#keepassxc

14 posts · Last used 11d

Replying to
@Sheep_Overboard@infosec.exchange fwiw, when i went on my recent #TOTP crusade, #myGov was one of my accounts where i enabled TOTP for my logins, for which i use the inbuilt TOTP function in my redoubtable #KeePassXC app... on my penguin pooter. works a treat.
0
1
0
0
I wish #KeepassXC had #LUKS 2 like slot based encryption so you could have a #fido2 with pin in a slot to easy acces while having a password file for recovery etc. also i wish it had proper #fido2 #hmac extension based unlock instead of current security key support so you could use auto deletion on failed attempts and use a pin with low entropy safely and do user verification on high end security keys
2
0
0
0
«Sicherheitsrisiko — Russland-Verbindungen: Europäischer IT-Dienst Passwork in der Kritik: Eine Untersuchung deckt enge technologische Verbindungen des europäischen Passwort-Managers Passwork zu einem staatlich zertifizierten russischen Ableger auf.» Ich nutze @keepassxc@fosstodon.org, das ist Open-Source und ich sehe jegliche kommerzielle Passwordmanager kritisch, egal welches. 🔓 https://www.it-daily.net/shortnews/it-dienst-passwork-in-der-kritik #russland #passwork #itsicherheit #keepassxc #opensource #politik #sicherheitslucken #sicherheitsrisiko
26
6
11
0
Replying to
@jerry@infosec.exchange woohoo, it was far more indirect than for github, but i've eventually sussed out just now how to setup #KeePassXC #TOTP for my sharkey #blahajzone account 💃🥳🎉 next, masto, i hope 🤞
0
1
1
0
Replying to
@jerry@infosec.exchange small update, fwiw. i fiddled about more with my desktop linux #keepassxc #totp tool, & understand it a bit better now, so then i used one of my #github accounts as the initial totp guinea pig. it works really well, i am impressed & like it a lot. so, fingers crossed that masto can use this method too, & not merely a phone, which as said would count me out. 🤞 thinks to self... now to discover which of my various other online accounts are also amenable to this
0
2
1
0
@jerry@infosec.exchange hi Jerry. i vaguely recall a post of yours from several weeks / maybe some months? ago, where you said you were going to introduce mandatory #TOTP / #2FA for accounts. that alarmed me coz i do not have any TOTP facility atm, & tbh know nothing about this tech at all. as i largely use #sharkey rather than masto for my daily fediversing these days, i shoved this into the too hard basket, & forgot about it. today though i chanced across discovering that my long-term password manager, #keepassxc, also includes a TOTP capability. i've now begun investigating it, though atm i still don't really understand it. this reminded me of that recent? post of yours, so i thought maybe i'd use my masto account for my first TOTP guinea pig. i fell at the first hurdle. the masto settings section for 2FA says: Two-factor Auth If you enable two-factor authentication using an authenticator app, logging in will require you to be in possession of your phone, which will generate tokens for you to enter.i do not use my phone for anything other than calls + sms. i have no intention to change from using my linux pc for my fediversing & all other interwebzing, to my phone. does this mean then that my infosec.space account is doomed? eg, next time i log out, for whatever reason, i'll no longer be able to log back in, if you have activated mandatory 2FA, & i don't have it? i'd really hoped that belatedly discovering kpxc [on my linux desktop] has totp might be my solution, but now i'm only more confused. thx.
0
3
1
0
Ich hätte schon viel früher #TOTP​s direkt in #KeePassXC einpflegen sollen, statt mit #Aegis auf Android zu hantieren. Einfach dann Kontextmenü auf einen Eintrag, "TOTP kopieren" und fertig. Ihr könnt vorhandene Codes in Aegis über deren Eigenschaften → "Fortgeschritten" einfach als Schlüssel kopieren und den direkt im ersten Feld "Geheimer Schlüssel" der TOTP-Einrichtung für einen Zugang in KeepassXC konfigurieren, braucht keine weiteren Anpassungen.
0
0
0
0
You've seen all posts