56,996 views
???? I’ve encouraged you to use password managers many times. I use them myself and I still think they’re one of the best things you can do to improve your digital security. But today I’m going to talk about when password managers can actually become a threat. Sources: ???? Analysis of the latest @LastPass attack https://bit.ly/3XqtoA4 & https://bit.ly/3RSB2SG ???? What does LastPass actually encrypt? https://bit.ly/3ltLGn1 ⏰ @1PasswordVideos on the time it takes to crack their passwords https://bit.ly/3YMkfmr ⁉️ Check if your password was leaked https://haveibeenpwned.com/ ???? @OWASPGLOBAL report on best practices for rounds and iterations https://bit.ly/3IjYDsz ????️ Implementation details on how to save a password https://bit.ly/2KLJHmm ???? A 20+ year old thread on StackExchange (still active!) about how security requirements have changed over time. https://bit.ly/3HRIKIh ???? 1password blog post on using secret keys https://bit.ly/3IfK1KC ❔ Why did 1password switch to 256-bit keys? https://bit.ly/3RV01ER ❓ Why was the data leak handled badly by LastPass? https://bit.ly/3E1irhs ???? Bugs in Bitwarden, DashLane, and Safari leading to password leaks https://bit.ly/3YGXy3a ????️ LastPass press release on the security incident https://bit.ly/3YFEWRa & https://bit.ly/3IhXL7u ????️ Password cracking in the cloud using graphics cards https://bit.ly/3IkAUsg ???? Elcomsoft tool for decrypting *.zip archives https://bit.ly/3Yp65rX If you don't trust shortened links (very good!), add a '+' at the end of them. That way, you can see where they lead on the bit.ly website. Relevant xkcd: https://xkcd.com/792/ © All trademarks belong to their rightful owners. Thank you for your attention. ❤️ You can also find me on; Instagram @mateuszemsi / mateuszemsi Twitter @MateuszChrobok / mateuszchrobok Mastodon https://infosec.exchange/@mateuszchrobok LinkedIn @mateuszchrobok / mateuszchrobok Patronite @MateuszChrobok https://patronite.pl/MateuszChrobok Podcasts on; Anchor https://anchor.fm/mateusz-chrobok Spotify https://open.spotify.com/show/6y6oWs2... Apple Podcasts https://apple.co/3OwjvOh Thank you for hosting the wonderful Synergia cafe. Good Place! Chapters: 00:00 Intro 01:16 Password Databases 05:09 Hash Functions 09:52 What to Choose? 10:54 LastPass 15:38 BitWarden, 1password 17:48 Summary 18:36 What to Do and How to Live? #security #password #LastPass #BitWarden #1password