Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.mobile.android > #57320 > unrolled thread
| Started by | K120 <hunterfox@interweb.net> |
|---|---|
| First post | 2018-11-08 10:52 -0500 |
| Last post | 2018-11-17 10:30 -0500 |
| Articles | 20 on this page of 170 — 15 participants |
Back to article view | Back to comp.mobile.android
8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-08 10:52 -0500
Re: 8MB sms pic KenW <ken1943@invalid.net> - 2018-11-08 09:11 -0700
Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-08 22:31 +0000
Re: 8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-09 17:07 -0500
Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-10 02:36 +0000
Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-11 11:34 +0000
Re: 8MB sms pic Andy Burns <usenet@andyburns.uk> - 2018-11-11 11:47 +0000
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-11 13:08 +0100
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-11 17:23 +0100
Re: 8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-11 12:37 -0500
Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-11 19:19 +0000
Re: 8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-11 16:34 -0500
Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-12 07:53 +0000
Re: 8MB sms pic Andy Burns <usenet@andyburns.uk> - 2018-11-12 08:11 +0000
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-12 02:29 +0100
Re: 8MB sms pic Piet <www.godfatherof.nl/@opt-in.invalid> - 2018-11-12 12:22 +0100
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-12 14:02 +0100
Re: 8MB sms pic Piet <www.godfatherof.nl/@opt-in.invalid> - 2018-11-12 20:01 +0100
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 02:27 +0100
Re: 8MB sms pic Piet <www.godfatherof.nl/@opt-in.invalid> - 2018-11-13 10:51 +0100
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 11:05 +0100
Re: 8MB sms pic Piet <www.godfatherof.nl/@opt-in.invalid> - 2018-11-13 12:39 +0100
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 19:02 -0700
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-12 21:16 +0100
[OT] Ping: Piet (was: 8MB sms pic) Frank Slootweg <this@ddress.is.invalid> - 2018-11-15 22:10 +0000
Re: [OT] Ping: Piet Piet <www.godfatherof.nl/@opt-in.invalid> - 2018-11-16 09:46 +0100
Re: [OT] Ping: Piet Frank Slootweg <this@ddress.is.invalid> - 2018-11-16 11:50 +0000
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-12 06:19 +0100
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-12 02:20 +0100
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-11 17:21 +0100
Re: 8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-11 16:44 -0500
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-12 06:21 +0100
Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-12 08:17 +0000
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-12 02:32 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-11 20:47 -0500
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-12 06:27 +0100
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-11 23:40 -0700
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-12 19:02 +0000
Re: 8MB sms pic Andy Burns <usenet@andyburns.uk> - 2018-11-12 19:07 +0000
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-12 21:28 +0100
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-12 21:21 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 20:25 -0500
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 02:29 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 20:39 -0500
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 08:11 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 09:03 -0500
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 15:40 +0100
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-13 15:50 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 11:13 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-13 10:26 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 13:08 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-13 11:43 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 13:49 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-13 12:06 -0700
Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-14 08:28 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 09:15 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-14 10:17 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 12:53 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-14 15:38 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 00:04 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 00:25 -0700
Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-14 18:46 +0000
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-14 15:38 -0700
Re: 8MB sms pic chris <ithinkiam@gmail.com> - 2018-11-15 18:57 +0000
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 12:37 -0700
Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-15 22:40 +0000
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 16:06 -0700
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-15 21:14 +0000
Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-15 22:16 +0000
Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-14 18:41 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 14:33 -0500
Re: 8MB sms pic chris <ithinkiam@gmail.com> - 2018-11-15 18:57 +0000
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 18:48 +0100
Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-13 18:36 +0000
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-13 20:32 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 15:49 -0500
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-16 14:30 +0100
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-13 15:12 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 10:21 -0500
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 18:51 +0100
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 19:22 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 21:42 -0400
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 19:54 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 22:06 -0400
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 20:26 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 22:40 -0400
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 21:23 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 23:32 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 22:21 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 00:50 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-13 08:18 -0700
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 19:02 +0100
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 09:29 +0100
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-13 08:18 -0700
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 08:27 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 23:34 -0500
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 09:32 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 09:08 -0500
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 15:43 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 09:54 -0500
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 19:08 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 13:22 -0500
Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-13 18:31 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 13:49 -0500
Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-13 19:16 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 14:24 -0500
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-14 09:34 +0100
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-14 09:31 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 09:15 -0500
Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-14 17:28 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 12:53 -0500
Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-14 18:47 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 14:33 -0500
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-14 19:00 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 14:33 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-14 15:38 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 00:04 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 00:25 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 12:09 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 12:53 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 15:08 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 15:03 -0700
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 17:10 -0500
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 15:40 -0700
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-15 16:27 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 12:09 -0500
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-15 19:01 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 14:51 -0500
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-15 21:11 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 16:47 -0500
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-16 14:43 +0000
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-16 13:11 -0500
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-17 01:10 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-16 20:10 -0500
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-17 11:24 +0100
Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 10:32 -0700
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-16 14:48 +0100
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-14 09:34 +0100
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 18:05 +0100
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 19:10 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 13:22 -0500
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-16 15:03 +0100
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 08:23 +0100
Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-13 11:40 +0000
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 15:46 +0100
Re: 8MB sms pic Andy Burns <usenet@andyburns.uk> - 2018-11-13 06:35 +0000
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 08:17 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 09:03 -0500
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 15:37 +0100
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 06:12 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 00:21 -0500
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 11:57 +0100
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 09:34 +0100
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 11:59 +0100
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 15:38 +0100
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 06:08 +0100
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 00:21 -0500
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 09:34 +0100
Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 08:12 +0100
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 06:06 +0100
Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-13 15:04 +0000
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-12 10:54 +0100
Re: 8MB sms pic M.L. <me@privacy.invalid> - 2018-11-13 06:59 -0600
Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 09:03 -0500
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-11 13:11 +0100
Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-11 17:27 +0100
Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-12 02:37 +0100
Re: 8MB sms pic KenW <ken1943@invalid.net> - 2018-11-08 09:19 -0700
Re: 8MB sms pic musika <mUs1Ka@NOSPAMexcite.com> - 2018-11-09 11:48 +0000
Re: 8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-17 10:30 -0500
Page 4 of 9 — ← Prev page 1 2 3 [4] 5 6 7 8 9 Next page →
| From | 123456789 <12345@12345.com> |
|---|---|
| Date | 2018-11-15 00:25 -0700 |
| Message-ID | <psj719$de0$1@dont-email.me> |
| In reply to | #57537 |
On 11/14/2018 10:04 PM, nospam wrote: > 123456789 <12345@12345.com> wrote: >>>> When I recently froze my three credit bureau records online >>>> they asked verification questions like what year my house was >>>> built? And what was the prefix of my previous home phone >>>> number? Those were not prearranged and apparently obtained >>>> from my account. >>> that's all public information. >> Glad someone else didn't hack in and freeze my accounts... > yet... Too late. I now have new official user name/password entry type credit bureau accounts with....drum roll... 2FA SMS security... ;)
[toc] | [prev] | [next] | [standalone]
| From | Chris <ithinkiam@gmail.com> |
|---|---|
| Date | 2018-11-14 18:46 +0000 |
| Message-ID | <pshqhb$fic$1@dont-email.me> |
| In reply to | #57516 |
123456789 <12345@12345.com> wrote: > On 11/14/2018 7:15 AM, nospam wrote: >> Chris <ithinkiam@gmail.com> wrote: > >>>>>> hijack your phone and game over. >>>>> Not so easy these days. But still useless without passwords. >>>> it's very easy these days and getting easier. > >>> Only if the target is a fool by reusing passwords. > > I use a formula that INTERMINGLES certain letters of the site/apps name > (for example first + third + last 2) with a memorized number/character > combination. The sensitive sites have an extra pin inserted. Looks like > gibberish, good for exercising the old memory, and no password lists > laying around. I used to do this too, but got fed up with so many sites being "incompatible" with my system. There isn't a single system that works with all websites. For example, some websites require special characters and others won't accept them. > Ok password manager users, I can see you squirming...GO It's just easier with a manager. >> they usually give real answers to the insecurity questions, which is >> almost always public information, including mother's maiden name, first >> car that they owned, etc. > > I thought insecurity questions dumb too. I always used nonsense answers > and just saved them. What was the make of your first car: Donkey... > > In recent years I've not been asked those questions. The sites that used > to use that system now rely on the (infamous?) semi-2FA we've been > discussing. Yep. Those questions have not caught on thankfully.
[toc] | [prev] | [next] | [standalone]
| From | 123456789 <12345@12345.com> |
|---|---|
| Date | 2018-11-14 15:38 -0700 |
| Message-ID | <psi85o$7gn$2@dont-email.me> |
| In reply to | #57522 |
On 11/14/2018 11:46 AM, Chris wrote: > 123456789 <12345@12345.com> wrote: >> Ok password manager users, I can see you squirming...GO > It's just easier with a manager. You could let Google Chrome save your passwords. It's always asking to save mine...
[toc] | [prev] | [next] | [standalone]
| From | chris <ithinkiam@gmail.com> |
|---|---|
| Date | 2018-11-15 18:57 +0000 |
| Message-ID | <pskfic$trq$1@dont-email.me> |
| In reply to | #57529 |
123456789 <12345@12345.com> wrote: > On 11/14/2018 11:46 AM, Chris wrote: >> 123456789 <12345@12345.com> wrote: > >>> Ok password manager users, I can see you squirming...GO > >> It's just easier with a manager. > > You could let Google Chrome save your passwords. It's always asking to > save mine... Never! Aside from the privacy issues you're completely screwed if the access went down or you have no internet access. This has happened to lastpass users and i store offline passwords as well as online ones. If anyone's considering a password manager always go for one which stores them locally and does an online sync.
[toc] | [prev] | [next] | [standalone]
| From | 123456789 <12345@12345.com> |
|---|---|
| Date | 2018-11-15 12:37 -0700 |
| Message-ID | <pskhtn$uhs$1@gioia.aioe.org> |
| In reply to | #57547 |
On 11/15/2018 11:57 AM, chris wrote: > 123456789 <12345@12345.com> wrote: >> You could let Google Chrome save your passwords. It's always asking >> to save mine... > Never! Aside from the privacy issues you're completely screwed if > the access went down or you have no internet access. Surely if one used Chrome to save passwords, one would keep a backup of those passwords somewhere else, wouldn't one?? And don't most have 2 Internet sources, home and phone? I even have a 3rd source, my neighbor's unlocked WiFi. Sometimes a neighbor's lack of security is a good thing... ;) But as always YMMV. > This has happened to lastpass users and i store offline passwords as > well as online ones. If anyone's considering a password manager > always go for one which stores them locally and does an online sync. Not a problem for us memory/sheet of passwords paper users...
[toc] | [prev] | [next] | [standalone]
| From | Chris <ithinkiam@gmail.com> |
|---|---|
| Date | 2018-11-15 22:40 +0000 |
| Message-ID | <psksl1$h1m$1@dont-email.me> |
| In reply to | #57550 |
123456789 <12345@12345.com> wrote: > On 11/15/2018 11:57 AM, chris wrote: >> 123456789 <12345@12345.com> wrote: > >>> You could let Google Chrome save your passwords. It's always asking >>> to save mine... > >> Never! Aside from the privacy issues you're completely screwed if >> the access went down or you have no internet access. > > Surely if one used Chrome to save passwords, one would keep a backup of > those passwords somewhere else, wouldn't one?? I mean if for some reason the chrome server is not available. Doesn't matter whose internet you use. >> This has happened to lastpass users and i store offline passwords as >> well as online ones. If anyone's considering a password manager >> always go for one which stores them locally and does an online sync. > > Not a problem for us memory/sheet of passwords paper users... > True
[toc] | [prev] | [next] | [standalone]
| From | 123456789 <12345@12345.com> |
|---|---|
| Date | 2018-11-15 16:06 -0700 |
| Message-ID | <psku59$phl$1@dont-email.me> |
| In reply to | #57563 |
On 11/15/2018 3:40 PM, Chris wrote: > 123456789 <12345@12345.com> wrote: >>>> You could let Google Chrome save your passwords. It's always >>>> asking to save mine... >> >>> Never! Aside from the privacy issues you're completely screwed >>> if the access went down or you have no internet access. > I mean if for some reason the chrome server is not available. > Doesn't matter whose internet you use. Ah. Chrome saves passwords locally (3 dots > Settings > Passwords). There you can make various changes. The passwords themselves are blanked but with extra confirmation you can make them visible (a fingerprint scan on my LT does it, YMMV.) So an out of whack Chrome server shouldn't be a password problem. As an aside you can also turn on password sync so that the passwords will be sent to your other Chrome browsers/devices and any PW changes are kept in sync. I find it very useful for my non-sensitive sites.
[toc] | [prev] | [next] | [standalone]
| From | Frank Slootweg <this@ddress.is.invalid> |
|---|---|
| Date | 2018-11-15 21:14 +0000 |
| Message-ID | <pskr3t.54c.1@ID-201911.user.individual.net> |
| In reply to | #57547 |
chris <ithinkiam@gmail.com> wrote: [...] You're suddenly 'chris' instead of 'Chris'. Intentional?
[toc] | [prev] | [next] | [standalone]
| From | Chris <ithinkiam@gmail.com> |
|---|---|
| Date | 2018-11-15 22:16 +0000 |
| Message-ID | <pskr8q$97j$1@dont-email.me> |
| In reply to | #57555 |
Frank Slootweg <this@ddress.is.invalid> wrote: > chris <ithinkiam@gmail.com> wrote: > [...] > > You're suddenly 'chris' instead of 'Chris'. Intentional? I used a rarely used device. I must've got my capitalisation wrong when I set up originally.
[toc] | [prev] | [next] | [standalone]
| From | Chris <ithinkiam@gmail.com> |
|---|---|
| Date | 2018-11-14 18:41 +0000 |
| Message-ID | <pshq7r$dha$1@dont-email.me> |
| In reply to | #57513 |
nospam <nospam@nospam.invalid> wrote: > In article <psgmb0$hm8$1@dont-email.me>, Chris <ithinkiam@gmail.com> > wrote: > >>>>> hijack your phone and game over. >>>> >>>> Not so easy these days. But still useless without passwords. >>> >>> it's very easy these days and getting easier. >> >> Only if the target is a fool by reusing passwords. > > that helps, but is not required. there is sufficient information about > people to pretend to be the target and pwn all sorts of stuff. > > not only are data breaches becoming more common, but people voluntarily > give out key information on various social media sites or other venues. > they usually give real answers to the insecurity questions, which is > almost always public information, including mother's maiden name, first > car that they owned, etc. > > and sometimes all that's needed is just a phone number: > <https://www.zdnet.com/article/tmobile-bug-let-anyone-see-any-customers- > account-details/> > A bug in T-Mobile's website let anyone access the personal account > details of any customer with just their cell phone number. > ... > The returned data included a customer's full name, postal address, > billing account number, and in some cases information about tax > identification numbers. The data also included customers' account > information, such as if a bill is past-due or if the customer had > their service suspended. > The data also included references to account PINs used by customers > as a security question when contacting phone support. Anyone could > use that information to hijack accounts. Irrelevant. >> A practical example of >> how not easy it is... >> http://infozonic.com/2018/11/06/operation-luigi-how-i-hacked-my-friend-without-her-noticing/ > > looks like he was successful. I didn't say otherwise. You said it was "very easy". It took this guy weeks and some quite elaborate phishing just to get access to an unused hotmail account and then eventually Twitter & LinkedIn. For someone he knew and thus would know what would work. It is far from easy and real exploiters will always focus on the low hanging fruit as it's not worth the extra effort. Do the basics and you're not going to get hacked.
[toc] | [prev] | [next] | [standalone]
| From | nospam <nospam@nospam.invalid> |
|---|---|
| Date | 2018-11-14 14:33 -0500 |
| Message-ID | <141120181433355344%nospam@nospam.invalid> |
| In reply to | #57521 |
In article <pshq7r$dha$1@dont-email.me>, Chris <ithinkiam@gmail.com> wrote: > >>>>> hijack your phone and game over. > >>>> > >>>> Not so easy these days. But still useless without passwords. > >>> > >>> it's very easy these days and getting easier. > >> > >> Only if the target is a fool by reusing passwords. > > > > that helps, but is not required. there is sufficient information about > > people to pretend to be the target and pwn all sorts of stuff. > > > > not only are data breaches becoming more common, but people voluntarily > > give out key information on various social media sites or other venues. > > they usually give real answers to the insecurity questions, which is > > almost always public information, including mother's maiden name, first > > car that they owned, etc. > > > > and sometimes all that's needed is just a phone number: > > <https://www.zdnet.com/article/tmobile-bug-let-anyone-see-any-customers- > > account-details/> > > A bug in T-Mobile's website let anyone access the personal account > > details of any customer with just their cell phone number. > > ... > > The returned data included a customer's full name, postal address, > > billing account number, and in some cases information about tax > > identification numbers. The data also included customers' account > > information, such as if a bill is past-due or if the customer had > > their service suspended. > > The data also included references to account PINs used by customers > > as a security question when contacting phone support. Anyone could > > use that information to hijack accounts. > > Irrelevant. not at all. until that exploit was disclosed, t-mobile customers were at risk of being pwned with nothing more than a phone number. anyone who has someone's (t-mobile) cellphone number (or can find out what it is with a simple search) could easily pwn someone. and if you think that's the only such exploit, think again. > >> A practical example of > >> how not easy it is... > >> > >> http://infozonic.com/2018/11/06/operation-luigi-how-i-hacked-my-friend-with > >> out-her-noticing/ > > > > looks like he was successful. > > I didn't say otherwise. You said it was "very easy". It took this guy weeks > and some quite elaborate phishing just to get access to an unused hotmail > account and then eventually Twitter & LinkedIn. For someone he knew and > thus would know what would work. that's only because he isn't particularly good at it, and was probably the very first time he tried. > It is far from easy and real exploiters will always focus on the low > hanging fruit as it's not worth the extra effort. Do the basics and you're > not going to get hacked. it requires quite a bit more than the basics to raise the bar to where one can be reasonably safe, but even then, it's still possible. however, if someone has you in their crosshairs, there's very little anyone can do. you *will* be pwned.
[toc] | [prev] | [next] | [standalone]
| From | chris <ithinkiam@gmail.com> |
|---|---|
| Date | 2018-11-15 18:57 +0000 |
| Message-ID | <pskfic$trq$2@dont-email.me> |
| In reply to | #57526 |
nospam <nospam@nospam.invalid> wrote: > In article <pshq7r$dha$1@dont-email.me>, Chris <ithinkiam@gmail.com> > wrote: > >>>>>>> hijack your phone and game over. >>>>>> >>>>>> Not so easy these days. But still useless without passwords. >>>>> >>>>> it's very easy these days and getting easier. >>>> >>>> Only if the target is a fool by reusing passwords. >>> >>> that helps, but is not required. there is sufficient information about >>> people to pretend to be the target and pwn all sorts of stuff. >>> >>> not only are data breaches becoming more common, but people voluntarily >>> give out key information on various social media sites or other venues. >>> they usually give real answers to the insecurity questions, which is >>> almost always public information, including mother's maiden name, first >>> car that they owned, etc. >>> >>> and sometimes all that's needed is just a phone number: >>> <https://www.zdnet.com/article/tmobile-bug-let-anyone-see-any-customers- >>> account-details/> >>> A bug in T-Mobile's website let anyone access the personal account >>> details of any customer with just their cell phone number. >>> ... >>> The returned data included a customer's full name, postal address, >>> billing account number, and in some cases information about tax >>> identification numbers. The data also included customers' account >>> information, such as if a bill is past-due or if the customer had >>> their service suspended. >>> The data also included references to account PINs used by customers >>> as a security question when contacting phone support. Anyone could >>> use that information to hijack accounts. >> >> Irrelevant. > > not at all. > > until that exploit was disclosed, t-mobile customers were at risk of > being pwned with nothing more than a phone number. > > anyone who has someone's (t-mobile) cellphone number (or can find out > what it is with a simple search) could easily pwn someone. > > and if you think that's the only such exploit, think again. > >>>> A practical example of >>>> how not easy it is... >>>> >>>> http://infozonic.com/2018/11/06/operation-luigi-how-i-hacked-my-friend-with >>>> out-her-noticing/ >>> >>> looks like he was successful. >> >> I didn't say otherwise. You said it was "very easy". It took this guy weeks >> and some quite elaborate phishing just to get access to an unused hotmail >> account and then eventually Twitter & LinkedIn. For someone he knew and >> thus would know what would work. > > that's only because he isn't particularly good at it, and was probably > the very first time he tried. Ok knowitall. How would you do it better? >> It is far from easy and real exploiters will always focus on the low >> hanging fruit as it's not worth the extra effort. Do the basics and you're >> not going to get hacked. > > it requires quite a bit more than the basics to raise the bar to where > one can be reasonably safe, but even then, it's still possible. No it doesn't. I don't need to outrun the Lion, i just need to outrun you. It was ever thus. If there are people who don't use 2fa then SMS 2fa is probably good enough. > however, if someone has you in their crosshairs, there's very little > anyone can do. you *will* be pwned. That's not news. It's the same offline. If someone really wants your car they will get it.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E. R." <robin_listas@es.invalid> |
|---|---|
| Date | 2018-11-13 18:48 +0100 |
| Message-ID | <g50h2nFl3a8U1@mid.individual.net> |
| In reply to | #57481 |
On 13/11/2018 16.50, Frank Slootweg wrote:
> Carlos E. R. <robin_listas@es.invalid> wrote:
>> On 13/11/2018 15.03, nospam wrote:
>>> In article <g4vborFd1mmU1@mid.individual.net>, Carlos E. R.
>>> <robin_listas@es.invalid> wrote:
>>>
>>>>>>>> It's not (only) for "credentials of forgotten logins". 123456789
>>>>>>>> mentioned quite different use for SMS, for which there is no practical
>>>>>>>> general alternative yet.
>>>>>>>
>>>>>>> there definitely is a very practical alternative, one which is also
>>>>>>> significantly more secure *and* works offline.
>>>>>>
>>>>>> Which is...?
>>>>>
>>>>> totp
>>>>>
>>>> <https://www.google.com/search?q=what+is+totp&ie=utf-8&oe=utf-8&client=firefox-
>>>> b>
>>>>
>>>> Time Based One Time Password?
>>>
>>> yes
>>>
>>>> Oh, common!
>>>
>>> very much so.
>>>
>>>> And where is the "all phones must have it out of the factory" requirement?
>>>
>>> no such requirement.
>>>
>>> there are *numerous* totp apps not just for phones, but also laptops
>>> and desktops, making it both more secure than sms and more convenient
>>> too.
>>
>> Hre it is the minimal requirement. If you want to use banks and other
>> services. It is your choice, of course: no SMS, no banking :-P
>
> Don't be a wuss, Carlos! If nospam says it can be done, it can be
> done! You just have to change banks, move to another country or similar
> minor inconviences. And when you've done that, there will be another
> problem with some other 'provider' so you once again change provider
> or/and company. Peanuts.
I know, I know. :-)))
> BTW, just for laughs have a look at the server and client
> implementations on the Wikipedia 'Time-based One-time Password
> algorithm' page to see what a total mess this "very practical
> alternative" is.
>
> <https://en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm>
>
> FYI, my bank(s) are using OTPs with proprietary tokens similar to the
> CAP readers which MC uses for their CAP. (There you have some more
> acronyms/initialisms to look up! :-)
>
> But as they're proprietary, they're obviously *not* the required
> "practical general alternative" for SMS.
Right.
The most I have seen here, and not always, are "push" messages with
Android applications. But it is an opt-in, the default is SMS. And
certainly, SMS are not really safe, I know.
But if I'm using the Android App and I have to be sent a code via
another method than the App - in order to fit the definition of two
factor auth - they are not going to send a push message via same app! So
SMS it is. But as it is the same device, the app reads automatically the
SMS, which defeats somewhat the purpose.
Well, us non rich people have to accept what we get :-p
--
Cheers,
Carlos E.R.
[toc] | [prev] | [next] | [standalone]
| From | Chris <ithinkiam@gmail.com> |
|---|---|
| Date | 2018-11-13 18:36 +0000 |
| Message-ID | <psf5k8$p4n$1@dont-email.me> |
| In reply to | #57485 |
Carlos E. R. <robin_listas@es.invalid> wrote: > On 13/11/2018 16.50, Frank Slootweg wr >> >> <https://en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm> >> >> FYI, my bank(s) are using OTPs with proprietary tokens similar to the >> CAP readers which MC uses for their CAP. (There you have some more >> acronyms/initialisms to look up! :-) >> >> But as they're proprietary, they're obviously *not* the required >> "practical general alternative" for SMS. > > Right. > > The most I have seen here, and not always, are "push" messages with > Android applications. But it is an opt-in, the default is SMS. And > certainly, SMS are not really safe, I know. > > But if I'm using the Android App and I have to be sent a code via > another method than the App - in order to fit the definition of two > factor auth - they are not going to send a push message via same app! It's not push, but pull. Use a third party authenticator app e.g authy or Google authenticator set it up with your service/website/etc job done. However, it does require that the service (i.e bank) supports the authenticator app. I'm not aware of any banks that do in the UK. Several have hardware based pin code generators which are a real PITA.
[toc] | [prev] | [next] | [standalone]
| From | Frank Slootweg <this@ddress.is.invalid> |
|---|---|
| Date | 2018-11-13 20:32 +0000 |
| Message-ID | <psffsb.bvo.1@ID-201911.user.individual.net> |
| In reply to | #57494 |
Chris <ithinkiam@gmail.com> wrote: > Carlos E. R. <robin_listas@es.invalid> wrote: > > On 13/11/2018 16.50, Frank Slootweg wr > >> > >> <https://en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm> > >> > >> FYI, my bank(s) are using OTPs with proprietary tokens similar to the > >> CAP readers which MC uses for their CAP. (There you have some more > >> acronyms/initialisms to look up! :-) > >> > >> But as they're proprietary, they're obviously *not* the required > >> "practical general alternative" for SMS. > > > > Right. > > > > The most I have seen here, and not always, are "push" messages with > > Android applications. But it is an opt-in, the default is SMS. And > > certainly, SMS are not really safe, I know. > > > > But if I'm using the Android App and I have to be sent a code via > > another method than the App - in order to fit the definition of two > > factor auth - they are not going to send a push message via same app! > > It's not push, but pull. Use a third party authenticator app e.g authy or > Google authenticator set it up with your service/website/etc job done. > However, it does require that the service (i.e bank) supports the > authenticator app. I'm not aware of any banks that do in the UK. Several > have hardware based pin code generators which are a real PITA. The problem is the "a" in "a third party authenticator app", i.e. there is not *one* "practical general alternative" (for SMS), but a zillion *different* and *incompatible* ones. My two banks already use two different, incompatible, OTP methods. I don't want to have to use yet another slew of different, incompatible, OTP methods with my other tens of providers, thank you very much. *If* and *when* the OTP mess I described (in the part before the part you quoted), settles down to one or at most two methods, then it might become an alternative. In it's current state, it a joke and a rather sad one.
[toc] | [prev] | [next] | [standalone]
| From | nospam <nospam@nospam.invalid> |
|---|---|
| Date | 2018-11-13 15:49 -0500 |
| Message-ID | <131120181549468563%nospam@nospam.invalid> |
| In reply to | #57501 |
In article <psffsb.bvo.1@ID-201911.user.individual.net>, Frank Slootweg <this@ddress.is.invalid> wrote: > > It's not push, but pull. Use a third party authenticator app e.g authy or > > Google authenticator set it up with your service/website/etc job done. > > However, it does require that the service (i.e bank) supports the > > authenticator app. I'm not aware of any banks that do in the UK. Several > > have hardware based pin code generators which are a real PITA. > > The problem is the "a" in "a third party authenticator app", i.e. > there is not *one* "practical general alternative" (for SMS), but a > zillion *different* and *incompatible* ones. except that there aren't a zillion different incompatible ones. google authenticator, microsoft authenticator, last pass, 1password, authy and others all produce the *same* totp code given the same seed (usually via qr code). use whichever app you prefer. use several of them. save or export the qr code and switch apps at any time. no issues at all.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2018-11-16 14:30 +0100 |
| Message-ID | <6dt2cf-lgc.ln1@Telcontar.valinor> |
| In reply to | #57494 |
On 13/11/2018 19.36, Chris wrote: > Carlos E. R. <robin_listas@es.invalid> wrote: >> On 13/11/2018 16.50, Frank Slootweg wr >>> >>> <https://en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm> >>> >>> FYI, my bank(s) are using OTPs with proprietary tokens similar to the >>> CAP readers which MC uses for their CAP. (There you have some more >>> acronyms/initialisms to look up! :-) >>> >>> But as they're proprietary, they're obviously *not* the required >>> "practical general alternative" for SMS. >> >> Right. >> >> The most I have seen here, and not always, are "push" messages with >> Android applications. But it is an opt-in, the default is SMS. And >> certainly, SMS are not really safe, I know. >> >> But if I'm using the Android App and I have to be sent a code via >> another method than the App - in order to fit the definition of two >> factor auth - they are not going to send a push message via same app! > > It's not push, but pull. Use a third party authenticator app e.g authy or > Google authenticator set it up with your service/website/etc job done. > However, it does require that the service (i.e bank) supports the > authenticator app. I'm not aware of any banks that do in the UK. Several > have hardware based pin code generators which are a real PITA. > I think it is called push by the app itself, which is the bank app for doing things with that particular bank, not a third party application. For instance, I want to do something on the computer, using firefox at the bank web site. Well, when I try to do some actual operation (say a money transfer) they send a code to the same bank application on my mobile phone. Otherwise, if the app is not installed, they send an SMS, which is the default. -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
| From | Frank Slootweg <this@ddress.is.invalid> |
|---|---|
| Date | 2018-11-13 15:12 +0000 |
| Message-ID | <pset5e.9u8.1@ID-201911.user.individual.net> |
| In reply to | #57448 |
Carlos E. R. <robin_listas@es.invalid> wrote: > On 13/11/2018 02.39, nospam wrote: > > In article <g4uno4F91i6U2@mid.individual.net>, Carlos E. R. > > <robin_listas@es.invalid> wrote: > > > >>>> It's not (only) for "credentials of forgotten logins". 123456789 > >>>> mentioned quite different use for SMS, for which there is no practical > >>>> general alternative yet. > >>> > >>> there definitely is a very practical alternative, one which is also > >>> significantly more secure *and* works offline. > >> > >> Which is...? > > > > totp > > <https://www.google.com/search?q=what+is+totp&ie=utf-8&oe=utf-8&client=firefox-b> > > Time Based One Time Password? > > Oh, common! > > And where is the "all phones must have it out of the factory" requirement? Be gentle with nospam! He's having problems with complex qualifiers such as "practical" and "general". And anyway, what does Top of the Pops have to do with anything!? :-)
[toc] | [prev] | [next] | [standalone]
| From | nospam <nospam@nospam.invalid> |
|---|---|
| Date | 2018-11-13 10:21 -0500 |
| Message-ID | <131120181021357058%nospam@nospam.invalid> |
| In reply to | #57477 |
In article <pset5e.9u8.1@ID-201911.user.individual.net>, Frank Slootweg <this@ddress.is.invalid> wrote: > > >>>> It's not (only) for "credentials of forgotten logins". 123456789 > > >>>> mentioned quite different use for SMS, for which there is no practical > > >>>> general alternative yet. > > >>> > > >>> there definitely is a very practical alternative, one which is also > > >>> significantly more secure *and* works offline. > > >> > > >> Which is...? > > > > > > totp > > > > <https://www.google.com/search?q=what+is+totp&ie=utf-8&oe=utf-8&client=firef > > ox-b> > > > > Time Based One Time Password? > > > > Oh, common! > > > > And where is the "all phones must have it out of the factory" requirement? > > Be gentle with nospam! He's having problems with complex qualifiers > such as "practical" and "general". not in the least, and you've now resorted to ad hominem attacks.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E. R." <robin_listas@es.invalid> |
|---|---|
| Date | 2018-11-13 18:51 +0100 |
| Message-ID | <g50h8tFl3a8U2@mid.individual.net> |
| In reply to | #57477 |
On 13/11/2018 16.12, Frank Slootweg wrote:
> Carlos E. R. <robin_listas@es.invalid> wrote:
>> On 13/11/2018 02.39, nospam wrote:
>>> In article <g4uno4F91i6U2@mid.individual.net>, Carlos E. R.
>>> <robin_listas@es.invalid> wrote:
>>>
>>>>>> It's not (only) for "credentials of forgotten logins". 123456789
>>>>>> mentioned quite different use for SMS, for which there is no practical
>>>>>> general alternative yet.
>>>>>
>>>>> there definitely is a very practical alternative, one which is also
>>>>> significantly more secure *and* works offline.
>>>>
>>>> Which is...?
>>>
>>> totp
>>
>> <https://www.google.com/search?q=what+is+totp&ie=utf-8&oe=utf-8&client=firefox-b>
>>
>> Time Based One Time Password?
>>
>> Oh, common!
>>
>> And where is the "all phones must have it out of the factory" requirement?
>
> Be gentle with nospam! He's having problems with complex qualifiers
> such as "practical" and "general".
:-)))
(not an attack; we are just having some humour at his cost :-) )
>
> And anyway, what does Top of the Pops have to do with anything!? :-)
>
X-)
--
Cheers,
Carlos E.R.
[toc] | [prev] | [next] | [standalone]
Page 4 of 9 — ← Prev page 1 2 3 [4] 5 6 7 8 9 Next page →
Back to top | Article view | comp.mobile.android
csiph-web