#roboform — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #roboform, aggregated by home.social.
-
Passwortmanager sind angreifbar. Das fand Marek Tóth heraus und berichtete darüber auf der #DefCon33:
https://marektoth.com/blog/dom-based-extension-clickjacking/
Die von Tóth aufgedeckten Schwachstellen ermöglichen es Hackern, sensible Daten aus Passwort-Managern zu stehlen, darunter Kreditkartendaten, Namen, Adressen und Telefonnummern, wenn ein Opfer eine bösartige Website besucht. Darüber hinaus können Hacker, wenn eine anfällige Website, auf der Ihre Passwort-Manager-Anmeldedaten gespeichert sind, eine Cross-Site-Scripting-Schwachstelle (XSS) oder eine Subdomain-Übernahme aufweist, diese ausnutzen, um Anmeldedaten (Benutzernamen und Passwörter), 2FA-Codes und Passkeys zu stehlen.
Nach Updates gelten inzwischen folgende Passwortmanager als sicher: #Bitwarden #Dashlane, #Keeper, #NordPass, #ProtonPass & #RoboForm.#infosec #passwortmanager #2FA#security #privacy #BeDiS
-
Passwortmanager sind angreifbar. Das fand Marek Tóth heraus und berichtete darüber auf der #DefCon33:
https://marektoth.com/blog/dom-based-extension-clickjacking/
Die von Tóth aufgedeckten Schwachstellen ermöglichen es Hackern, sensible Daten aus Passwort-Managern zu stehlen, darunter Kreditkartendaten, Namen, Adressen und Telefonnummern, wenn ein Opfer eine bösartige Website besucht. Darüber hinaus können Hacker, wenn eine anfällige Website, auf der Ihre Passwort-Manager-Anmeldedaten gespeichert sind, eine Cross-Site-Scripting-Schwachstelle (XSS) oder eine Subdomain-Übernahme aufweist, diese ausnutzen, um Anmeldedaten (Benutzernamen und Passwörter), 2FA-Codes und Passkeys zu stehlen.
Nach Updates gelten inzwischen folgende Passwortmanager als sicher: #Bitwarden #Dashlane, #Keeper, #NordPass, #ProtonPass & #RoboForm.#infosec #passwortmanager #2FA#security #privacy #BeDiS
-
Passwortmanager sind angreifbar. Das fand Marek Tóth heraus und berichtete darüber auf der #DefCon33:
https://marektoth.com/blog/dom-based-extension-clickjacking/
Die von Tóth aufgedeckten Schwachstellen ermöglichen es Hackern, sensible Daten aus Passwort-Managern zu stehlen, darunter Kreditkartendaten, Namen, Adressen und Telefonnummern, wenn ein Opfer eine bösartige Website besucht. Darüber hinaus können Hacker, wenn eine anfällige Website, auf der Ihre Passwort-Manager-Anmeldedaten gespeichert sind, eine Cross-Site-Scripting-Schwachstelle (XSS) oder eine Subdomain-Übernahme aufweist, diese ausnutzen, um Anmeldedaten (Benutzernamen und Passwörter), 2FA-Codes und Passkeys zu stehlen.
Nach Updates gelten inzwischen folgende Passwortmanager als sicher: #Bitwarden #Dashlane, #Keeper, #NordPass, #ProtonPass & #RoboForm.#infosec #passwortmanager #2FA#security #privacy #BeDiS
-
Passwortmanager sind angreifbar. Das fand Marek Tóth heraus und berichtete darüber auf der #DefCon33:
https://marektoth.com/blog/dom-based-extension-clickjacking/
Die von Tóth aufgedeckten Schwachstellen ermöglichen es Hackern, sensible Daten aus Passwort-Managern zu stehlen, darunter Kreditkartendaten, Namen, Adressen und Telefonnummern, wenn ein Opfer eine bösartige Website besucht. Darüber hinaus können Hacker, wenn eine anfällige Website, auf der Ihre Passwort-Manager-Anmeldedaten gespeichert sind, eine Cross-Site-Scripting-Schwachstelle (XSS) oder eine Subdomain-Übernahme aufweist, diese ausnutzen, um Anmeldedaten (Benutzernamen und Passwörter), 2FA-Codes und Passkeys zu stehlen.
Nach Updates gelten inzwischen folgende Passwortmanager als sicher: #Bitwarden #Dashlane, #Keeper, #NordPass, #ProtonPass & #RoboForm.#infosec #passwortmanager #2FA#security #privacy #BeDiS
-
Passwortmanager sind angreifbar. Das fand Marek Tóth heraus und berichtete darüber auf der #DefCon33:
https://marektoth.com/blog/dom-based-extension-clickjacking/
Die von Tóth aufgedeckten Schwachstellen ermöglichen es Hackern, sensible Daten aus Passwort-Managern zu stehlen, darunter Kreditkartendaten, Namen, Adressen und Telefonnummern, wenn ein Opfer eine bösartige Website besucht. Darüber hinaus können Hacker, wenn eine anfällige Website, auf der Ihre Passwort-Manager-Anmeldedaten gespeichert sind, eine Cross-Site-Scripting-Schwachstelle (XSS) oder eine Subdomain-Übernahme aufweist, diese ausnutzen, um Anmeldedaten (Benutzernamen und Passwörter), 2FA-Codes und Passkeys zu stehlen.
Nach Updates gelten inzwischen folgende Passwortmanager als sicher: #Bitwarden #Dashlane, #Keeper, #NordPass, #ProtonPass & #RoboForm.#infosec #passwortmanager #2FA#security #privacy #BeDiS
-
Secure your online world with RoboForm Password Manager, the ultimate tool for keeping your credentials safe and accessible! Enjoy one-click logins, cross-device syncing, and military-grade encryption to protect against cyber threats. Don't miss out on our limited-time deals—take control of your digital security today! #CyberSecurity #PasswordManager #StaySafeOnline #RoboForm
https://livingsafeonline.com/product/roboform-password-manager/ -
-2-
Joe and Bruno's Guide to Hacking Time: Regenerating Passwords from RoboForm's Password GeneratorWhen Joe started talking about RoboForm and cracking password generators, something clicked — I remembered watching a Youtube video about abusing random number generation to unlock a bitcoin wallet worth millions...
Turns out, it was Joe and Bruno’s video! It’s incredibly well-edited, and you should definitely watch it right after the DEFCON talk (though it spoils the ending a little 😉): https://www.youtube.com/watch?v=o5IySpAkThg
The talk dives into pseudo-random number generators (PRNGs) — software that takes an initial seed to generate a sequence of random numbers. If the generator doesn’t use real randomness (like lava lamps, for example), knowing the initial seed lets you predict all the numbers it will generate, including passwords.
RoboForm, a well-known password generator, used to rely on the current time as its seed — specifically a Unix timestamp in seconds. Unfortunately, this means that the number of passwords that can possibly be generated given a time frame is relatively small. This means that if you know roughly when a password was generated and its options (like length, capitals, symbols), you could easily brute-force all possible passwords in that timeframe.
Joe and Bruno exploited this exact idea! They knew (from the wallet’s owner) when the password was generated and the generation options. They reverse-engineered the RoboForm app, found a way to iteratively change the system time, and hooked into the code to regenerate the password as if it was created back then.
They managed to generate around 1,000 passwords per second, and within hours, they cracked open the wallet!
https://www.youtube.com/watch?v=N2eKCAzM2kw
#DEFCON
#Passwords
#RoboForm
#HackingTime -
Gestor de contraseñas y 2FA ROBOFORM -> https://burp.es/gestor-de-contrasenas-y-2fa-roboform/
#roboform -
Gestor de contraseñas y 2FA ROBOFORM -> https://burp.es/gestor-de-contrasenas-y-2fa-roboform/
#roboform -
Probando el gestor de contraseñas RoboForm. Muy, muy bien de momento.
-
Probando el gestor de contraseñas RoboForm. Muy, muy bien de momento.
-
Security Week 2423: о плохих генераторах случайных чисел и пароле к криптокошельку
«Взлом» криптокошелька, пароль к которому был утерян больше 10 лет назад, — это самая красивая история по теме кибербезопасности на прошлой неделе. Пожелавший остаться анонимным пользователь приобрел биткоины на сумму примерно 4000 евро в 2013 году. Криптовалюта хранилась в цифровом кошельке, доступ к которому был защищен паролем. Известный исследователь Джо Гранд на пару с коллегой помогли владельцу криптокошелька восстановить пароль, и не при помощи простого перебора, а, как правильно отметили в обсуждении на Хабре, «решив проблему мозгами». Джо Гранд любит подавать свои истории красиво, он снял видео и дал интервью журналу Wired, где использовал красивые и понятные более широкой аудитории метафоры типа «мы нашли способ повернуть время вспять». Реально интересная техническая информация этой работы, впрочем, уместилась на одну страницу текстом . Для облегчения «взлома» криптокошелька хакерам требовалось уменьшить количество возможных вариаций пароля для перебора. Им удалось это сделать благодаря одной особенности программы RoboForm, которую владелец кошелька использовал для генерации пароля. И это, пожалуй, самое интересное: анализ старой версии RoboForm показывает нам пример, как не надо генерировать случайные последовательности символов.
-
Security Week 2423: о плохих генераторах случайных чисел и пароле к криптокошельку
«Взлом» криптокошелька, пароль к которому был утерян больше 10 лет назад, — это самая красивая история по теме кибербезопасности на прошлой неделе. Пожелавший остаться анонимным пользователь приобрел биткоины на сумму примерно 4000 евро в 2013 году. Криптовалюта хранилась в цифровом кошельке, доступ к которому был защищен паролем. Известный исследователь Джо Гранд на пару с коллегой помогли владельцу криптокошелька восстановить пароль, и не при помощи простого перебора, а, как правильно отметили в обсуждении на Хабре, «решив проблему мозгами». Джо Гранд любит подавать свои истории красиво, он снял видео и дал интервью журналу Wired, где использовал красивые и понятные более широкой аудитории метафоры типа «мы нашли способ повернуть время вспять». Реально интересная техническая информация этой работы, впрочем, уместилась на одну страницу текстом . Для облегчения «взлома» криптокошелька хакерам требовалось уменьшить количество возможных вариаций пароля для перебора. Им удалось это сделать благодаря одной особенности программы RoboForm, которую владелец кошелька использовал для генерации пароля. И это, пожалуй, самое интересное: анализ старой версии RoboForm показывает нам пример, как не надо генерировать случайные последовательности символов.
-
Security Week 2423: о плохих генераторах случайных чисел и пароле к криптокошельку
«Взлом» криптокошелька, пароль к которому был утерян больше 10 лет назад, — это самая красивая история по теме кибербезопасности на прошлой неделе. Пожелавший остаться анонимным пользователь приобрел биткоины на сумму примерно 4000 евро в 2013 году. Криптовалюта хранилась в цифровом кошельке, доступ к которому был защищен паролем. Известный исследователь Джо Гранд на пару с коллегой помогли владельцу криптокошелька восстановить пароль, и не при помощи простого перебора, а, как правильно отметили в обсуждении на Хабре, «решив проблему мозгами». Джо Гранд любит подавать свои истории красиво, он снял видео и дал интервью журналу Wired, где использовал красивые и понятные более широкой аудитории метафоры типа «мы нашли способ повернуть время вспять». Реально интересная техническая информация этой работы, впрочем, уместилась на одну страницу текстом . Для облегчения «взлома» криптокошелька хакерам требовалось уменьшить количество возможных вариаций пароля для перебора. Им удалось это сделать благодаря одной особенности программы RoboForm, которую владелец кошелька использовал для генерации пароля. И это, пожалуй, самое интересное: анализ старой версии RoboForm показывает нам пример, как не надо генерировать случайные последовательности символов.
-
The #RoboForm password regeneration source code and technical notes are up! https://grandideastudio.com/portfolio/security/roboform-password-regeneration/
-
The #RoboForm password regeneration source code and technical notes are up! https://grandideastudio.com/portfolio/security/roboform-password-regeneration/
-
The #RoboForm password regeneration source code and technical notes are up! https://grandideastudio.com/portfolio/security/roboform-password-regeneration/
-
The #RoboForm password regeneration source code and technical notes are up! https://grandideastudio.com/portfolio/security/roboform-password-regeneration/
-
The #RoboForm password regeneration source code and technical notes are up! https://grandideastudio.com/portfolio/security/roboform-password-regeneration/
-
How Researchers Cracked an 11-Year-Old #Password to a $3 Million#CryptoWallet
Thanks to a flaw in a decade-old version of the #RoboForm password manager and a bit of luck, researchers were able to unearth the password to a #crypto wallet containing a fortune.
#securityhttps://www.wired.com/story/roboform-password-3-million-dollar-crypto-wallet/
-
How Researchers Cracked an 11-Year-Old #Password to a $3 Million#CryptoWallet
Thanks to a flaw in a decade-old version of the #RoboForm password manager and a bit of luck, researchers were able to unearth the password to a #crypto wallet containing a fortune.
#securityhttps://www.wired.com/story/roboform-password-3-million-dollar-crypto-wallet/
-
How Researchers Cracked an 11-Year-Old #Password to a $3 Million#CryptoWallet
Thanks to a flaw in a decade-old version of the #RoboForm password manager and a bit of luck, researchers were able to unearth the password to a #crypto wallet containing a fortune.
#securityhttps://www.wired.com/story/roboform-password-3-million-dollar-crypto-wallet/
-
How Researchers Cracked an 11-Year-Old #Password to a $3 Million#CryptoWallet
Thanks to a flaw in a decade-old version of the #RoboForm password manager and a bit of luck, researchers were able to unearth the password to a #crypto wallet containing a fortune.
#securityhttps://www.wired.com/story/roboform-password-3-million-dollar-crypto-wallet/
-
How Researchers Cracked an 11-Year-Old #Password to a $3 Million#CryptoWallet
Thanks to a flaw in a decade-old version of the #RoboForm password manager and a bit of luck, researchers were able to unearth the password to a #crypto wallet containing a fortune.
#securityhttps://www.wired.com/story/roboform-password-3-million-dollar-crypto-wallet/
-
How Researchers Cracked an 11-Year-Old Password to a $3 Million Crypto Wallet | WIRED
https://www.wired.com/story/roboform-password-3-million-dollar-crypto-wallet/
Thanks to a flaw in a decade-old version of the RoboForm password manager and a bit of luck, researchers were able to unearth the password to a crypto wallet containing a fortune.
-
World Password Day: Top 10 Password Managers for Ultimate Digital Safety https://thecyberexpress.com/top-password-managers-for-digital-safety/ #GooglePasswordManager #TheCyberExpressNews #PasswordManagers #WorldPasswordDay #TheCyberExpress #FirewallDaily #1Password #Bitwarden #LogMeOnce #ZohoVault #Features #Dashlane #NordPass #RoboForm #Enpass #Keeper
-
World Password Day: Top 10 Password Managers for Ultimate Digital Safety https://thecyberexpress.com/top-password-managers-for-digital-safety/ #GooglePasswordManager #TheCyberExpressNews #PasswordManagers #WorldPasswordDay #TheCyberExpress #FirewallDaily #1Password #Bitwarden #LogMeOnce #ZohoVault #Features #Dashlane #NordPass #RoboForm #Enpass #Keeper
-
World Password Day: Top 10 Password Managers for Ultimate Digital Safety https://thecyberexpress.com/top-password-managers-for-digital-safety/ #GooglePasswordManager #TheCyberExpressNews #PasswordManagers #WorldPasswordDay #TheCyberExpress #FirewallDaily #1Password #Bitwarden #LogMeOnce #ZohoVault #Features #Dashlane #NordPass #RoboForm #Enpass #Keeper
-
World Password Day: Top 10 Password Managers for Ultimate Digital Safety https://thecyberexpress.com/top-password-managers-for-digital-safety/ #GooglePasswordManager #TheCyberExpressNews #PasswordManagers #WorldPasswordDay #TheCyberExpress #FirewallDaily #1Password #Bitwarden #LogMeOnce #ZohoVault #Features #Dashlane #NordPass #RoboForm #Enpass #Keeper
-
@stk @shipp @mmiasma @tokyo_0 @cooopsspace
@alfredo @xmetal
ENThanks SO much everyone for the tips and encouragement about dealing with my gmail password problems! I've purchased and installed #Roboform as an affordable #PasswordManager and I've set them as the default for passwords on my phone. Always a learning curve with a new process. Since I have 2FA for Google, it's possible that folks couldn't do anything with my password, even if they found it. I've had no unusual security alerts.
-
@stk @shipp @mmiasma @tokyo_0 @cooopsspace
@alfredo @xmetal
ENThanks SO much everyone for the tips and encouragement about dealing with my gmail password problems! I've purchased and installed #Roboform as an affordable #PasswordManager and I've set them as the default for passwords on my phone. Always a learning curve with a new process. Since I have 2FA for Google, it's possible that folks couldn't do anything with my password, even if they found it. I've had no unusual security alerts.
-
@stk @shipp @mmiasma @tokyo_0 @cooopsspace
@alfredo @xmetal
ENThanks SO much everyone for the tips and encouragement about dealing with my gmail password problems! I've purchased and installed #Roboform as an affordable #PasswordManager and I've set them as the default for passwords on my phone. Always a learning curve with a new process. Since I have 2FA for Google, it's possible that folks couldn't do anything with my password, even if they found it. I've had no unusual security alerts.
-
@stk @shipp @mmiasma @tokyo_0 @cooopsspace
@alfredo @xmetal
ENThanks SO much everyone for the tips and encouragement about dealing with my gmail password problems! I've purchased and installed #Roboform as an affordable #PasswordManager and I've set them as the default for passwords on my phone. Always a learning curve with a new process. Since I have 2FA for Google, it's possible that folks couldn't do anything with my password, even if they found it. I've had no unusual security alerts.
-
@stk @shipp @mmiasma @tokyo_0 @cooopsspace
@alfredo @xmetal
ENThanks SO much everyone for the tips and encouragement about dealing with my gmail password problems! I've purchased and installed #Roboform as an affordable #PasswordManager and I've set them as the default for passwords on my phone. Always a learning curve with a new process. Since I have 2FA for Google, it's possible that folks couldn't do anything with my password, even if they found it. I've had no unusual security alerts.
-
Which password manager do you use? If you choose other, please comment and mention which one you use.
P. S.: About to migrate away from LastPass and am looking for suggestions...
#lastpass #hack #hacked #passwords #1password #bitwarden #nordpass #roboform #iolo #totalav #kaspersky #vault #security
-
Which password manager do you use? If you choose other, please comment and mention which one you use.
P. S.: About to migrate away from LastPass and am looking for suggestions...
#lastpass #hack #hacked #passwords #1password #bitwarden #nordpass #roboform #iolo #totalav #kaspersky #vault #security
-
Which password manager do you use? If you choose other, please comment and mention which one you use.
P. S.: About to migrate away from LastPass and am looking for suggestions...
#lastpass #hack #hacked #passwords #1password #bitwarden #nordpass #roboform #iolo #totalav #kaspersky #vault #security
-
Which password manager do you use? If you choose other, please comment and mention which one you use.
P. S.: About to migrate away from LastPass and am looking for suggestions...
#lastpass #hack #hacked #passwords #1password #bitwarden #nordpass #roboform #iolo #totalav #kaspersky #vault #security
-
Which password manager do you use? If you choose other, please comment and mention which one you use.
P. S.: About to migrate away from LastPass and am looking for suggestions...
#lastpass #hack #hacked #passwords #1password #bitwarden #nordpass #roboform #iolo #totalav #kaspersky #vault #security
-
I haven't used #LastPass for about 4 years, but certainly I still had a vault on their server.
I've been using #Roboform, and took at a look at it today.
Of the 2,000 logins, about 300 were classified as weak #passwords, or had turned up at some point in HIBP.I started changing the weak ones. Since I've been on the internet 30 years, there was a shitload of sites that were long gone, merged or which I had log forgotten. Yet my password manager keeps those for me, forever. Throwing more garbage onto a never ending pile of passwords that can only get bigger.
I don't have time to regularly change 2,000 passwords. I can't manage the time to weed the website garden.
It seems every year there's a great idea for replacing the password that never comes to adoption. Meanwhile, the password pile gets even deeper.
I'm seriously considering a clean start. A change of phone number, change of email, just pick the top 50 sites I regularly use, scale back the online services I use, and let everything else just rot.
-
I haven't used #LastPass for about 4 years, but certainly I still had a vault on their server.
I've been using #Roboform, and took at a look at it today.
Of the 2,000 logins, about 300 were classified as weak #passwords, or had turned up at some point in HIBP.I started changing the weak ones. Since I've been on the internet 30 years, there was a shitload of sites that were long gone, merged or which I had log forgotten. Yet my password manager keeps those for me, forever. Throwing more garbage onto a never ending pile of passwords that can only get bigger.
I don't have time to regularly change 2,000 passwords. I can't manage the time to weed the website garden.
It seems every year there's a great idea for replacing the password that never comes to adoption. Meanwhile, the password pile gets even deeper.
I'm seriously considering a clean start. A change of phone number, change of email, just pick the top 50 sites I regularly use, scale back the online services I use, and let everything else just rot.
-
I haven't used #LastPass for about 4 years, but certainly I still had a vault on their server.
I've been using #Roboform, and took at a look at it today.
Of the 2,000 logins, about 300 were classified as weak #passwords, or had turned up at some point in HIBP.I started changing the weak ones. Since I've been on the internet 30 years, there was a shitload of sites that were long gone, merged or which I had log forgotten. Yet my password manager keeps those for me, forever. Throwing more garbage onto a never ending pile of passwords that can only get bigger.
I don't have time to regularly change 2,000 passwords. I can't manage the time to weed the website garden.
It seems every year there's a great idea for replacing the password that never comes to adoption. Meanwhile, the password pile gets even deeper.
I'm seriously considering a clean start. A change of phone number, change of email, just pick the top 50 sites I regularly use, scale back the online services I use, and let everything else just rot.
-
I haven't used #LastPass for about 4 years, but certainly I still had a vault on their server.
I've been using #Roboform, and took at a look at it today.
Of the 2,000 logins, about 300 were classified as weak #passwords, or had turned up at some point in HIBP.I started changing the weak ones. Since I've been on the internet 30 years, there was a shitload of sites that were long gone, merged or which I had log forgotten. Yet my password manager keeps those for me, forever. Throwing more garbage onto a never ending pile of passwords that can only get bigger.
I don't have time to regularly change 2,000 passwords. I can't manage the time to weed the website garden.
It seems every year there's a great idea for replacing the password that never comes to adoption. Meanwhile, the password pile gets even deeper.
I'm seriously considering a clean start. A change of phone number, change of email, just pick the top 50 sites I regularly use, scale back the online services I use, and let everything else just rot.
-
I haven't used #LastPass for about 4 years, but certainly I still had a vault on their server.
I've been using #Roboform, and took at a look at it today.
Of the 2,000 logins, about 300 were classified as weak #passwords, or had turned up at some point in HIBP.I started changing the weak ones. Since I've been on the internet 30 years, there was a shitload of sites that were long gone, merged or which I had log forgotten. Yet my password manager keeps those for me, forever. Throwing more garbage onto a never ending pile of passwords that can only get bigger.
I don't have time to regularly change 2,000 passwords. I can't manage the time to weed the website garden.
It seems every year there's a great idea for replacing the password that never comes to adoption. Meanwhile, the password pile gets even deeper.
I'm seriously considering a clean start. A change of phone number, change of email, just pick the top 50 sites I regularly use, scale back the online services I use, and let everything else just rot.
-
@jenny_sivapalan If you do look to moving in be been very happy with #RoboForm.
-
@jenny_sivapalan If you do look to moving in be been very happy with #RoboForm.