VehiclesFashionRecipesBlogsHuntTravelsSportFunHandmadeITEducation
Mini-Games
x

x
zakruti.com » IT - Software » IT, programs, coding
Was LastPass Compromised? - Surveillance Report 69 - Techlore

Was LastPass Compromised? - Surveillance Report 69 - Techlore

FBTwitterReddit

video description

Rating: 4.5; Vote: 2
Was LastPass Compromised? - Surveillance Report 69 - Techlore This week we cover LastPass's alleged compromise, another T-Mobile data breach, DuckDuckGo's growth, and more! Xankill3r: Have you folks looked at the new tokenized credit/debit card storage requirements implemented in India? Basically companies are no longer legally allowed to store full card info on their servers and instead have to get permission from users to store a unique token that is generated from a combination of card number, bank, payment provider and merchant. I'm only aware of it from a consumer pov but don't know if it would actually prevent misuse of card info (eg: Could tokens obtained from a data breach be used to make unauthorized payments on the same service.
Date: 2022-04-15

Comments and reviews: 9


Regarding the German law. This is just doing what courts ruled (the previous law was not enforced because of court rulings, so right now we don't have any active policies for providers to save communication data in general. But previous governments always tried to work around the court rulings (going on for 10 years or so now) in a not so good way, so it's definitely a win the new one won't try this again. Also our new government seems do be a lot better when it comes to privacy and IT-security. But right now it's all just plans nothing done yet as far as I know.
reply

About the cookies. Sure, you can clear cookies but some websites are poorly made. So they do not renew session cookies and keep reusing the same session cookie o. o
This means that an attacker may keep on reusing that same session cookie xD
The good websites renew the session cookie and the session cookie (should) only be able to be used not more than once: P also a good habit is to have one session active on an account and not more.

reply

How would clearing cookies make you safer against MitM attacks on auth cookies? The server doesn't know that you deleted a cookie it provided, and doesn't even have much reason to invalidate it until it times out - as far as it knows, you're just on a new device. Clearing cookies will keep you safe(ish) when using public computing resources, but that's not a MitM attack then.
reply

About clearing cookies every time at browser exit, it does feel a little too annoying but after doing it for couple of months, it becomes both easy and useful. Now I don't have to worry about forgetting to log out of websites I'm not using currently or frequently. All websites should not be kept logged in and this just makes it easier for me.
reply

If your Ssn is likely already available online from previous data breaches (equifax) then what-s the point of being cautious in giving it to phone carriers? Just freeze the score until you need it.
reply

The penny challenge will likely not electrocute you at least in the UK or Europe as most of their household plugs are designed such that the metal contact have already disconnected if they are visible.
reply

I just want to point out that retyping you login information, or copying your password does make you vulnerable to keyloggers. Personally I prefer using browser extensions with autofill
reply

So we shouldn't use sms 2fa. Does that mean it's less safe to use it than to not do anything at all? Or that we should do something instead of sms 2fa?
reply

I wouldn't use anything than self hosted non publicly accessible password managers. (Currently using self hosted VaultWarden)
reply
Add a review, comment






Other channel videos