
Was LastPass Compromised? - Surveillance Report 69 - Techlore
video description
Date: 2022-04-15
Comments and reviews: 9
Sam
Regarding the German law. This is just doing what courts ruled (the previous law was not enforced because of court rulings, so right now we don't have any active policies for providers to save communication data in general. But previous governments always tried to work around the court rulings (going on for 10 years or so now) in a not so good way, so it's definitely a win the new one won't try this again. Also our new government seems do be a lot better when it comes to privacy and IT-security. But right now it's all just plans nothing done yet as far as I know.
reply
Regarding the German law. This is just doing what courts ruled (the previous law was not enforced because of court rulings, so right now we don't have any active policies for providers to save communication data in general. But previous governments always tried to work around the court rulings (going on for 10 years or so now) in a not so good way, so it's definitely a win the new one won't try this again. Also our new government seems do be a lot better when it comes to privacy and IT-security. But right now it's all just plans nothing done yet as far as I know.
reply
The
About the cookies. Sure, you can clear cookies but some websites are poorly made. So they do not renew session cookies and keep reusing the same session cookie o. o
This means that an attacker may keep on reusing that same session cookie xD
The good websites renew the session cookie and the session cookie (should) only be able to be used not more than once: P also a good habit is to have one session active on an account and not more.
reply
About the cookies. Sure, you can clear cookies but some websites are poorly made. So they do not renew session cookies and keep reusing the same session cookie o. o
This means that an attacker may keep on reusing that same session cookie xD
The good websites renew the session cookie and the session cookie (should) only be able to be used not more than once: P also a good habit is to have one session active on an account and not more.
reply
Asdayasman
How would clearing cookies make you safer against MitM attacks on auth cookies? The server doesn't know that you deleted a cookie it provided, and doesn't even have much reason to invalidate it until it times out - as far as it knows, you're just on a new device. Clearing cookies will keep you safe(ish) when using public computing resources, but that's not a MitM attack then.
reply
How would clearing cookies make you safer against MitM attacks on auth cookies? The server doesn't know that you deleted a cookie it provided, and doesn't even have much reason to invalidate it until it times out - as far as it knows, you're just on a new device. Clearing cookies will keep you safe(ish) when using public computing resources, but that's not a MitM attack then.
reply
ActiveTurtle
About clearing cookies every time at browser exit, it does feel a little too annoying but after doing it for couple of months, it becomes both easy and useful. Now I don't have to worry about forgetting to log out of websites I'm not using currently or frequently. All websites should not be kept logged in and this just makes it easier for me.
reply
About clearing cookies every time at browser exit, it does feel a little too annoying but after doing it for couple of months, it becomes both easy and useful. Now I don't have to worry about forgetting to log out of websites I'm not using currently or frequently. All websites should not be kept logged in and this just makes it easier for me.
reply
ParaPatty
If your Ssn is likely already available online from previous data breaches (equifax) then what-s the point of being cautious in giving it to phone carriers? Just freeze the score until you need it.
reply
If your Ssn is likely already available online from previous data breaches (equifax) then what-s the point of being cautious in giving it to phone carriers? Just freeze the score until you need it.
reply
Harsh
The penny challenge will likely not electrocute you at least in the UK or Europe as most of their household plugs are designed such that the metal contact have already disconnected if they are visible.
reply
The penny challenge will likely not electrocute you at least in the UK or Europe as most of their household plugs are designed such that the metal contact have already disconnected if they are visible.
reply
saudfata
I just want to point out that retyping you login information, or copying your password does make you vulnerable to keyloggers. Personally I prefer using browser extensions with autofill
reply
I just want to point out that retyping you login information, or copying your password does make you vulnerable to keyloggers. Personally I prefer using browser extensions with autofill
reply
Alejandro
So we shouldn't use sms 2fa. Does that mean it's less safe to use it than to not do anything at all? Or that we should do something instead of sms 2fa?
reply
So we shouldn't use sms 2fa. Does that mean it's less safe to use it than to not do anything at all? Or that we should do something instead of sms 2fa?
reply
Im1Random
I wouldn't use anything than self hosted non publicly accessible password managers. (Currently using self hosted VaultWarden)
reply
I wouldn't use anything than self hosted non publicly accessible password managers. (Currently using self hosted VaultWarden)
reply
Add a review, comment
Other channel videos















