Gentoo Archives: gentoo-user

From: Dale <rdalek1967@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Questions about hacked sites and passwords
Date: Tue, 17 Jan 2012 11:32:01
Message-Id: 4F155B93.9090006@gmail.com
In Reply to: Re: [gentoo-user] Questions about hacked sites and passwords by Neil Bothwick
1 Neil Bothwick wrote:
2 > On Tue, 17 Jan 2012 04:27:09 -0600, Dale wrote:
3 >
4 >>>> I use Lastpass which does about the same as other password
5 >>>> managers.
6 >>> Doesn't LastPass store your passwords on their servers, and weren't
7 >>> they compromised last year? I'll stick with KeePassX, the password
8 >>> database is stored and encrypted locally. Even if I put it on
9 >>> DropBox, hacking that will only give the encrypted database.
10 >>>
11 >>>
12 >> None of the passwords were lost tho.
13 > This time.
14
15 And maybe not the next time either, or the next time, or the next time.
16 Point is, can you state for a fact that no site will ever be broke into,
17 ever?
18
19 >
20 >> They got everyone to change them
21 >> just in case but according to what I read, the hackers didn't get
22 >> anything.
23 > This time.
24
25 See above.
26
27 >
28 >> Keep in mind, they are encrypted locally, then sent to
29 >> them. They can't see the passwords either.
30 > How is it encrypted? If the encryption system is not open source, it is
31 > not trustworthy.
32
33 The guy that owns it posted on this list a good while back. This was
34 before the hack job. According to the things I have read, it has been
35 improved even more than it was. I agree open source can be good but
36 that doesn't mean closed can't be since we don't know what it does. If
37 we don't know, neither does the hackers.
38
39 >
40 >> So, Lastpass is basically the same thing you use. It just has a
41 >> different name. lol
42 > Not really.
43 >
44 > I wouldn't store my banking passwords anywhere online, in fact I cannot
45 > access my bank account with password alone. I also need my debit card,
46 > PIN and the card reader they supply. This generates one-time password
47 > using my card's details and no online component. I realise that card
48 > security is not the greatest, but if they've got my card and PIN, I'm
49 > screwed anyway.
50 >
51 >
52
53
54 Well, if I understand what you call a dropbox, that is online. I have
55 never used it so I have no idea.
56
57 My bank doesn't have all that. Honestly, until it is absolutely needed,
58 I wouldn't want to go through all that just to see if I have enough
59 money to buy milk. :/
60
61 Dale
62
63 :-) :-)
64
65 --
66 I am only responsible for what I said ... Not for what you understood or how you interpreted my words!
67
68 Miss the compile output? Hint:
69 EMERGE_DEFAULT_OPTS="--quiet-build=n"

Replies

Subject Author
Re: [gentoo-user] Questions about hacked sites and passwords Florian Philipp <lists@×××××××××××.net>
Re: [gentoo-user] Questions about hacked sites and passwords Neil Bothwick <neil@××××××××××.uk>