Tootfinder

Opt-in global Mastodon full text search. Join the index!

@theodric@social.linux.pizza
2026-02-19 19:09:33

If you're using an LLM to generate passwords, STOP. For one, your chat logs are a matter of record and are open to people within the company! For another, LLMs aren't smart and don't know what they're doing, so that password isn't guaranteed to be any good. Just use apg or something

@metacurity@infosec.exchange
2026-02-16 11:44:39

Researchers from ETH Zurich have discovered serious security vulnerabilities in three popular, cloud-based password managers. During testing, they were able to view and even make changes to stored passwords.
ethz.ch/en/news-and-events/eth

@hanno@mastodon.social
2026-04-17 17:08:12

Completely boring take on IT security in the age of AI-discovered security vulnerabilities: Everything in IT security that was a good idea before is still a good idea. When security updates are available, install them. Reduce attack surface, avoid unnecessary complexity. Don't reuse passwords.

@vyskocilm@witter.cz
2026-02-10 17:33:19

New post: Bytekit: Generating Passwords (online)
#blog

@privacity@social.linux.pizza
2026-04-10 00:59:18

"Snoopy", "Adolf" e "Password": le password del governo ungherese esposte online
Quasi 800 indirizzi e-mail del governo ungherese e le relative password stanno circolando online, rivelando vulnerabilitŠ di base nei protocolli di sicurezza dei ministeri coinvolti in attivitŠ classificate e sensibili.
Un’analisi di Bellingcat dei dati della violazione mostra che 12 dei 13 ministeri del governo sono stati colpiti, il che in alcuni casi ha rivelato le in…

@fgraver@hcommons.social
2026-03-12 16:23:48

‘Exploit every vulnerability’: rogue AI agents published passwords and overrode anti-virus software
theguardian.com/technology/ng-

@adamhotep@infosec.exchange
2026-04-17 15:23:24

RE: vis.social/@infobeautiful/1164
PIN codes, like passwords and pass phrases, are impossible for a human to randomly create. If you want a secure code, generate it. Also: use a longer code if permitted. Don't use a date, sequence, o…

@socallinuxexpo@social.linux.pizza
2026-02-13 21:25:01

jeff deifik will speak on 'Cracking Passwords Like a Boss' as part of our Security track at SCaLE 23x. Full details: socallinuxexpo.org/scale/23x

@metacurity@infosec.exchange
2026-02-05 11:40:04

It's downright weird that McDonald's is leading a campaign to advise us to use more secure passwords.
McDonald's is not lovin' your bigmac, happymeal, and mcnuggets passwords
theregister.com/2026/02/02/mcd

@publicvoit@graz.social
2026-03-02 17:12:30

I've got 1237 entries in my #KeePassXC storage at the moment.
Don't tell me you're remembering all your #passwords and still have a unique one (without obvious patterns) per service. 😜
Use an open source

@michabbb@social.vivaldi.net
2026-04-12 23:16:00

🤡 No joke – this is literally how the industry works:
1. Company sends me an NDA 📝
2. Then they email me login credentials – plain text, no temporary link, nothing… and four people in CC ✉️
Honestly, the fact that like 99% of companies still send passwords via email is insane. You can only imagine what other security issues they have.
And when they eventually get hacked, they’ll tell their insurance:
"We did everything in our power to… blah blah blah…"

@Techmeme@techhub.social
2026-04-07 16:25:54

The UK says Russia-linked hacking group APT28 is hijacking popular internet routers from MikroTik, TP-Link, and others to steal credentials and redirect traffic (Ryan Gallagher/Bloomberg)
bloomberg.com/news/articles/20

@metacurity@infosec.exchange
2026-01-23 11:42:28

149 Million Usernames and Passwords Exposed by Unsecured Database
wired.com/story/149-million-st

@thomasfuchs@hachyderm.io
2026-01-27 21:56:05

So what’s good alternative to Firefox?
I need something for Windows and iOS and it should sync passwords. Ideally not Chromium-based and obviously no AI slop.

@TFG@social.linux.pizza
2026-02-09 11:19:11

TIL:
If you have your Samsung T7 Touch SSD encrypted with a password (and maybe a fingerprint) ..and you want to remove the encryption (or delete/change password/fingerprint).... Your device (MS Win) has to be connected to the internet. Otherwise the neccessary software just hangs after unlocking the SSD.
WTAF Samsung. For real.
This lead me to two questions:
1. What are the odds that passwords and fingerprints are casually transfered to some Samsung service? (Rhetor…

@curiouscat@fosstodon.org
2026-04-09 23:02:26

Threats Against Routers
"The FBI, NSA, and co-sealing agencies encourage SOHO router users to change default usernames and passwords, disable remote management interfaces from the Internet, update to latest firmware versions, and upgrade end-of-support devices. Users should also carefully consider certificate warnings in web browsers and email clients."

@ErikJonker@mastodon.social
2026-01-30 08:07:43

Moltbot is like giving some stranger you can't really trust access to all your data, communications, passwords, your computer etc.. It is maybe fascinating but just don't do it..... The large AI players can already build this for a long time but there is a reason they are not doing it....

@metacurity@infosec.exchange
2026-02-13 12:20:31

Just in time for Valentine's Day, you can share your password with your partner, but I would reconsider if I were you. It's OK to keep something private.
Bitwarden has launched a new system called ‘Cupid Vault’ that allows users to safely share passwords with trusted email addresses.

@chris@mstdn.chrisalemany.ca
2026-02-25 17:28:58

Wow, so 1Password has increased its already expensive services. I have only used it for work/volunteer related stuff. I've been using Apple's Keychain and now Passwords App for years.
If you're on a Mac/iOS system and want to switch, 9to5 has a good run down on how to export your 1Password database and bring it into Passwords.
if you've never used a Password Manager, you really really should.
#Security #Passwords #Apple #1Password #PasswordManager
9to5mac.com/2026/02/25/heres-h

@frankel@mastodon.top
2026-02-26 09:02:43

#PasswordManagers less secure than promised
ethz.ch/en/news-and-events/eth

@jswright61@ruby.social
2026-04-01 11:33:21

#LeftWordle
Would you like to track streaks and stats in Left Wordle across multiple devices?
Would you use a Passkey for this purpose? Passkeys would allow users to stay anonymous (or provide an email for recovery if desired), and they wouldn’t require sensitive info (passwords) to be stored on the server.
The option to play and store data in your browser, the way it works toda…

@al3x@hachyderm.io
2026-02-27 16:19:57

@… when you switched to Chrome, part of the simplicity is that tou are using 1Password and not Apple Passwords, right?
I might have missed it when you said what password manager you’re using and I don’t want to mix it up with the reading of ads

@hanno@mastodon.social
2026-04-03 06:05:51

Not sure if this is a hot take, but: I believe most WiFi passwords serve no meaningful purpose and are actively harmful to security.
You all know how this works. You're in a hotel, at a conference, in a restaurant, etc., you want to connect to the wifi. There's probably a sign somewhere with the password.
First of all, it's annoying that you have to figure out where to find it, ask around if anyone knows it.
🧵

@metacurity@infosec.exchange
2026-01-23 16:25:56

Before you head out for the weekend, don't miss today's Metacurity for the crucial cybersecurity developments you should know, including
--A database with 149 million usernames and passwords was exposed on the internet,
--Venezuelan nationals who stole cash from ATMs using malware will be deported from US,
--FBI asked Microsoft to unlock encrypted laptops,
--Under Armour is investigating massive data breach,
--Tech investors want the US government to prob…

@hanno@mastodon.social
2026-04-03 06:05:51

Not sure if this is a hot take, but: I believe most WiFi passwords serve no meaningful purpose and are actively harmful to security.
You all know how this works. You're in a hotel, at a conference, in a restaurant, etc., you want to connect to the wifi. There's probably a sign somewhere with the password.
First of all, it's annoying that you have to figure out where to find it, ask around if anyone knows it.
🧵

@metacurity@infosec.exchange
2026-02-10 14:13:08

Metacurity operates outside the infosec news echo chamber to track patterns, context, and connections that most other sources miss.
Check out today's issue for the most critical developments you should know, including
--Defense companies face a 'relentless barrage' of cyberespionage, Google,
--Fugitive sentenced to 2 years for pig butchering money laundering,
--Coupang data breach scope was more massive than reported,
--Discord to demand face scans or…

@michabbb@social.vivaldi.net
2026-04-02 08:28:09

🤖 AI-native #CMS: built-in #MCP server, CLI & Agent Skills — let agents handle migrations, schema changes and content updates programmatically.
🔑 Passkey auth by default — no passwords, no brute-force vectors. Role-based access for admins, editors,
authors & contributors.
📦 Im…

@al3x@hachyderm.io
2026-02-26 08:43:20

Can anyone share & teach me how to use #macOS Keychain to manage software keys?
Applications like Bitwarden, 1Password, etc. offer specific categories in their apps to manage licenses and keys.
#macOS Passwords offers nothing like that. Obviously.

@hanno@mastodon.social
2026-04-03 06:11:05

But why actively harmful?
You're conditioning people to treat a "password" not like a secret. If you missed the sign at the entrance, you'll ask the next person for the wifi password. And, of course, they'll usually give it to you.
That's obviously not how you should treat passwords.
We call a thing a "password" if it serves a security purpose, locks access to something that's for you, not for random other people. We probably shouldn&…

@khalidabuhakmeh@mastodon.social
2026-03-24 13:08:55

We're doing a #livestream today around a first look at our User Management library here at Duende. Think of it as an alternative to #aspnetcore Identity. It let's you manage users (shocking I know 😅), and their profile, passwords, auth mechanisms, and more.

@metacurity@infosec.exchange
2026-04-08 13:42:21

Someday, I will send out a Metacurity email that doesn't get clipped by Gmail for having too much information, but that day is not today.
Check out today's intensely packed Metacurity that covers a host of critical infosec developments, including
--Iran-linked hackers target critical infrastructure controls, risking disruption and sabotage,
--Anthropic's Glasswing could upend bug discovery and fixes,
--GRU-linked hackers infiltrate routers to steal email a…

@ErikJonker@mastodon.social
2026-01-30 08:07:43

Moltbot is like giving some stranger you can't really trust access to all your data, communications, passwords, your computer etc.. It is maybe fascinating but just don't do it..... The large AI players can already build this for a long time but there is a reason they are not doing it....

@teledyn@mstdn.ca
2026-03-29 17:09:49

something I didn't need for a Sunday morning: my #Ubuntu 25.10 media machine will no longer login via gdm3 since the last upgrade, I can use a console to run gnome-shell -wayland without issue, but the gdm3 (even re-installed) just returns to the list of users and after the first attempt will no longer offer to enter passwords and hangs.
I did inadvertently leave my keyboard unlocked and two cats in the house left unattended, but it was logged into the guest account, so I doubt they did this 😅
Curiously their snap-edition "firefox -kiosk <url>" now also hangs.
I don't want to spend too much on this: as soon as no.4 son drops by to unlock the broken Win10 and fetch his stuff, I will wipe the thing to install Debian 13 anyway.

@pre@boing.world
2026-03-28 19:49:41

One machine decided literally today when booting that it's bit-defender key was invalidated and refused to boot.
I thought bit-defender was a password manager? No idea why the machine has decided secure boot changed and it needed this key which nobody has ever heard of, even me a computer professional.
I think maybe Bit Defender is a boot-disk encryption system not a password manager after all?
It suggests checking with your Microsoft account to get the key. Nobody thinks they have a microsoft account, even though they do. Nobody knows any passwords for them.
Password reset, sure, but nobody knows their email password either. They never use email.
Google once lied to them that their password was wrong, and made them change it. But banned them from changing it to any old one that they actually know. It must be a new one they don't know. They wrote some down, but probably these are old ones and there's several different ones written down.
We get through all that with recovery methods for email address, luckily one phone was still logged in to read a reset email.
This bit defender key is attached to the account and I have to hand-type a 32 digit number from one screen to another.
My god.
If you only have one computer, then fuck you I guess.

@metacurity@infosec.exchange
2026-03-20 20:54:23

California city reports ransomware attack as LA transit agency finds ‘unauthorized activity’
therecord.media/california-cit