privacyguides

This magazine is from a federated server and may be incomplete. Browse more on the original instance.

badgrandpa, in Where to store OTP tokens
@badgrandpa@lemmy.world avatar

Yuibkey authenticator app looks good. All tokens are in the hardkey.

Toneswirly, in Perfectly legal for cars to harvest your texts, call logs

If this is legal, then hacking it to take it out should be legal.

PleasantAura, (edited )

No, because if every piece of your entire existence isn’t dedicated to making profit for the upper class, your life is worthless, and anything that devalues the profit they could make from you is stealing.

To be clear, I’m not saying you’re wrong, just expressing frustration at the current state of the world.

CJOtheReal, in If you can create a Lemmy instance and federate, you can shovel data about every vote linked to an account

Since there isn’t a Karma system i don’t think its a problem unless advertisers federate.

petrescatraian, in If you can create a Lemmy instance and federate, you can shovel data about every vote linked to an account

@andrew_bidlaw You can simply see this data on any Friendica instance if you have an account. Just hover your mouse over the like/dislike numbers, and you can see who upvoted/downvoted shit. You can even receive notifications about this on your own posts, just as on Facebook.

To me, it was funny back in the day to see all tankies brigading to downvote me on any single post or comment I made, the moment I started showing my political stances 😆 (yes, even stuff posted before that had no political stuff in them, lol). But yea. To some people, this might be a drawback.

The good thing, however, is that neither Kbin nor Friendica show you a centralized place in your profile to see what did you downvote. You just have to search every post you can find to see this info.

cooopsspace, in Where to store OTP tokens

Hardware keys for everything. Bitwarden for the rest.

capital, in Where to store OTP tokens

I throw them all in Bitwarden which is protected with a long, unique password and a yubikey.

kniescherz,

Same. Maximum comfort since Bitwarden autofills and puts the token in your clipboard, you dont have to change apps or need you smartphone when you are on desktop.

You are less secure though, but its worth it to me.

Xirup, in Where to store OTP tokens

In the case of Keepass, it is commonly said that it is best to have a database exclusively for your OTP.

For example, you have your passwords in a db called “My passwords” with an exclusive encryption password, and then another db called “My OTP’s” with its own encryption password, so if someone somehow get access to one, that person still won’t have access to the other, and therefore cannot enter your account.

SweetMylk,

Then use the same password for both for the sake of convenience.

rhythmisaprancer, in Perfectly legal for cars to harvest your texts, call logs
@rhythmisaprancer@kbin.social avatar

This, and the other things I read about (like subscriptions for heated seats) are what will lead to some bizarre third party hack market for cars. Instead of taking a new vehicle to a place for custom pinstriping or whatever, folks will get them privatized.

Anticorp,

Ideally people just don’t buy cars that require subscriptions. That’s what happened with BMW’s terrible subscription model and BMW stopped doing that shit. The only way to make companies stop doing shitty things is to stop giving them money when they do those things.

thanksforallthefish, in Thoughts on this Reddit post claiming 'Lemmy doesn't care about privacy'?

Slanted but accurate.

Neither Lemmy nor Reddit are private, they’re both publicly indexable (google et al).

On the other hand reddit goes to a lot of trouble to capture everything about you. Lemmy is not quite that greedy.

One is a for profit willing to do whatever it takes to make a buck. The other is FOSS and run by volunteers.

I think it’s pretty clear which is the greater threat.

JohnDClay, in Perfectly legal for cars to harvest your texts, call logs

Is android auto harvesting data to the car manufacturers, or just the first party replacements?

Schlemmy, in Perfectly legal for cars to harvest your texts, call logs

It’s not in the EU

Tibert, in Where to store OTP tokens

Well, the whole point of otp tokens/2fa, is to have a second login confirmation. Mostly on another device, like a phone.

Now maybe if you store your 2fa way on the same device, but locked away with a strong password, it may work, and could be safe enough.

But if it’s the same password as your device or another account, it isn’t that safe.

ReversalHatchery, in Why Not Store Encrypted Emails in Plaintext Locally?

Protonmail now supports searching in the content of all your mail, though.
Or at least the web client. It will ask you to download all your mail, and it will make an encrypted search index on your computer.

spookedbyroaches,

That’s cool but I like to have a central client for all my email providers. I’ve decided to go to fastmail which is good enough for my threat model. The thing that really convinced me is their blog post.

The main thing I care about is the security of the text in transit, and the philosophy of the service I’m using. All respectable mail providers use TLS (even gmail and outlook) but I don’t like their advertiser dependent business model. Proton, tutanota, and I think startmail do respect privacy, but I believe it’s dumb to depend on an external server if you’re that paranoid about your communications that you need to have your email using PGP. Just encrypt your own stuff and tell the other party to do the same. Or self host everything.

ReversalHatchery,

fastmail

That’s a paid service, right? I don’t know much about them, they may have other pros too, but proton also allows you to use your own email client if you’re in a plan.

randombullet, in Where to store OTP tokens

Aegis with the password in a YubiKey.

My password manager and I don’t know the password.

badgrandpa, in Where to store OTP tokens
@badgrandpa@lemmy.world avatar

I might keep the in Bitwarden, then secured with hardware key.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • privacyguides@lemmy.one
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #