2021-01-13 13:04:05

Thing is, the more you adjust and the more you try to protect yourself, more inconveniences you are facing.
Let's take just one example, password managers. I am using one myself, and I am extremely happy with randomly generated passwords, the ability to autofill everything on my mobile phone instead of having to type and remember passwords. However, when I need to setup a new device for the first time, I necessarily need to have another one with me to be able to check the password for the first time, and then manually enter that randomly generated password.

2021-01-13 15:07:34 (edited by Ghost 2021-01-13 15:08:37)

Or, what happened if someone hacked your password manager, or it broke and suddenly stopped accepting your master password. Apps fuck up, it happens. Then you're truly fucked because your ultrasecure  randomly generated passwords just locked you out of every account you had in existance. Or if someone cracked the master password, they still would have all your passwords, and you'd be screwed again. Here is a really good example of ultraparanoid security
I had a bank when I was studying in the UK. It took me weeks to get an account with my foreign passport because of their appointment, investigation etc.  But they had to send me the pin for my card, my card reader, and card all seperately. When I tried to pay all my accumulated bills, all my transactions  got rejected  for hours until the confirmation texts arrived. Alsso, they had this idiotic ultrasecure card reader. Each time I logged into the bank, it would recommend I log in securely with their inaccessible time consuming card reader. When choosing the other method, I would be asked three random pieces of info to log in each fucking time. And when you sent money to someone you hadn't before, I needed a sighted person to tap send on the reader, I then had to insert card, type the pin, generate the coede, and type the code on the website to  initiate transaction. When calling bank, when the automatic voice recognition locked me out of the bank when it couldnn't hear my randomly generated password I spoke to it. I got 3 tries.
You guys might think this level of security is awsome,  but it is wayyyyyy wayyyyyyyyyy overkill for a personal account, and is like planting mines in your house. It was far to  time consuming for any benefit it provides. I literally was begging a sighted friend to help me make the bank transfer because I couldn't pay him back because of ultrasecurity.

2021-01-13 21:51:50 (edited by defender 2021-01-13 22:01:56)

I'm not trying to hide my info from the government, that's a lost cause, I'm trying to keep it out of extra hands, so that I can hopefully avoid breaches and make it clear that I expect to be treated fairly by the services I use.
If a person can't find a good balance of security VS paranoia, that's their problem, but I really don't think I'm there yet.
As for password managers, that's what backing up the database is for.  And why choosing your manager carefully is an important part of it, so that you know it's one who is trusted and has been audited by a third party.  15 minutes on Google is enough for that info.
This way, even if your password vault gets cracked, at least you know they are salted, hashed, and allot harder to bruteforce than what most people use for passwords.

I really don't understand how that's an issue, unless you are getting new devices every week.  I mean honestly if that's too much for you, fine, but it isn't for most people so...
But I get your over all point.  This is why I don't use 2FA apps, it's just too much of a pain in the ass and what if my phone is dead but I need to get into an account on the computer quickly?  I don't mind the 2FA codes sent via SMS as much, even if they are less secure.

My point is just that not trying at all is foolish.  Everyone has their own individual point at which the constant extra work outweighs the potential risks, and that's okay.  But fostering a general attitude of (why bother) is exactly what large tech companies want to become the norm, and it's also probably going to come back and bite you in the ass at some point.

2021-01-14 00:31:57

for me, though, ease of use, and time saving outway the amount of time I spend on security measures. Facebook for example, I constantly get 2fa codes and messages because facebook marks my IP as suspicious because its virtual, same with amazon. The amount of time I spend verifying that I am real could have been actually spent doing something that deserved that time.

2021-01-14 01:06:15

I go for Signal. The iOS app is accessible. But there are some points to make it better. I made this topic:
https://community.signalusers.org/t/acc … ents/19259

Give some +1s on the topic to help to improve the accessebility

2021-01-14 01:18:19

Signal desktop is improving from the last time I used it. I hope they take those feedbacks to heart.

2021-01-14 04:02:31

Ultra security is bad, and I agree with @ghost with that point. That's just too much. But it in no way means you should shirk security entirely. There is a way of keeping things secure while not going overboard.
As for the password manager thing, that's a valid concern: what if it gets hacked? One could say you could back up the database, but even backups aren't foolproof. One could then argue: well, where do you then back it up? And so on and so forth. Using a password manager like Bitwarden is good; yes, it might be hacked, but that's a risk you have to take everywhere. Saying don't use bitwarden or <insert password manager here> because it might be hacked is akin to saying "Well, I just won't lock my car because someone might smash the windows or pick the lock". You do it, and you do it anyway, even if the risk is there, because risks like that will always be there and you can't eliminate them permanently. If your password manager gets hacked, then that's just something you have to deal with, and in time you will. But password managers like Bitwarden, even if they did get hacked, wouldn't provide much useful info because password databases are encrypted. Hackers wouldn't get anything useful out of those.

2021-01-14 11:14:05 (edited by Dakonna 2021-01-14 11:14:44)

Honestly Defender, the way the system works is fair already. Let's get one thing out of the way first. There is no such thing as a "free service". Some platforms may try to charge you for using them. Those shouldn't be selling your data because you're a direct revenue source. If you choose to use a so called free service, it's only free in the sense that you yourself don't have to pay to use it. So the company behind the service will have to make money some other way. And for most, that's selling your information for ad purposses or for other things of a similar nature. You can layor as many encryptions, vpns, and super duper anti tracking apps over one another as you wish. As long as you're using the site in question, you're still providing them with info they can use and sell. it may be fake info, but it's still info. What you think is preventing them from getting ritch off of your usage of their site is only fighting part of the problem. They'll sell fake info just as quickly as real info since it's all done automatically. Take YouTube and its stance on ad blockers. Part of the reason that YouTube doesn't simply ban anyone using ad blockers is they know they have the potential to lose a lot of people to other platforms if they do that. But the other part of it is, YouTube still obtains revenue from people with ad blockers watching videos. The ad itself is sent out, it just doesn't play on your computer. So they have no reason to care.

2021-01-14 12:06:47

It's funny to se how many people actually change from Whatsapp to Telegram these days. While TG doesn't share it's data with Facebook, it sure as hel does have a bunch of other security and data protection risks that people don't even realise.
Things as, Telegram bots analysing what you type and general saving of chatlogs on their servers.

2021-01-14 13:52:29

Facebook probably knows many things I've posted. Because I've been their customer, a user, or whatever you called it since 2011. They're probably selling a bunch of data about me. But what can you do? If you use a service for free, it means that you are the product.

2021-01-14 14:36:01 (edited by Ghost 2021-01-14 14:36:23)

Again as I said, I don't think the advantages of using a password manager outweigh the costs.  With mmy passwords written down, or stored in my head, I can log into any website, on any device, without also worrieing about my passwords  getting hacked. Could someone break into my house and steal my pc and thus have access to all of my data? Sure they can. But what are the mathematical odds of that happening, given that I have no important data that would increase the odds beyond the average joe. And even if it did happen, then I could recover from that easily. The most important passwords I store as text have a secondary authentication method that is required to log in, and the ones that don't get stored in my head.

2021-01-14 17:36:28 (edited by defender 2021-01-14 17:38:06)

@connor142 and @Socheat
I understand that we are the product, and my problem isn't the concept, but the execution.  As with any service, the customer has the right to not get ripped off on cost or have sneaky extra charges added.
Highly targeted or unnecessary data collection is a serious problem, and they can still make money off of more anonymized data but have gotten greedy and taken advantage of slow regulation.  Now it's so normalized that we all just take it foregranted, and I think that's fucked up.
IMO people should not have to give so much up either way, but it's important for companies to make us aware of what data is collected and how it's used, then provide an easy and effective way of making choices based on that information.  It's the consumer's responsibility to take advantage of that, which is what I'm trying to get people to care about.
If that means users can't use certain parts of the service because of a lack of permissions, that's their choice, but they need to have the option.
Until things improve however, I'm using the tools I have to force the issue, within reason.  Doing otherwise would just send the message that I'm okay with whatever they want to do.  If people don't show their displeasure with these actions, how can we ever expect meaningful change.
But again, allot of this is just reducing attack surface, rather than a social statement.

We already established in a previous disgussion a few months ago that you are far better at remembering passwords than most, and also apparently don't mind storing your passwords in insecure ways if I remember right.  Your decisions and capabilities are your own, but I prefer to have both easy access as well as good passwords with salting and hashing.  It's a compromise yes, but for me and many others, it's a good one.

2021-01-14 19:10:49

@39, sorry, but the "I'll just remember my passwords" trick doesn't work all that well. Random passwords have no kind of variation. They have no kind of "base template" to go off of. If you remember your password, you'll fall into this habit of "Well I'll just use this prefix and add some extra things on the end/beginning/middle". Point being that it becomes mathematically probable to break your password at some distant point in the future, and then to find out all other possible permutations and combinations of that password. Then they know all possible variations of your password and it becomes a matter of just simple iteration.

2021-01-14 20:37:43 (edited by ignatriay 2021-01-14 20:46:48)

Here's the thing. Even though this is going on; whatsapp chats will still be encripted, so no one will be able to know with whom, or what; your are chatting with people anyway so... Mainly what whatsapp is doing is for advertising purposes, which yeah, is all kind of... intrusive, but since your chats will still remain encrypted... No big deal; at least for me. Granted data such as, when where you last active will be given to facebook; but that's really no use if they cant tell with who your talking or whatnot anyway so... If, for instance, whatsapp removed the chat encription and was able to collect your chats, with whom you where chatting, etc; then yes, i would move. However read this,
https://www.financialexpress.com/indust … e/2169283/

Granted I dont have anything to hide; but still. If they could see what people talked about; and with whom, that is what would be a gamechanger for me, and would cause me to switch. Whatsapp doesn't keep your messages in their servers plus they are end to end encripted,  or anything else so yeah.

2021-01-14 23:43:05

Yeah, they updated their statement to clarify some things, and it's worth reading the new one.
It's still not good, but not as bad as the tech news sources made it out to be at first.

2021-01-15 00:30:41

Ethin, with all due respect, who  would go through the trouble of hacking an ordinary user's unimportant accounts? Randoomly generated passwords may be secure yes, but that is ultrasecurity to me. Try typing #_@$%$+ASFqrtZXC23)[ on the new phone you just purchased to log into your e-mail. I'll gladly pass that one.
Defender I use a specific set of passwords for most accounts. It isn't hard to memorize that set but as I said, important accounts have other methods of verification.

2021-01-15 00:43:36

@15, Don't programs like Outlook, Teams, Zoom, and Google Meet or whatever that thing is called use your data? So even if you're not using WhatsApp for school, there are probably still companies selling it

2021-01-15 00:55:14 (edited by Ethin 2021-01-15 01:01:05)

@44, sorry, but your logic still isn't sound. A hacker does not need to hack you in particular for any reason whatsoever. The justification that "Oh, my information isn't useful to anyone" doesn't fly, and never has. Especially because you can't actually prove that. Random passwords are not 'ultrasecurity'. If they were, security experts wouldn't recommend them as common and best practice, but they do. And as for that random password? That's not even random -- or not cryptographically random, at any case. Not random enough. A random password would be something like W2!vDHmdeGUAJu3Y (though you could also use a passphrase too). I don't need to type such a random password in, however, because I can tell Bitwarden to store it. I needn't remember any password that I store in bitwarden. It can be as long as I like -- most of mine are ridiculously long -- and the only password I need to remember is my master one, which also functions as part of the input to retrieve my password vaults encryption key. The server doesn't even know what it is because its a key derivation function that's being used. So yes, I would think that, considering my password vault contains other information than just passwords (though passwords are sensitive enough) a hacker might find it quite useful, even if its just something to hold over me to extort money out of me. As for your "set" of passwords? Congratulations. You've just doomed yourself. Your limiting yourself to a set list of password character sequences that you then append or prepend to. And once a hacker finds that character sequence that is common across all the passwords in one set, they can compromise all the other passwords in that set within a practical amount of time by just enumerating all possible permutations of that password. It might take a long time to do, but in a security scenario you have to assume that the hacker has unlimited resources and an infinite amount of time, because you know nothing about your foe.

2021-01-15 01:23:16

ok 46, so assume a hacker will try to hack me for the sake of hacking me. Ask yourself this question. Is my data really worth it to go through that trouble? For me, it really isn't. None of my accounts have anything that isn't easily replaceable or recoverable. Got a hacked credit card? I cancel it and order a new one. Hacked e-learning account I never use? Delete that account. Hacked social media/bank? 2fa blocks it. If I had multimillion dollars in the account, or  had highly sensetive or irreplaceable documents or files, then sure. But nothing I currently have justifies ultrasecurity.

2021-01-15 02:36:17

@47, again, random passwords are not paranoia. I'd really like to learn where you came up with that mentality because such a mentality is that of the purely ignorant. A hacker does not need to give a damn if your info is useful or not. A hacker just needs to hack you because they can. Perhaps they might even do it to extort money out of you. Point being that just because you might think its not useful to someone doesn't mean it really isn't. You should always use best security practices; you shouldn't ignore them because you think you know better.

2021-01-15 02:52:57

Well again, good luck memorizing your fully ultrasecure random passwords. Very  very few people will be able to do that, maybe people with photographic memory or something. Security is a subjective case based on what your protecting, the cost of losing it, and the stakes when you do lose it, as well as the time you lose with said security precautions, because afterall, time is money, and is far more valuable even, because time lost is not replaceable, and I'd rather  spend my  time doing things I like, instead of recrewting sighted people to read my ultrasecure physical card reader device so I can make that money transfer, or trying to  type in a shitty randomized password, or being locked out of an account on a different device because I  don't know the password from memory.

2021-01-15 03:44:10

@49, again, I don't need to memorize my random passwords. I let my password manager do that. I ned to only memorize one password, not hundreds to thousands. If I lose it, well, that's why we have password resets.

2021-01-15 05:55:17

Fixing all of your accounts after a breach seems harder than having to put in a long random password once or twice in the event that your password manager is unavailable for some reason.
I to am not particularly concerned about being targeted specifically, but I really don't want to deal with fixing any damage that occurs as a result of an untargeted hack that I get caught up in.  Some of the bank, ID, or SSI stuff in particular can be a big problem down the road, so I just like being able to lock down the parts of that system I have control over.

2021-01-15 07:48:21 (edited by zenothrax 2021-01-15 07:49:07)

As widespread as the data mining and things are, I'm becoming more privacy minded lately, and I'm trying to reduce the data that I do inevitably share with Big Tech.
I switched to mastodon after the twitter thread blew up, and I've been using telegram since 2019.
Telegram, BTW, is completely accessible on iOS, Android, and on Windows using Unigram.

Now I just need to find an alternative to facebook, because so many of my friends and family members use it, even though they're aware of the practices of FB and Mark Zuckerberg.

2021-01-15 08:05:12

51, again that is based on the number and usefulness of said accounts. As I have stated, very important accounts, most at least have 2 factor authentication  for unknown IP ranges or  have  secondary info to authenticate. Fixing or getting rid of a small number of accounts I never use on the very unlikely chance of a hack is a justified risk. Of  course there is info like your SSN where it is next to impossible to change it and if someone knows it, your fucked. But you can memorize that info anyway.

