2026-06-30 15:14:55
I would really like passkey advocates to lay out in full how one helps elderly parents once they switch to passkeys. (Can be done; not trivial. This article rambles about YubiKeys—like typical customers need one—while entirely missing this disadvantage.)
https://www.nytimes.com/wirecutter/reviews
While passkeys are an improvement on passwords in security terms, they are not perfect, and there are inevitable trade‑offs in their implementation.
https://www.computing.co.uk/analysis/2026/
Get your #passwords out of #BitWarden while you still can
https://www.osnews.com/story/…
Passkeys Explained: Are They Actually Better Than Passwords? by Addie LaMarr
https://www.youtube.com/watch?v=1nnOvYHwweE
Apple unveils an Apple Intelligence feature that can automatically change compromised passwords, using agentic AI, and save them to the Passwords app (James Pero/Gizmodo)
https://gizmodo.com/apple-intelligence-can-change-your-passwords-…
It's so wild to me that people have professionals install their WiFi and just never get the passwords for their routers. Like, I get the whole "I just want to pay for an appliance and never think about it" thing, but by definition it's locked down and so you can't have someone ELSE fix it.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
has been leaving the digital keys to its own cloud storage accounts sitting out in the open, in plain text form,
for some unknown amount of time,
according to a report from Krebs on Security.
The problem finally got fixed over the weekend, the report says.
The repository was reportedly named “Private-CISA.”
The contents included passwords, keys, and tokens
—and the passwords were plain …
“One of the exposed files, titled ‘importantAWStokens,’ included the administrative credentials to three Amazon AWS GovCloud servers. Another file exposed in their public GitHub repository — ‘AWS-Workspace-Firefox-Passwords.csv’ — listed plaintext usernames and passwords for dozens of internal CISA systems. According to Caturegli, those system[s] included one called ‘LZ-DSO,’ which appears short for ‘Landing Zone DevSecOps,’ the agency’s secure code development environment.”
1Password launches a new Claude integration for Mac that lets Anthropic's AI agent sign in to websites without seeing the user's password or 2FA code (Zac Hall/9to5Mac)
https://9to5mac.com/2026/07/16/1password-now-lets-claud…
Is there anyone I know using Vivaldi on iOS and *never* having issues autocompleting passwords from Apple Passwords?
#🙌
#Microsoft #Edge Stores All Saved #Passwords in Cleartext Process Memory at Launch
All the passwords were stored in Active Directory description fields
https://www.theregister.com/security/2026/06/04/all-the-passwords-were-stored-in-active-directory-description-fields/5250820
&quo…
«Security — 60% of MD5 password hashes are crackable in under an hour:
Happy World Password Day! Maybe it's finally time to kill this holiday in favor of World No-More-Passwords Day?»
I don't want to know where MD5 is still being used for services in the background. The dark side is certainly bigger than we assume.
🔓
World leaders want American AI. They just don’t want America to be able to turn it off
https://techcrunch.com/2026/06/17/cybercriminals-allegedly-hacked-tens-of-thousands-of-fortinet-firewall…
Man, the ACM website -- the Association for Computing Machinery's site -- is so confusing with all the usernames and accounts.
I am trying to subscribe to one of their mailing lists and it's asking me for an email address and a password. As an ACM member, I have an @acm.org email; my account also knows about my Macalester email, and my newer St. Olaf email. I have tried all of those, and all the various passwords in my password manager. None work.
If only, somehow, someo…
I am a developer and I have never been told to use a cloud AI for anything. I was told to only use Copilot if I was to use one, though. That makes sense to me because copilot through the o365 tenant has extra data protections. I'm guessing that someone out there is uploading passwords and keys to a cloud AI.
Website: Please register for an account
qbi: OK, Username: foo and Passwort: "EEbkVt3nAqdUsgtuUgbX5wjW".
Webseite: "Passwords must have at least one non letter or digit character."
qbi: 🤔
general IT screaming.....
it's not hard to save your passwords securely people! You are Professionals. Save a unique password for every website!
Oh god I have been putting off fixing my passwords for too long.
This is a godsend.
Auto change passwords is really cool. No snark. @…
Multiple high profile website breaches over the years mean cybercriminals already have your personal data, including things as sensitive as passwords and Social Security numbers. It's too late to hide from them, but you can be prepared for them.
https://cybersecuritysimplified.subst…
The Spood And Matt Show
Expect stories, kids, mates, work, travel, terrible passwords, accidental forklift purchases, and the occasional Japanese ryokan dance party...
Great Australian Pods Podcast Directory: https://www.greataustralianpods.com/the-spood-and-matt-show…
Una pšgina muy interesante para leer... #noChatControl #chatControl #ExitChatControl
I still don't understand why you'd want an AI web browser. https://thenextweb.com/news/bioshocking-ai-browser-credential-leak-layerx
RE: https://aus.social/@slevelt/116717340602235855
Any password you store in the Passwords app may be changed without your knowledge.
You may lose access to your existing web accounts outside of Apple devices.
IANAL, but this may be a crime in some …
Ente's Legacy Kit looks like an interesting new tool!
https://ente.com/blog/legacy-kit/
"Ente Locker is for the practical parts of a life: IDs, insurance papers, medical records, passwords, notes, and the documents someone may need in your absence.
Since launch, we learned that som…
The idea that the KeePassXC database with your passwords is within your own ecosystem, and not on someone else's computer, is absolutely worth the minor hoops you have to crawl through.
#keepassxc
A very, very obscure nerdy cool thing:
When installing Ubuntu, you can choose to set up ssh -- and there's now a feature where it downloads your ssh keys from GitHub! Just give it a username.
This may just be with Ubuntu Server, but it's really nice, since you can install ssh without password auth and never need to actually log into the machine from the terminal to import ssh keys, or allow passwords and then later turn them off.
Even better would be some local vers…
AdaptHealth says attackers used social engineering to breach its systems
and steal sensitive patient data,
including passwords associated with insurance billing.
The medical equipment company disclosed the attack to the Securities and Exchange Commission (SEC) on Thursday,
noting that attackers accessed internal patient management systems, document storage platforms,
and external electronic health record system portals.
The attack targeted an unwitting thi…
CISA says weak security controls around the use of public GitHub repos allowed a contractor to accidentally leak private cloud access keys and other credentials (Eric Geller/Cybersecurity Dive)
https://www.cybersecuritydive.com/news/cisa-github-pas…
Notice: Meta says ~20,000 Instagram accounts may have been hacked in a recent attack that abused an AI-powered account recovery support tool to reset passwords (Eduard Kovacs/SecurityWeek)
https://www.securityweek.com/meta-says-20000-instagram-accoun…
Apple announces new Apple Intelligence features for its apps, including a Notify Me feature in Safari and a Call Context feature in the Phone app (John Quintet/iPhone in Canada)
https://www.iphoneincanada.ca/2026/06/08/safari-ga…