope new users will read it, before investing their hard earned money.

https://bitcointalk.org/index.php?topic=577790.0;topicseen


Title: Re: Stay safe.
Post by: Orthy on April 22, 2014, 02:26:03 AM
I've been using lastpass for quite some time now and it gives me peace of mind knowing my passwords are always safe and secured.

It's great to have this thread up. Thanks.


Title: Re: Stay safe.
Post by: pekv2 on April 22, 2014, 02:49:35 AM
I have added a new thread about IPO investments. I hope new users will read it, before investing their hard earned money.

https://bitcointalk.org/index.php?topic=577790.0;topicseen

Nice.

I've been using lastpass for quite some time now and it gives me peace of mind knowing my passwords are always safe and secured.

It's great to have this thread up. Thanks.

It is, Also, for everyone to know, they may export their lastpass as lastpass csv file and then import it to keepass2 as Lastpass CSV by signing into lastpass, left click the lastpass addon icon, Tools/Advance Tools/Export to/Lastpass CSV , save where ever.

Open keepass2, make a new data base, create strong PW for keepass2 new database.

On the Menu bar of keepass2, click File/Import/ scroll down to /Lastpass CSV. Highlight it. Click the folder icon that appears that says "File to be imported". Navigate to your exported Lastpass CSV file click ok.

Reason of this new plugin is it handles PW's, secure notes, ect ect ect just like how lastpass handles everything which is very very awesome.

The two mixes very nicely now.


Title: Re: Stay safe.
Post by: Orthy on April 22, 2014, 03:51:29 AM
I have added a new thread about IPO investments. I hope new users will read it, before investing their hard earned money.

https://bitcointalk.org/index.php?topic=577790.0;topicseen

Nice.

I've been using lastpass for quite some time now and it gives me peace of mind knowing my passwords are always safe and secured.

It's great to have this thread up. Thanks.

It is, Also, for everyone to know, they may export their lastpass as lastpass csv file and then import it to keepass2 as Lastpass CSV by signing into lastpass, left click the lastpass addon icon, Tools/Advance Tools/Export to/Lastpass CSV , save where ever.

Open keepass2, make a new data base, create strong PW for keepass2 new database.

On the Menu bar of keepass2, click File/Import/ scroll down to /Lastpass CSV. Highlight it. Click the folder icon that appears that says "File to be imported". Navigate to your exported Lastpass CSV file click ok.

Reason of this new plugin is it handles PW's, secure notes, ect ect ect just like how lastpass handles everything which is very very awesome.

The two mixes very nicely now.

Nice, thank you.

Didn't know I can import my lastpass passwords and notes to keepass2. It's really awesome.

I can have a secured backup of my passwords and notes in keepass2 now. +1



Title: Re: Stay safe.
Post by: Newar on April 22, 2014, 06:26:42 AM
Maybe add that Android apps (and I guess iPhones apps too) should not be run on rooted phones, as this opens the door to malware to read sensible information (at least that's how I understand it).

I never knew this.

Care to explain? Only if you can. In detail why and how it is very bad. I'll add it.

I was running a rooted android but nothing to real connected to sensitive data, separated email account, used it as a 2ndary pc for when I had problems or doing technical work with pc off, I need a laptop.

The one I remember off the top of my head is an early version of the blockchain.info app where users lost funds running the app on rooted phones. Blockchaininfo kept the password in a plaintext file that would not have been accessible on a sandboxed phone. Since it was rooted that info was accessible to the malware. A combination of things for sure, but if you're phone was not rooted, the malware could not have gotten to it.

A second example would be your Google Authenticator keys, which can be relatively easy read out from a rooted phone (I did this myself when I had to switch phones). Not so from a sandboxed one.


Title: Re: Stay safe.
Post by: pekv2 on April 22, 2014, 10:13:19 AM
The one I remember off the top of my head is an early version of the blockchain.info app where users lost funds running the app on rooted phones. Blockchaininfo kept the password in a plaintext file that would not have been accessible on a sandboxed phone. Since it was rooted that info was accessible to the malware. A combination of things for sure, but if you're phone was not rooted, the malware could not have gotten to it.

A second example would be your Google Authenticator keys, which can be relatively easy read out from a rooted phone (I did this myself when I had to switch phones). Not so from a sandboxed one.

Holy Moly. Not good.


Title: Re: Stay safe.
Post by: escrow.ms on April 22, 2014, 10:40:03 AM
Thanks Newar, I have Added it in android security

Quote
Android Security

TIP #1 Don't store bitcoins on a rooted cellphone.
Rooting your device increases the security exposure to malicious applications and potential application flaws, thus any malware can steal your wallet/keys stored in a protected directory.
Malware on a rooted phone can also access other applications like google authenticator and read/write phone logs,sms etc which are needed for verification process in many websites/apps.

TIP #2 – Don’t install apps from untrusted third party apps stores.
TIP #3 – Use an anti-virus app for an extra layer of protection.


Title: Re: Stay safe.
Post by: Newar on April 22, 2014, 12:01:43 PM
Some more stay safe ideas: 

http://crunchbang.org/forums/viewtopic.php?id=24722


Title: Re: Stay safe.
Post by: escrow.ms on April 22, 2014, 02:03:03 PM
Some more stay safe ideas:  

http://crunchbang.org/forums/viewtopic.php?id=24722

Thanks, It's really good. I am also making same kind of detailed guide.

Ps: APK scanner links added.

Quote
APK scanners:
http://apkscan.nviso.be/
http://mobilesandbox.org/
http://virustotal.com/
http://scan.netqin.com/en/
https://anubis.iseclab.org/


Title: Re: Stay safe.
Post by: pekv2 on April 22, 2014, 02:07:49 PM
I am very happy I have resigned. Thread is already improving. Great work.


Title: Re: Stay safe.
Post by: escrow.ms on April 22, 2014, 02:23:15 PM
I am very happy I have resigned. Thread is already improving. Great work.
Thanks :)

Just added a link of GPG guide by GoldenWings91

Proper way to Create & verify GPG Signature using Kleopatra on Windows (https://bitcointalk.org/index.php?topic=297434.msg3202050#msg3202050)


Title: Re: Stay safe.
Post by: escrow.ms on April 24, 2014, 10:49:02 PM
Bump.


Title: Re: Stay safe.
Post by: cookiemonsterwhat on April 24, 2014, 11:51:31 PM
I read up to the password part of Lastpass and freeware.

I`ll continue to read where i left to for your safety tips.

Bookmarked, and thank you  :)

Can you also link your escrow stuff?

Edit: Never mind, just overlooked the small words "escrow" in your signature lol.


Title: Re: Stay safe.
Post by: PerrythePlatypus on April 26, 2014, 07:15:01 AM
I like Lastpass's password generator. Nice tutorial though.  :D


Title: Re: Stay safe.
Post by: pekv2 on April 26, 2014, 10:07:00 AM
If this is true, watch out for malicious browser addons.

https://bitcointalk.org/index.php?topic=584963.msg6400146#msg6400146

Don't use online wallet storage and divide your btc up into multiple dif wallets if you have a lot.


Title: Re: Stay safe.
Post by: pekv2 on May 07, 2014, 02:35:36 AM
Bump for the community.


Title: Re: Stay safe.
Post by: Vitsila on May 07, 2014, 03:21:13 AM
Paper wallets isn't the safest way?


Title: Re: Stay safe.
Post by: Chemistry1988 on May 07, 2014, 08:17:45 PM
Paper wallets isn't the saferst way?

IMO, paper wallet is one of the safest way to keep your bitcoin as long as you set it up correctly.  :)


Title: Re: Stay safe.
Post by: Vitsila on May 07, 2014, 08:46:39 PM
Paper wallets isn't the saferst way?

IMO, paper wallet is one of the safest way to keep your bitcoin as long as you set it up correctly.  :)

Thanks , i am going to search for instructions for set up in the forum.


Title: Re: Stay safe.
Post by: escrow.ms on May 07, 2014, 10:15:42 PM
Paper wallets isn't the saferst way?

IMO, paper wallet is one of the safest way to keep your bitcoin as long as you set it up correctly.  :)

Thanks , i am going to search for instructions for set up in the forum.

http://www.coindesk.com/information/paper-wallet-tutorial/


Title: Re: Stay safe.
Post by: Vitsila on May 07, 2014, 11:02:38 PM
http://www.coindesk.com/information/paper-wallet-tutorial/
Thank you.  :)


Title: Re: Stay safe.
Post by: Sonny on May 08, 2014, 04:48:05 AM
http://www.coindesk.com/information/paper-wallet-tutorial/
Thank you.  :)


The coindesk article is good, but you should read the "Security Concerns" section (especially the part of creating your private keys offline) before following the 10 steps :)


Title: Re: Stay safe.
Post by: Newar on May 08, 2014, 06:03:25 AM
See also: http://localbitcoins.blogspot.com/2012/11/start-your-own-money-press.html?m=1


Mycelium works great to spend from paper wallets.


Title: Re: Stay safe.
Post by: Newar on May 20, 2014, 03:28:21 AM
Don't think this was posted before. A good tool to check for your password strength (includes english dictionary and patterns):

https://dl.dropboxusercontent.com/u/209/zxcvbn/test/index.html


Title: Re: Stay safe.
Post by: escrow.ms on May 20, 2014, 04:02:05 AM
Thanks Newar both links are really useful.


Title: Re: Stay safe.
Post by: worth5868 on May 20, 2014, 07:26:10 AM
Thanks author very informative, big thumbs up.


Title: Re: Stay safe.
Post by: carb0nf1b3r on May 24, 2014, 01:39:15 AM
Thank you for taking the time to post this


Title: Re: Stay safe.
Post by: Muhammed Zakir on August 04, 2014, 02:53:58 PM
Don't think this was posted before. A good tool to check for your password strength (includes english dictionary and patterns):

https://dl.dropboxusercontent.com/u/209/zxcvbn/test/index.html

Thanks for the link. It really is useful.
Password : You can make harder pass with some sentences too. Eg:- My Name Is Zakir . Take first letters of all the word, i.e., MNIZ . Try to use some signs instead of letters, i.e., /\/\|\||$z . Try not to use any phrases or words. Use random letters - both uppercase and lowercase, signs and numbers . You can use Bitgo for checking password strength too by clicking sign up wand entering the password but it is better to use the link given by Newar as it gives more details. Don't ever store your password in any digital things, store it in any book and try not to give any headings or something like that, which can will lead a person to think it is a pass. Try to write it as you write other contents in it, in a usual way.

Kindly,
      MZ


Title: Re: Stay safe.
Post by: Newar on August 09, 2014, 10:36:34 AM
/\/\|\||$z

IMO, the main factor is length. Once you got at least one of each (of course more symbols are better), length becomes most important since the attacker can not know the length. He has to start from low character count passwords and work his way up. (And I feel zxcvbn doesn't take that into account enough.)

https://www.grc.com/haystack.htm
Quote
But wouldn't something like “D0g” be in a dictionary, even with the 'o' being a zero?

Sure, it might be. But that doesn't matter, because the attacker is totally blind to the way your passwords look. The old expression “Close only counts in horseshoes and hand grenades” applies here. The only thing an attacker can know is whether a password guess was an exact match . . . or not. The attacker doesn't know how long the password is, nor anything about what it might look like. So after exhausting all of the standard password cracking lists, databases and dictionaries, the attacker has no option other than to either give up and move on to someone else, or start guessing every possible password.


Title: Re: Stay safe.
Post by: jeroenn13 on August 09, 2014, 04:21:41 PM
Great topic!
Thank you