Opisek

joined 2 weeks ago
[–] Opisek@piefed.blahaj.zone 4 points 4 hours ago

I don't know how I feel about this new revelation

[–] Opisek@piefed.blahaj.zone 3 points 13 hours ago* (last edited 13 hours ago)

It's actually even outright discouraged by NIST.

For those who don't see the reason why, forced password resets lead to users using predictable passwords like "password2025october", "password2025november", etc.

[–] Opisek@piefed.blahaj.zone 1 points 13 hours ago* (last edited 13 hours ago) (1 children)

Good parenting! I hate to see most parents nowadays give their children unsupervised access to the mindless brainrot boxes that are smartphones or tablets. Personally, having grown up with computers (and an analogue screentime limit), figuring things out through one's own curiosity is the way to learn about how things work and how to solve problems on your own.

[–] Opisek@piefed.blahaj.zone 2 points 13 hours ago

Hi I'm not a millennial, yet I do enjoy my beloved pdftk.

Though it may have to do with a suspected level of neurodivergence.

[–] Opisek@piefed.blahaj.zone 9 points 13 hours ago (2 children)

I don't know if amazing or just privileged. Shouldn't someone stand up in the face of injustice and human rights violation?

[–] Opisek@piefed.blahaj.zone 19 points 13 hours ago (4 children)

Actual gestapo. Can't wait to see them all face a trial. (I do still hope that fascism can be defeated again.)

[–] Opisek@piefed.blahaj.zone 1 points 14 hours ago (6 children)

What's wrong with beinhalten?

[–] Opisek@piefed.blahaj.zone 2 points 14 hours ago

Why yes I always dreamed of writing code like a full on novel.

[–] Opisek@piefed.blahaj.zone 2 points 14 hours ago

Quellcodeanglizismussubstastivbeispielersatzgroßschreibungsregel

[–] Opisek@piefed.blahaj.zone 4 points 14 hours ago

Seven bald eagles and three units of freedom

[–] Opisek@piefed.blahaj.zone 2 points 14 hours ago* (last edited 14 hours ago)

Well, they're not a bad thing per se, it's just important to remember that by doing that you are essentially delegating the access security (including any means of MFA) from the target website to the password manager. I.e., instead of inputting password and 2FA code for example.com, you have to input your password and 2FA code for the password manager itself. This has the same security guarantees, so long as you don't set your vault to—for example—never lock automatically.

For the case of passkeys, using Bitwarden, even with 2FA does reduce the security level in my eyes somewhat, since I'd argue passkeys to be a more secure measure than password + OTP. Unless, of course, you use a different passkey to authenticate yourself to Bitwarden.

TLDR; be careful about putting everything inside Bitwarden. You'll be fine if you make sure to protect your password manager adequately, but if you put OTP secrets (or passkeys) for other website inside Bitwarden AND only use password authentication for Bitwarden without any MFA, then you are effectively reducing your MFA back to a single factor (the Bitwarden password).

I'm afraid user authentication on the internet is broken beyond salvation. It's already complex enough to grasp fully for tech-savvy people, meanwhile we've taught the general population to use password123 for all their accounts and write it on a post-it for a good measure.

228
submitted 5 days ago* (last edited 5 days ago) by Opisek@piefed.blahaj.zone to c/the_pack@lemmy.world
view more: next ›