← Home ← Back to /g/

Thread 106404941

72 posts 22 images /g/
Anonymous No.106404941 >>106405203 >>106405221 >>106405295 >>106405858 >>106406125 >>106406798 >>106407881 >>106408037 >>106408480 >>106411561
> trying to log in into my github accout
> fuck you, you must enable 2fa with some 3rd party services first
Why? I've never asked for this.
Anonymous No.106405203 >>106406125 >>106410305
>>106404941 (OP)
So that Islamic empire won't steal your account and use it for pro Palestine propaganda
Anonymous No.106405221
>>106404941 (OP)
So that Jewish empire will steal your account and use it for anti-Palestine propaganda
Anonymous No.106405284 >>106405308
Passwords are legacy tech. Absolutely useless security theatre in the age of AI-assisted spearphishing.
Anonymous No.106405295 >>106405400
>>106404941 (OP)
TOTP, retard bro
Anonymous No.106405308 >>106405315
>>106405284
But I don't give a fuck
Anonymous No.106405315 >>106408857
>>106405308
your parents too and we can see the results
Anonymous No.106405400 >>106405618 >>106408712 >>106414601
>>106405295
What totp? Why can't I use 2nd password, but forced to install some shit on my smartphone (which I don't have) or browser instead?
Anonymous No.106405618 >>106405687 >>106410440
>>106405400
you don't use any sort of password manager??
Anonymous No.106405687 >>106405769 >>106405792
>>106405618
My brain is the password manager I use.
Anonymous No.106405769
>>106405687
that's kind of awesome.
Anonymous No.106405792 >>106405841
>>106405687
Your passwords are most likely ass, then.
Anonymous No.106405841 >>106406031 >>106410359
>>106405792
No, they are words+digits combinations, strong enough.
Anonymous No.106405858 >>106409247
>>106404941 (OP)
Forcing people to either be an itoddler or use android for various services now requiring phone as the second factor or a 'random' security check.
It is everywhere.
It's over.
Anonymous No.106406031 >>106406089
>>106405841
Anon, you need to stop using qwerty12345 as your password.
Anonymous No.106406089 >>106406118 >>106406153 >>106406157
>>106406031
No, it's combination of words and digits like picrel.
Anonymous No.106406118 >>106406209 >>106414731
>>106406089
>using real words
>with obvious replacements
>only digits between the words
NGMI, 1 GPU-hour at worst and you're cooked
Anonymous No.106406125 >>106406172
>>106404941 (OP)
>uses jewhub
you deserve it
>>106405203
kys
Anonymous No.106406146 >>106408827
if a website allows an attacker to brute force a password without setting off any red flags, it's the website's fault
>maybe this legitimate user just forgot his password and is trying 50,000 different combinations per second
Anonymous No.106406153 >>106406209 >>106410583
>>106406089
It's really cute that you think that's a strong password.
Anonymous No.106406157 >>106406209 >>106410419
>>106406089
anon who told you that was a good password?
Anonymous No.106406172 >>106406179
>>106406125
Nobody wants you here
Go back to r3ddit
Anonymous No.106406179
>>106406172
this is a jew hating site, anon. Unlike reddit.
Anonymous No.106406209 >>106406750 >>106406817
>>106406118
>>106406153
>>106406157
Using this for decades, never got hacked. Good luck bruteforcing it.
Anonymous No.106406750 >>106408453
>>106406209
Sorry, your password is not good. Stay buttmad I guess?
Anonymous No.106406798
>>106404941 (OP)
baseddevs love that shit
Anonymous No.106406817 >>106408453
>>106406209
Yeah and I never locked the door and never been robbed
Therefore unlocked doors are safe
Anonymous No.106407881
>>106404941 (OP)
i use passkey, much more secure. requires device to be present to login
Anonymous No.106408037 >>106408453
>>106404941 (OP)
Retarded people use Passw0rd and get their accounts taken over, so everyone has to suffer to prevent them from being so retarded.
Anonymous No.106408453 >>106408491
>>106406750
But it's you mad, trying to prove me that my password is bad.

>>106406817
It's completely wrong analogy and conclusion.

>>106408037
> to prevent
In the most retarded inconvenient way.
GREY1 No.106408480
>>106404941 (OP)
WERE GONNA HAVE TO FORK GITHUB SADLY.
Anonymous No.106408491 >>106408775
>>106408453
>In the most retarded inconvenient way.
How else are you going to prevent dumb fucking retards from getting their accounts """hacked""" when they use the same password on 50 different sites?
Anonymous No.106408712 >>106408775
>>106405400
TOTP is just a password that is used to generate a temporary password based on the current time, can be completely offline as long as the clocks are synced
Anonymous No.106408775 >>106408799 >>106412774
>>106408491
Send a code to email like any other service did?

>>106408712
So just another password, but in a complicated way.
Anonymous No.106408799 >>106408805 >>106408975 >>106409420
>>106408775
The difference is that if someone how temporary password is leaked, it doesn't work anymore since the time has passed
Anonymous No.106408805
>>106408799
if somehow*
Anonymous No.106408827 >>106408854
>>106406146
Fucking Google made me 'recover' my account after I fucking typo'd my password TWICE.
Realistically I know this is because there are bots hammering it 24/7, but holy fuck that is both annoying and scary that if I didn't have my other recovery email I'd lose my roughly 20(? when it was new) year old gmail and shit.
Anonymous No.106408840
They had to save face after disabling git password authentication, which was pure security theater given that you could still log in via password on the website and do whatever the hell you wanted.
Now it's technically more secure so it was "worth it" to waste everyone's time with inane bullshit.
GREY1 No.106408854
>>106408827
GOOGLE IS SO DEAD
I WOULDN'T BE SUPRISED IF THEY START CRYPTO SCAMMING NEXT.
YOU KNOW, THOSE PEOPLE HAVE NO MORALS.
Anonymous No.106408857
>>106405315
If OP's parents never gave a fuck he would never be here.
Anonymous No.106408975 >>106409114
>>106408799
The same if your temporary password generator password leaked.
Anonymous No.106409114 >>106409862
>>106408975
You don't send it anywhere, unlike a password that you use it on sites
Anonymous No.106409150 >>106411170 >>106414624
Why not use a local TOTP? Even elgoog lets you use that shit
Anonymous No.106409181 >>106409284
Ideally passwords wouldn't exist.
Anonymous No.106409247 >>106410341
>>106405858
It's over for retards addicted to corporate slop. Intelligent people build their own platforms in the dark web.tgtxt
Anonymous No.106409284
>>106409181
I remember this schizo
Anonymous No.106409420 >>106409445
>>106408799
the difference is that the totp secret can't be stored hashed, because it needs to be used server-side to generate the temporary password
also that when you set up totp, pretty much any service also gives you 10(sic!) permanent recovery codes in a text file for safekeeping, which can be leaked
Anonymous No.106409445 >>106409558
>>106409420
It can be stored encrypted, and again, you don't go sharing the recovery code or the secret like you do with passwords, that some people reuse in multiple websites
Anonymous No.106409558 >>106411580
>>106409445
>that some people
problems of stupid people are not my problem
Anonymous No.106409862 >>106411231
>>106409114
On what sites? Are you using the same password on multiple sites?
Anonymous No.106409900 >>106411170
just set it up with keepassxc totp
Anonymous No.106410305
>>106405203
It's called a Caliphate, Jeet.
Anonymous No.106410341 >>106412988
>>106409247
Having a bank account is appearantly an addiction then.
Anonymous No.106410359 >>106411170
>>106405841
>No, they are words
ngmi
Anonymous No.106410402
github's totp implementation is broken
Anonymous No.106410419
>>106406157
correct horse battery staple
Anonymous No.106410440
>>106405618
use a book
Anonymous No.106410583
>>106406153
go on, then
Anonymous No.106411170
>>106409150
>>106409900
Because I didn't ask what to install.

>>106410359
It works and is as safe as your jf(743*&$hgHUG, but possible to remember
Anonymous No.106411231
>>106409862
People are doing that. And they're also using their password on networks that aren't end-to-end secured. And their passwords are as short and simple as they can be. And so on.

The move to FIDO2 / webauthn with like yubi-, token2 or neonkeys is quite logical, and TOTP on smartphones is probably fine too.
Anonymous No.106411561 >>106411608
>>106404941 (OP)
Just use KeepAssXC you stupid nigger.
Anonymous No.106411580
>>106409558
>I am so le smart
hackers love hubris just as much as cluelessness
Anonymous No.106411608
>>106411561
> KeepAssXC
For amateurs. Professionals write their own password managers.
Anonymous No.106412774 >>106412806
>>106408775
>send a code to an email service that has the same username and password as the one that may be compromised
Anonymous No.106412806 >>106414510
>>106412774
> send a key to a totp password generator that is installed on a hacked or stolen device
Anonymous No.106412988
>>106410341
Yes. One of the worst.
Free yourself.
Anonymous No.106414510
>>106412806
That requires the user to be retarded enough to get their iPhone hacked, and an attacker to hack that and get the user's password. The other option just requires the user to be of average retardation (password reuse).
Anonymous No.106414601
>>106405400
>but forced to install some shit on my smartphone (which I don't have)
stop noticing, goy
Anonymous No.106414624
>>106409150
>Why not use a local TOTP?
because banks don't let you
you (((must))) use their (((app))) on a (((smartphone))) for (((reasons)))
Anonymous No.106414731 >>106414769
>>106406118
heres a sha256 of a password similar to what anon posted:
8e8bba732ace6141c16fd1067238b1b51ad1e83df6461e093f5e3a6825e31b52
if you can break it within 5 hours ill do nothing
Anonymous No.106414769
>>106414731
ill help by saying it starts and ends with numbers and has 5 words, there are 3 two digit numbers, 1 three digit number and 2 one digit numbers, good luck
Anonymous No.106414953
>log into github account
>Code better with Copilot AI
Ah fuck, time to find something else.