RDMC
Enemy Wheelbarrow Spotted..!!
+736|6566|Area 51
I think this topic is kinda going off topic-ish.
GC_PaNzerFIN
Work and study @ Technical Uni
+528|6415|Finland

Zimmer wrote:

At the end of the day, this site is safe, but you shouldn't in principle be putting in your passwords on random and potentially risky sites. Is that a better way of putting it?
Sounds good. *hand shake of truce*
3930K | H100i | RIVF | 16GB DDR3 | GTX 480 | AX750 | 800D | 512GB SSD | 3TB HDD | Xonar DX | W8
Bertster7
Confused Pothead
+1,101|6582|SE London

GC_PaNzerFIN wrote:

There are zero benefits from giving away your password, yet there is potential harm.
Not true. I have people giving me their passwords all the time - to their benefit. If someone has a department server that isn't supported by our desktop support teams (and most aren't, they just provide racks, network and power for them), they tend to come running to me for support. I can't help them unless they give me passwords. I always make very clear that they don't have to give me their password, but that their problems will be fixed much faster if they do.

I see loads of scenarios every day when people benefit from giving out their passwords for various systems. I also hate SOX compliance with a passion. But then I also get very pissed off with all the chumps who don't conform with security policy.

GC_PaNzerFIN wrote:

It is useless to talk about security when ppl throw away all advice starting from most important one everyone should know by now, never tell your password to anyone. I wish one day people would start using their common sense, goes far in terms of security.
Common sense is a good thing - but loads of security policies are not grounded in common sense and are just complete bullshit. I deal with user accounts and directory services systems all the time and get very frustrated by how stupid some of these rules are.
GC_PaNzerFIN
Work and study @ Technical Uni
+528|6415|Finland

Of course, if it helps in house tech support you might ask for password. Especially if they physically bring the server to you. That is pretty guaranteed to be trustable, or someone is gonna get fired.

But it is not good idea to give passwords to anywhere outside your corporation for example. I am sure you understood my point.

I mean, comon. If I worked in same corporation as you, you being tech support for servers. That falls in the common sense box too to trust the guy.
3930K | H100i | RIVF | 16GB DDR3 | GTX 480 | AX750 | 800D | 512GB SSD | 3TB HDD | Xonar DX | W8
.Sup
be nice
+2,646|6454|The Twilight Zone
I use https://www.passpack.com/ for some passwords for others I have a dedicated USB key
https://www.shrani.si/f/3H/7h/45GTw71U/untitled-1.png
rdx-fx
...
+955|6592

Zimmer wrote:

At the end of the day, this site is safe, but you shouldn't in principle be putting in your passwords on random and potentially risky sites. Is that a better way of putting it?
Fair enough.
Thanks for being reasonable.
Defiance
Member
+438|6672

RDMC wrote:

I think this topic is kinda going off topic-ish.
Funny enough, it seems about as on topic as you could be. A valid question of password security was raised, tested, and concluded on in a thread about password security, but it's sad that it turned it to a silly fight.
FEOS
Bellicose Yankee Air Pirate
+1,182|6412|'Murka

rdx-fx wrote:

Zimmer wrote:

At the end of the day, this site is safe, but you shouldn't in principle be putting in your passwords on random and potentially risky sites. Is that a better way of putting it?
Fair enough.
Thanks for being reasonable.
Glad it got resolved all nice-like. Didn't mean to lob a chaos grenade.

My job is testing shit developed to trick-fuck people in various ways and also to see if our stuff is vulnerable to getting trick-fucked (very technical terms, to be sure). That includes PEBKAC issues. So when I see stuff like this, the first thing I think of is, "Why in the wide, wide, world of sports would you EVER do that?!" Then I think of all the little jewels I've seen run through our test ranges that have looked absolutely benign, even on forensic analysis, that were anything but. And all they relied on was a stupid user trick to work--and they worked well.
“Everybody is a genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is stupid.”
― Albert Einstein

Doing the popular thing is not always right. Doing the right thing is not always popular
Dilbert_X
The X stands for
+1,810|6107|eXtreme to the maX
Just got called by the phone scammers.
http://www.microsoft.com/australia/pres … phone-scam

You'd think they'd use a decent line or mike, could barely make out what they were saying.

"We have just detected your computer has downloaded a malicious virus, please go and turn your computer on and log into our website"
LOL Indians...

Still, my mother would have gone for it.
Русский военный корабль, иди на хуй!
PrivateVendetta
I DEMAND XMAS THEME
+704|6192|Roma
TBH, one of the first things I thought about was if this guy was harvesting passwords. But I know next to nothing about web languages or w/e.
And I guess it shows. My 'secure' password would only last 4 days..
I have a few, but generally don't care about the other ones, i only use them to make an account somewhere, wouldn't really care if someone got those accounts tbh.
https://static.bf2s.com/files/user/29388/stopped%20scrolling%21.png
RDMC
Enemy Wheelbarrow Spotted..!!
+736|6566|Area 51

Defiance wrote:

RDMC wrote:

I think this topic is kinda going off topic-ish.
Funny enough, it seems about as on topic as you could be. A valid question of password security was raised, tested, and concluded on in a thread about password security, but it's sad that it turned it to a silly fight.
True true. Hence why I said -ish.
Bertster7
Confused Pothead
+1,101|6582|SE London

GC_PaNzerFIN wrote:

Of course, if it helps in house tech support you might ask for password. Especially if they physically bring the server to you. That is pretty guaranteed to be trustable, or someone is gonna get fired.

But it is not good idea to give passwords to anywhere outside your corporation for example. I am sure you understood my point.

I mean, comon. If I worked in same corporation as you, you being tech support for servers. That falls in the common sense box too to trust the guy.
That's my point - common sense is the best security policy there is. Despite the fact that certain security policies in place don't adhere to basic common sense principles.

For example for a particular system if a user wants their password reset they need to phone the support team, give them a secure PIN code that only they know (which the support team then type into a window to verify whether it is accurate) and then get their new password mailed back to them.

That seems like a flawed system to me. A signed email is more secure than a phone call. Sending secure information by email is more secure than just telling it to someone over the phone. Yet this is a real security policy that needs to be adhered to where I work. Does it mke any sense? No, not one bit.
Mekstizzle
WALKER
+3,611|6622|London, England
Yeah I'll just go ahead and type in a password into some random website, if I used a fake password it would defeat the whole purpose and if I used a real one it's risky. No way man, No can do

Surely the first step in password security is making sure you keep it to yourself

Last edited by Mekstizzle (2010-10-22 03:22:56)

mtb0minime
minimember
+2,418|6655

Missed a few pages, Mek
13urnzz
Banned
+5,830|6498

LoL
Finray
Hup! Dos, Tres, Cuatro
+2,629|5789|Catherine Black

Mekstizzle wrote:

Yeah I'll just go ahead and type in a password into some random website, if I used a fake password it would defeat the whole purpose and if I used a real one it's risky. No way man, No can do

Surely the first step in password security is making sure you keep it to yourself
troll or dumbass
https://i.imgur.com/qwWEP9F.png
13urnzz
Banned
+5,830|6498

Finray wrote:

Mekstizzle wrote:

Yeah I'll just go ahead and type in a password into some random website, if I used a fake password it would defeat the whole purpose and if I used a real one it's risky. No way man, No can do

Surely the first step in password security is making sure you keep it to yourself
troll or dumbass
what a coincidence!

Board footer

Privacy Policy - © 2024 Jeff Minard