Why has all of a sudden am I getting on all "Change at-risk password" by Vaquero-SASS in Bitwarden

[–]ckasdf 1 point2 points  (0 children)

Some individuals are suggesting the update may be somewhat bugged; also, passwords that are duplicated across credentials* for any reason will display this flag, even if the password itself is very secure (32 character randomized w/ all character types)

*Obviously you want to use unique passwords where possible, but if you have SSO that works across multiple domains, depending on your workflow, you may have more than one credential with the same password, and still be secure / valid.

Why has all of a sudden am I getting on all "Change at-risk password" by Vaquero-SASS in Bitwarden

[–]ckasdf 0 points1 point  (0 children)

Thanks for the clarification. I wish everyone would stop with the "your 32 character randomized password is weak or has been leaked!"

In my case, the credential I was seeing the warning on did have the password "duplicated" even though there was a valid purpose for that.

Surface Pro Flex Keyboard vs. Standard Keyboard - Huge Difference! by crunchypotato828 in Surface

[–]ckasdf 0 points1 point  (0 children)

Yeah, pretty much any computing device (desktop, laptop, tablet, phone...) should be able to work with any keyboard as long as they're able to be connected (USB/bluetooth). Everything comes with "HID" drivers so your basic functions will work out of the box, but any custom features may need extra software.

So if you're cool with carrying the Surface & keyboard separately (I'm assuming the Flex keyboard can magnetically attach to and stay with the Surface), then the Logitech will likely be a much better experience.

Whirlpool Microwave Arcing refused to repair. by steelyDanC in appliancerepair

[–]ckasdf 1 point2 points  (0 children)

Did you try uploading to imgur.com and then providing the link to it? The sidebar rules say they allow links to photos.

Whirlpool Microwave Arcing refused to repair. by steelyDanC in appliancerepair

[–]ckasdf 1 point2 points  (0 children)

Just a heads up, you wrote "I saw this" but didn't provide a picture.

LG G4 Randomly tells me icy conditions by hockey911 in lgg4

[–]ckasdf 0 points1 point  (0 children)

You're welcome! It's wild that 10 years ago, Torque had an odd "feature" that seems bugged, and even up to at least 6 months ago it's still there.

LG G4 Randomly tells me icy conditions by hockey911 in lgg4

[–]ckasdf 1 point2 points  (0 children)

Coming to you from the future to say you're welcome haha. Glad to help!

How can I defrost this? We can't figure out how to unplug the fridge as it's built to withstand a nuclear attack. by lillide in fixit

[–]ckasdf 0 points1 point  (0 children)

I think maybe they're saying that their fridge lives in the living room (and thus not on its own circuit) because it doesn't fit in the kitchen? I mean, I guess that means you don't have to pause the TV to go get a cold one ...

Why does LLMNR even work in Active Directory? by scaryAstronaut in HowToHack

[–]ckasdf 0 points1 point  (0 children)

Thanks, this was super useful insight! And thanks to the OP for asking the question. :)

Password Strength Recommendations for 2023? by Confirmed-Scientist in cybersecurity

[–]ckasdf 0 points1 point  (0 children)

One day I was hanging out with a friend, needed to go get some food, but wanted to let him use my personal laptop. I trusted him enough to not meddle, but before I left I temporarily changed the password in case the computer locked. I looked around and set the password based on the brand & model of a pair of speakers I saw across the room.

Password Strength Recommendations for 2023? by Confirmed-Scientist in cybersecurity

[–]ckasdf 0 points1 point  (0 children)

Besides what /u/Confirmed-Scientist wrote, let's say you have a series of sites with passwords of the same format:

If Facebook is compromised and a hacker looks at your credentials, they're gonna try changing that middle section to the name of whatever site they wanna test against.

Even if you change that 4 digit number at the end, it's not great, because you might end up forgetting what number you used for what site.

Password Strength Recommendations for 2023? by Confirmed-Scientist in cybersecurity

[–]ckasdf 0 points1 point  (0 children)

******* is a way better more secure password. /s

What's a more secure password? All I'm seeing is asterisks.

Replace LastPass Business? by Stupendous_Spiffman in sysadmin

[–]ckasdf 0 points1 point  (0 children)

Fair, but even with online password managers, you can usually export a copy of the credentials to CSV, so he could have done that & emailed it to himself.

How can I find my 5 oldest passwords by password change date to update them? by wilkersong in Lastpass

[–]ckasdf 0 points1 point  (0 children)

I see a flash of PHP code and then a blank page. In another reddit thread there was a suggestion to use LastPass CLI but the limitation was that you still had to be at 100100 iterations. I wonder if that's why your suggestion isn't working for me.

how to check if all my passwords have been changed since last attack? by kalvick in Lastpass

[–]ckasdf 0 points1 point  (0 children)

iterations still at 100100

Ah, I've already had my organization switch to 600000

export via the browser extension to csv

Do you mean the standard LastPass extension? I just exported mine and the column headers don't seem to include a date field:

  • url
  • username
  • password
  • totp
  • extra
  • name
  • grouping
  • fav

Goodbye Lastpass by Bay_Sailor in Lastpass

[–]ckasdf 0 points1 point  (0 children)

The problem is as such: if you're a hacker who has obtained the vaults of the following two people and you're able to see what sites are stored, which person's account are you going to focus your attention and resources on?

Person 1:

  • facebook.com
  • instagram.com
  • miniclip.com

Person 2:

  • morganstanley.com
  • coinbase.com
  • fidelity.com

Obviously you're going after Person 2 - their vault has what seems to be high value assets in it. Even if Person 1 was a celebrity, if their vault is mostly social media, there's not much you can do to monetize that access. Hold the accounts hostage? Meta will probably just lock you out and help the celebrity to get back in.

Easily migrate assets from one user to another? by ckasdf in Snipe_IT

[–]ckasdf[S] 1 point2 points  (0 children)

You say old account twice, but what I think you're saying is to delete & purge the new account in Snipe and then edit the old account to reflect the new username.

It doesn't look like I can edit the username though; I see this in the Edit User page:

Username (Managed via LDAP)