Skip to content

Most privacy / security focused password manager

Unsolved Privacy
12 4 1.4k 1

Related Topics
  • Ex GCHQ employee risk to national security

    Discussion gchq security
    4
    1 Votes
    4 Posts
    738 Views
    @phenomlab said in Ex GCHQ employee risk to national security: I can’t believe also that security is so lax that someone without adequate clearance can waltz into a restricted area and take what they want. Yeah I can’t believe that either. It is crazy
  • OKTA offering personal password manager

    General okta password manager
    31
    18 Votes
    31 Posts
    5k Views
    @Madchatthew yes, works well for us.
  • 0 Votes
    3 Posts
    608 Views
    @Madchatthew feel free! You never know
  • 12 Votes
    8 Posts
    2k Views
    @crazycells good question. Gmail being provided by Google is going to be one of the more secure by default out of the box, although you have to bear in mind that you can have the best security in the world, but that is easily diluted by user decision. Obviously, it makes sense to secure all cloud based services with at least 2fa protection, or better still, biometric if available, but email still remains vastly unprotected (unless enforced in the sense of 2fa, which I know Sendgrid do) because of user choice (in the sense that users will always go for the path of least resistance when it comes to security to make their lives easier). The ultimate side effect of taking this route is being vulnerable to credentials theft via phishing attacks and social engineering. The same principle would easily apply to Proton Mail, who also (from memory) do not enforce 2fa. Based on this fact, neither product is more secure than the other without one form of additional authentication at least being imposed. In terms of direct attack on the servers holding mail accounts themselves, this is a far less common type of attack these days as tricking the user is so much simpler than brute forcing a server where you are very likely to be detected by perimeter security (IDS / IPS etc).
  • 5 Votes
    4 Posts
    878 Views
    @DownPW here. Hostrisk is automated and doesn’t accept registrations.
  • 4 Votes
    3 Posts
    2k Views
    @phenomlab No they have a free and pro console instance. We can see alert with IP, Source AS, scenario attack etc… Installation on the NODEBB server without problems. Very good tools [image: 1668812242411-cf7e5a89-84f4-435b-82eb-434c0bfc895e-image.png] [image: 1668811810555-cc82a10e-a1f1-4fd8-a433-7c9b2d31f254-image.png] [image: 1668811841819-1b7147b0-37c6-4d87-b4f1-a0fe92e74afd-image.png] [image: 1668811924623-7c21fc10-1825-48e1-a993-92b84455f074-image.png] – We can also do research on IPs via the crowdsec analyzer I believe it’s 500 per month in the Free version [image: 1668812069082-43bc8265-a57c-4439-829c-0bb8602d99b4-image.png]
  • Addressing vulnerability management

    Blog security vulnerability
    1
    1
    0 Votes
    1 Posts
    582 Views
    No one has replied
  • is my DMARC configured correctly?

    Solved Configure
    3
    2
    3 Votes
    3 Posts
    1k Views
    @phenomlab said in is my DMARC configured correctly?: you’ll get one from every domain that receives email from yours. Today I have received another mail from outlook DMARC, i was referring to your reply again and found it very helpful/informative. thanks again. I wish sudonix 100 more great years ahead!