Forumi


Povratak   PC Ekspert Forum > Ostalo > Razno
Ime
Lozinka

Odgovori
 
Uređivanje
Staro 01.04.2025., 06:34   #1
tomek@vz
Premium
Moj komp
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: München/Varaždin
Postovi: 4,350
Privatnost i sigurnost podataka i korisnika

Mislim da nam fali jedna tema za sve vijesti ovog tipa pa eto prvi post .
Citiraj:
Earlier this month, a threat actor going by Rose87168 claimed to have breached Oracle Cloud's federated SSO servers and exfiltrated around 6 million records, affecting over 144,000 Oracle clients. The hacker provided an internal customer list and threatened to sell the data unless clients paid to remove their data from the trove, which included single sign-on credentials, Lightweight Directory Access Protocol passwords, OAuth2 keys, tenant data, and more. Rose87168 has also solicited help from the hacking community to crack the hashed passwords in trade for some of the data.
> Techspot


__________________
Lenovo LOQ 15AHP9: AMD Ryzen 5 8645HS / 16GB DDR5 / Micron M.2 2230 1TB / Sandisk Extreme Pro 1TB / Radeon 760M + Geforce RTX 4050 / Windows 11 Pro
Acer Aspire V3-574G: Intel i3 5005U / 8GB DDR3 / Seagate 1TB HDD / Geforce GT 940M / OpenSuse Tumbleweed

Zadnje izmijenjeno od: tomek@vz. 01.04.2025. u 06:45.
tomek@vz je offline   Reply With Quote
Staro 01.04.2025., 11:03   #2
OuttaControl
Premium
Moj komp
 
OuttaControl's Avatar
 
Datum registracije: Feb 2007
Lokacija: Dalmacija
Postovi: 5,738
Enkriptirani passwordi, evo jos jedna sijeda.
Inace funfact svaki al bas svaki apac i vecina latamovaca koje sam intervjuirao koriste iskljucivo enkriptiranje passworda. U americi pola pola a u europi vecina hashira.
OuttaControl je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Staro 01.04.2025., 16:45   #3
mkey
Premium
Moj komp
 
Datum registracije: Sep 2018
Lokacija: tu
Postovi: 3,056
Jesam li u zabludi ako smatram da je hashiranje pouzdanija opcija?
__________________
Citiraj:
Autor George Carlin
But there’s a reason. There’s a reason. There’s a reason for this, there’s a reason education sucks, and it’s the same reason that it will never, ever, ever be fixed. It’s never gonna get any better. Don’t look for it. Be happy with what you got. Because the owners of this country don't want that. I'm talking about the real owners now, the real owners, the big wealthy business interests that control things and make all the important decisions. Forget the politicians. The politicians are put there to give you the idea that you have freedom of choice. You don't. You have no choice. You have owners. They own you. They own everything. They own all the important land. They own and control the corporations. They’ve long since bought and paid for the senate, the congress, the state houses, the city halls, they got the judges in their back pockets and they own all the big media companies so they control just about all of the news and information you get to hear. They got you by the balls. They spend billions of dollars every year lobbying, lobbying, to get what they want. Well, we know what they want. They want more for themselves and less for everybody else, but I'll tell you what they don’t want: They don’t want a population of citizens capable of critical thinking. They don’t want well informed, well educated people capable of critical thinking. They’re not interested in that. That doesn’t help them. Thats against their interests. Thats right. They don’t want people who are smart enough to sit around a kitchen table to figure out how badly they’re getting f*cked by a system that threw them overboard 30 f*cking years ago. They don’t want that. You know what they want? They want obedient workers. Obedient workers. People who are just smart enough to run the machines and do the paperwork, and just dumb enough to passively accept all these increasingly shittier jobs with the lower pay, the longer hours, the reduced benefits, the end of overtime and the vanishing pension that disappears the minute you go to collect it, and now they’re coming for your Social Security money. They want your retirement money. They want it back so they can give it to their criminal friends on Wall Street, and you know something? They’ll get it. They’ll get it all from you, sooner or later, 'cause they own this f*cking place. It's a big club, and you ain’t in it. You and I are not in the big club. And by the way, it's the same big club they use to beat you over the head with all day long when they tell you what to believe. All day long beating you over the head in their media telling you what to believe, what to think and what to buy. The table is tilted folks. The game is rigged, and nobody seems to notice, nobody seems to care. Good honest hard-working people -- white collar, blue collar, it doesn’t matter what color shirt you have on -- good honest hard-working people continue -- these are people of modest means -- continue to elect these rich c*cksuckers who don’t give a f*ck about them. They don’t give a f*ck about you. They don’t give a f*ck about you. They don't care about you at all -- at all -- at all. And nobody seems to notice, nobody seems to care. That's what the owners count on; the fact that Americans will probably remain willfully ignorant of the big red, white and blue dick that's being jammed up their assholes everyday. Because the owners of this country know the truth: it's called the American Dream, because you have to be asleep to believe it.
mkey je offline   Reply With Quote
Staro 01.04.2025., 18:52   #4
OuttaControl
Premium
Moj komp
 
OuttaControl's Avatar
 
Datum registracije: Feb 2007
Lokacija: Dalmacija
Postovi: 5,738
Apsolutno, enkripcija je dvosmjerna funkcija dakle naprabljena da se moze vratiti sa kljucem, hashiranje je jednosmjerna. U implementaciji se jos posoli i hashira vise puta, a pametni i lijeni koriste gotov library i onda si miran i niko nece iz breacha izvuc password.
OuttaControl je offline   Reply With Quote
Staro 01.04.2025., 20:51   #5
mkey
Premium
Moj komp
 
Datum registracije: Sep 2018
Lokacija: tu
Postovi: 3,056
Po meni jedina mana hashiranja je što se password ne može povratiti, ali uvijek se može postaviti novi.
__________________
Citiraj:
Autor George Carlin
But there’s a reason. There’s a reason. There’s a reason for this, there’s a reason education sucks, and it’s the same reason that it will never, ever, ever be fixed. It’s never gonna get any better. Don’t look for it. Be happy with what you got. Because the owners of this country don't want that. I'm talking about the real owners now, the real owners, the big wealthy business interests that control things and make all the important decisions. Forget the politicians. The politicians are put there to give you the idea that you have freedom of choice. You don't. You have no choice. You have owners. They own you. They own everything. They own all the important land. They own and control the corporations. They’ve long since bought and paid for the senate, the congress, the state houses, the city halls, they got the judges in their back pockets and they own all the big media companies so they control just about all of the news and information you get to hear. They got you by the balls. They spend billions of dollars every year lobbying, lobbying, to get what they want. Well, we know what they want. They want more for themselves and less for everybody else, but I'll tell you what they don’t want: They don’t want a population of citizens capable of critical thinking. They don’t want well informed, well educated people capable of critical thinking. They’re not interested in that. That doesn’t help them. Thats against their interests. Thats right. They don’t want people who are smart enough to sit around a kitchen table to figure out how badly they’re getting f*cked by a system that threw them overboard 30 f*cking years ago. They don’t want that. You know what they want? They want obedient workers. Obedient workers. People who are just smart enough to run the machines and do the paperwork, and just dumb enough to passively accept all these increasingly shittier jobs with the lower pay, the longer hours, the reduced benefits, the end of overtime and the vanishing pension that disappears the minute you go to collect it, and now they’re coming for your Social Security money. They want your retirement money. They want it back so they can give it to their criminal friends on Wall Street, and you know something? They’ll get it. They’ll get it all from you, sooner or later, 'cause they own this f*cking place. It's a big club, and you ain’t in it. You and I are not in the big club. And by the way, it's the same big club they use to beat you over the head with all day long when they tell you what to believe. All day long beating you over the head in their media telling you what to believe, what to think and what to buy. The table is tilted folks. The game is rigged, and nobody seems to notice, nobody seems to care. Good honest hard-working people -- white collar, blue collar, it doesn’t matter what color shirt you have on -- good honest hard-working people continue -- these are people of modest means -- continue to elect these rich c*cksuckers who don’t give a f*ck about them. They don’t give a f*ck about you. They don’t give a f*ck about you. They don't care about you at all -- at all -- at all. And nobody seems to notice, nobody seems to care. That's what the owners count on; the fact that Americans will probably remain willfully ignorant of the big red, white and blue dick that's being jammed up their assholes everyday. Because the owners of this country know the truth: it's called the American Dream, because you have to be asleep to believe it.
mkey je offline   Reply With Quote
Staro 01.04.2025., 21:41   #6
OuttaControl
Premium
Moj komp
 
OuttaControl's Avatar
 
Datum registracije: Feb 2007
Lokacija: Dalmacija
Postovi: 5,738
Ne moze uvijek ali ako spremas password moras ga hashat i to je to, strasno je sto previse programera to ne radi, i seniori i leadovi koji su se javljali na te pozicije sa 20+ godina iskustva....
OuttaControl je offline   Reply With Quote
Staro 01.04.2025., 22:29   #7
medo
#erase startup-config
Moj komp
 
medo's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 3,500
Citiraj:
Autor mkey Pregled postova
Po meni jedina mana hashiranja je što se password ne može povratiti, ali uvijek se može postaviti novi.

Poanta hashiranja je da nije reverzibilno. U protivnom puno toga ne bi radilo ukkjučujući i potpisivanje certova.
__________________
"It's not a bug, it's a feature!"
1N6pJsvusP7afu23qs1uBscK16wfcG7C8m
medo je offline   Reply With Quote
Staro 01.04.2025., 23:07   #8
mkey
Premium
Moj komp
 
Datum registracije: Sep 2018
Lokacija: tu
Postovi: 3,056
Citiraj:
Autor OuttaControl Pregled postova
Ne moze uvijek ali ako spremas password moras ga hashat i to je to, strasno je sto previse programera to ne radi, i seniori i leadovi koji su se javljali na te pozicije sa 20+ godina iskustva....
Mislim na postavljanje lozinke za accounte na raznim web servisima. Na kraju i tako se podrazumijeva da vlasnik accounta ima ekskluzivni pristup svom mailu.

Mislim da oni koji to ne rade ne rade zato jer je nekada davno bilo tako napravljeno i jednostavno to nitko nije promijenio jer nitko nije tako naložio. Pa onda padnu razne pentestove i promijene to zato jer im je tako naloženo
__________________
Citiraj:
Autor George Carlin
But there’s a reason. There’s a reason. There’s a reason for this, there’s a reason education sucks, and it’s the same reason that it will never, ever, ever be fixed. It’s never gonna get any better. Don’t look for it. Be happy with what you got. Because the owners of this country don't want that. I'm talking about the real owners now, the real owners, the big wealthy business interests that control things and make all the important decisions. Forget the politicians. The politicians are put there to give you the idea that you have freedom of choice. You don't. You have no choice. You have owners. They own you. They own everything. They own all the important land. They own and control the corporations. They’ve long since bought and paid for the senate, the congress, the state houses, the city halls, they got the judges in their back pockets and they own all the big media companies so they control just about all of the news and information you get to hear. They got you by the balls. They spend billions of dollars every year lobbying, lobbying, to get what they want. Well, we know what they want. They want more for themselves and less for everybody else, but I'll tell you what they don’t want: They don’t want a population of citizens capable of critical thinking. They don’t want well informed, well educated people capable of critical thinking. They’re not interested in that. That doesn’t help them. Thats against their interests. Thats right. They don’t want people who are smart enough to sit around a kitchen table to figure out how badly they’re getting f*cked by a system that threw them overboard 30 f*cking years ago. They don’t want that. You know what they want? They want obedient workers. Obedient workers. People who are just smart enough to run the machines and do the paperwork, and just dumb enough to passively accept all these increasingly shittier jobs with the lower pay, the longer hours, the reduced benefits, the end of overtime and the vanishing pension that disappears the minute you go to collect it, and now they’re coming for your Social Security money. They want your retirement money. They want it back so they can give it to their criminal friends on Wall Street, and you know something? They’ll get it. They’ll get it all from you, sooner or later, 'cause they own this f*cking place. It's a big club, and you ain’t in it. You and I are not in the big club. And by the way, it's the same big club they use to beat you over the head with all day long when they tell you what to believe. All day long beating you over the head in their media telling you what to believe, what to think and what to buy. The table is tilted folks. The game is rigged, and nobody seems to notice, nobody seems to care. Good honest hard-working people -- white collar, blue collar, it doesn’t matter what color shirt you have on -- good honest hard-working people continue -- these are people of modest means -- continue to elect these rich c*cksuckers who don’t give a f*ck about them. They don’t give a f*ck about you. They don’t give a f*ck about you. They don't care about you at all -- at all -- at all. And nobody seems to notice, nobody seems to care. That's what the owners count on; the fact that Americans will probably remain willfully ignorant of the big red, white and blue dick that's being jammed up their assholes everyday. Because the owners of this country know the truth: it's called the American Dream, because you have to be asleep to believe it.
mkey je offline   Reply With Quote
Staro 02.04.2025., 11:51   #9
tomek@vz
Premium
Moj komp
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: München/Varaždin
Postovi: 4,350
Citiraj:
Google recently announced two major initiatives aimed at enhancing web security, with the ultimate goal of making encryption and certificate management more reliable and resilient against cybercrime. These new features are part of the Chrome Root Program, which, according to Google, demonstrates the company's commitment to strengthening online security through its Chrome browser.

Citiraj:
Google explained that MPIC enhances existing methods for validating domain legitimacy before a Certificate Authority issues a new TLS certificate. The current process, known as "domain control validation," can be exploited in various ways, potentially leading to fraudulent certificate issuance. MPIC aims to mitigate these risks by introducing additional verification perspectives.

> Techspot
__________________
Lenovo LOQ 15AHP9: AMD Ryzen 5 8645HS / 16GB DDR5 / Micron M.2 2230 1TB / Sandisk Extreme Pro 1TB / Radeon 760M + Geforce RTX 4050 / Windows 11 Pro
Acer Aspire V3-574G: Intel i3 5005U / 8GB DDR3 / Seagate 1TB HDD / Geforce GT 940M / OpenSuse Tumbleweed
tomek@vz je offline   Reply With Quote
Staro 03.04.2025., 07:14   #10
tomek@vz
Premium
Moj komp
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: München/Varaždin
Postovi: 4,350
Citiraj:
A joint investigation found that at least five popular VPN apps on the App Store and Google Play have ties to Qihoo 360, a Chinese company with military links. Apple has since removed two of the apps but has not confirmed the status of the remaining three, which 9to5Mac notes have "racked up more than a million downloads." The five apps in question are Turbo VPN, VPN Proxy Master, Thunder VPN, Snap VPN, and Signal Secure VPN (not associated with the Signal messaging app). The Financial Times reports: At least five free virtual private networks (VPNs) available through the US tech groups' app stores have links to Shanghai-listed Qihoo 360, according to a new report by research group Tech Transparency Project, as well as additional findings by the Financial Times. Qihoo, formally known as 360 Security Technology, was sanctioned by the US in 2020 for alleged Chinese military links. The US Department of Defense later added Qihoo to a list of Chinese military-affiliated companies [...] In recent recruitment listings, Guangzhou Lianchuang says its apps operate in more than 220 countries and that it has 10mn daily users. It is currently hiring for a position whose responsibilities include "monitoring and analyzing platform data." The right candidate will be "well-versed in American culture," the posting says.
__________________
Lenovo LOQ 15AHP9: AMD Ryzen 5 8645HS / 16GB DDR5 / Micron M.2 2230 1TB / Sandisk Extreme Pro 1TB / Radeon 760M + Geforce RTX 4050 / Windows 11 Pro
Acer Aspire V3-574G: Intel i3 5005U / 8GB DDR3 / Seagate 1TB HDD / Geforce GT 940M / OpenSuse Tumbleweed
tomek@vz je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Staro 03.04.2025., 07:52   #11
spiderhr
Premium
 
spiderhr's Avatar
 
Datum registracije: Jul 2021
Lokacija: Sesvete
Postovi: 893
Je najbolje je kad negdje zatražim izgubljenu lozinku pa mi je oni vrate u mailu.
__________________
tomek@vz: ajd nemoj | Mali Čile SAD Češka Peru | Windows Free
spiderhr je offline   Reply With Quote
Staro 03.04.2025., 15:53   #12
medo
#erase startup-config
Moj komp
 
medo's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 3,500
Dogodilo mi se. Ne jednom
__________________
"It's not a bug, it's a feature!"
1N6pJsvusP7afu23qs1uBscK16wfcG7C8m
medo je offline   Reply With Quote
Staro 03.04.2025., 19:22   #13
sinisa1989
Bazinga
Moj komp
 
sinisa1989's Avatar
 
Datum registracije: Nov 2007
Lokacija: Križevci
Postovi: 3,922
Ja sam dobio zahtjev za implementacijom raw passworda. Želja je kupcu prikazati password na ekranu kad dođe potpisati ugovor
__________________
The best place to hide a dead body
is page 2 of Google search results.
sinisa1989 je offline   Reply With Quote
Staro 03.04.2025., 21:23   #14
OuttaControl
Premium
Moj komp
 
OuttaControl's Avatar
 
Datum registracije: Feb 2007
Lokacija: Dalmacija
Postovi: 5,738
Imao sam nešto slicno, rjesio sam tako da sam ima odvojenu tablicu za tempPass, enkriptirano sa hashom emaila i unique saltom, acceptanjem termsa se pass hashira, i temp se hard deletea. Nije idealno al risk accepted
OuttaControl je offline   Reply With Quote
Staro 04.04.2025., 09:14   #15
sinisa1989
Bazinga
Moj komp
 
sinisa1989's Avatar
 
Datum registracije: Nov 2007
Lokacija: Križevci
Postovi: 3,922
Ovo čak nije ni bio temp pass. Glavni razlog je bio "to su kupci koji ne vole mijenjati lozinke te koriste jednu za sve servise jer ne žele pamtiti za svaki servis posebno". Moram priznati da sam ostao bez teksta. Uspio sam ih nagovoriti na 8 random slova i brojeva (ne i random znakova). Da ne pričam da je u jednom momentu uletila ideja o četveroznamenkastom PIN-u
__________________
The best place to hide a dead body
is page 2 of Google search results.
sinisa1989 je offline   Reply With Quote
Staro 05.04.2025., 00:07   #16
OuttaControl
Premium
Moj komp
 
OuttaControl's Avatar
 
Datum registracije: Feb 2007
Lokacija: Dalmacija
Postovi: 5,738
Bas to je najveci problem sto svi koriste isti pass za sve, hakens na jednom haknio si svagdi. A znam i za takve klijente i ovaj iz skucaja gore je imao slicnu zelju ali kad sam mu sa ozbiljnom pogledom rekao ne shvatio me je ozbiljno pa smo trazili alternative.

Svega sam se nagledao u karijeri, brojevi kreditne kartice, cvv , exp date, drzavna firma, jedno 50k kartica u pure plain textu, site imao sql injectable polja.... to je bilo prije pci dss, sad je to malo bolje, svima naporno ali bolje iako i dalje ima svega.

2 factor auth na svemu bitnom, passkey je dobra stvar ali ja volim znat svoj pass.
Razlicit pass na svemu bitnom, a na nebitnom ja jos nakon istog passa dodam domenu, dovoljno da skripte failaju a skripte su 99.999 posto pokusaja hackanja, nece se skripta pretjerano trudit pokusavat skuzit password, par matchanih passworda ce probat ako ne prolazi ide dalje.
Isto tako volim korisitit mail+nesto@gmail na gmailu tako da znam odakle breach dolazi, problem je sto dosta sajtova ne dozvoljava + u emailu.

Uglavnom se najbitnije zastiti od skripti, jer rijetko kad je osoba ko osoba meta napada, onda se cesce ide na social engineering. Sad sta ce nam ai/ml donit koji je sposoban prokuzit dodavanje domene i emaila u password, tesko je znat, ali opet mala je vjerojatnost da ce neko koristiti skupe resurse da skripta pokusa pogoditi razliku passworda ukoliko nisi highly exposed persona.
OuttaControl je offline   Reply With Quote
Staro 05.04.2025., 07:53   #17
tomek@vz
Premium
Moj komp
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: München/Varaždin
Postovi: 4,350
Sve tekve p***rije proizlaze iz odluka onih koji koncept IT-a ni sigurnosti ne razumiju. Al hebiga tako je to kad zivimo u svijetu gdje vlada "Petrov princip" a korisnici ne shvacaju istu dovoljno ozbiljno


__________________
Lenovo LOQ 15AHP9: AMD Ryzen 5 8645HS / 16GB DDR5 / Micron M.2 2230 1TB / Sandisk Extreme Pro 1TB / Radeon 760M + Geforce RTX 4050 / Windows 11 Pro
Acer Aspire V3-574G: Intel i3 5005U / 8GB DDR3 / Seagate 1TB HDD / Geforce GT 940M / OpenSuse Tumbleweed
tomek@vz je offline   Reply With Quote
Staro 05.04.2025., 13:04   #18
medo
#erase startup-config
Moj komp
 
medo's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 3,500
Privatnost i sigurnost podataka i korisnika

Jednostavno rečeno, loš šef će reći: “napravi kako ti se kaže”. Dobar šef će te pitati što treba napraviti…

Za sve ostalo tu je Yubikey



Yebemu, Dave…
__________________
"It's not a bug, it's a feature!"
1N6pJsvusP7afu23qs1uBscK16wfcG7C8m

Zadnje izmijenjeno od: medo. 05.04.2025. u 13:09.
medo je offline   Reply With Quote
Staro 05.04.2025., 15:16   #19
Nikky
Moderator
 
Nikky's Avatar
 
Datum registracije: Sep 2006
Lokacija: St
Postovi: 23,365
Dave će zahebat sve živo a pogotovo zdrav razum 😎
Nikky je offline   Reply With Quote
Staro 05.04.2025., 16:02   #20
Pupo
Nikad sit, uvijek žedan
Moj komp
 
Pupo's Avatar
 
Datum registracije: Jun 2005
Lokacija: Vallis Aurea / ZG
Postovi: 8,173
Citiraj:
Autor OuttaControl Pregled postova
Bas to je najveci problem sto svi koriste isti pass za sve, hakens na jednom haknio si svagdi. A znam i za takve klijente i ovaj iz skucaja gore je imao slicnu zelju ali kad sam mu sa ozbiljnom pogledom rekao ne shvatio me je ozbiljno pa smo trazili alternative.

Svega sam se nagledao u karijeri, brojevi kreditne kartice, cvv , exp date, drzavna firma, jedno 50k kartica u pure plain textu, site imao sql injectable polja.... to je bilo prije pci dss, sad je to malo bolje, svima naporno ali bolje iako i dalje ima svega.

2 factor auth na svemu bitnom, passkey je dobra stvar ali ja volim znat svoj pass.
Razlicit pass na svemu bitnom, a na nebitnom ja jos nakon istog passa dodam domenu, dovoljno da skripte failaju a skripte su 99.999 posto pokusaja hackanja, nece se skripta pretjerano trudit pokusavat skuzit password, par matchanih passworda ce probat ako ne prolazi ide dalje.
Isto tako volim korisitit mail+nesto@gmail na gmailu tako da znam odakle breach dolazi, problem je sto dosta sajtova ne dozvoljava + u emailu.

Uglavnom se najbitnije zastiti od skripti, jer rijetko kad je osoba ko osoba meta napada, onda se cesce ide na social engineering. Sad sta ce nam ai/ml donit koji je sposoban prokuzit dodavanje domene i emaila u password, tesko je znat, ali opet mala je vjerojatnost da ce neko koristiti skupe resurse da skripta pokusa pogoditi razliku passworda ukoliko nisi highly exposed persona.


Prije godinu i pol nam ukinuli passworde na poslu. Najbolja fora i odluka ikad.
__________________
Sent from AS/400.
Pupo je offline   Reply With Quote
Staro 05.04.2025., 16:36   #21
medo
#erase startup-config
Moj komp
 
medo's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 3,500
Privatnost i sigurnost podataka i korisnika

To i ja pokušavam uvesti već neko vrijeme. Mojim kolegama se to čini kao puno posla jer imamo puno internih appova (developerima pogotovo) a managementu se to čini kao ukidanje autorizacije

A svi su svjesni da je hw key puno sigurniji od passworda pogotovo onih zaljepljenih za kućište laptopa
__________________
"It's not a bug, it's a feature!"
1N6pJsvusP7afu23qs1uBscK16wfcG7C8m
medo je offline   Reply With Quote
Staro 05.04.2025., 20:17   #22
mkey
Premium
Moj komp
 
Datum registracije: Sep 2018
Lokacija: tu
Postovi: 3,056
Citiraj:
Autor medo Pregled postova
A svi su svjesni da je hw key puno sigurniji od passworda pogotovo onih zaljepljenih za kućište laptopa
Koja je u tom smislu razlika između ključa ukopčanog u laptop i password nalijepljenog na laptop?
__________________
Citiraj:
Autor George Carlin
But there’s a reason. There’s a reason. There’s a reason for this, there’s a reason education sucks, and it’s the same reason that it will never, ever, ever be fixed. It’s never gonna get any better. Don’t look for it. Be happy with what you got. Because the owners of this country don't want that. I'm talking about the real owners now, the real owners, the big wealthy business interests that control things and make all the important decisions. Forget the politicians. The politicians are put there to give you the idea that you have freedom of choice. You don't. You have no choice. You have owners. They own you. They own everything. They own all the important land. They own and control the corporations. They’ve long since bought and paid for the senate, the congress, the state houses, the city halls, they got the judges in their back pockets and they own all the big media companies so they control just about all of the news and information you get to hear. They got you by the balls. They spend billions of dollars every year lobbying, lobbying, to get what they want. Well, we know what they want. They want more for themselves and less for everybody else, but I'll tell you what they don’t want: They don’t want a population of citizens capable of critical thinking. They don’t want well informed, well educated people capable of critical thinking. They’re not interested in that. That doesn’t help them. Thats against their interests. Thats right. They don’t want people who are smart enough to sit around a kitchen table to figure out how badly they’re getting f*cked by a system that threw them overboard 30 f*cking years ago. They don’t want that. You know what they want? They want obedient workers. Obedient workers. People who are just smart enough to run the machines and do the paperwork, and just dumb enough to passively accept all these increasingly shittier jobs with the lower pay, the longer hours, the reduced benefits, the end of overtime and the vanishing pension that disappears the minute you go to collect it, and now they’re coming for your Social Security money. They want your retirement money. They want it back so they can give it to their criminal friends on Wall Street, and you know something? They’ll get it. They’ll get it all from you, sooner or later, 'cause they own this f*cking place. It's a big club, and you ain’t in it. You and I are not in the big club. And by the way, it's the same big club they use to beat you over the head with all day long when they tell you what to believe. All day long beating you over the head in their media telling you what to believe, what to think and what to buy. The table is tilted folks. The game is rigged, and nobody seems to notice, nobody seems to care. Good honest hard-working people -- white collar, blue collar, it doesn’t matter what color shirt you have on -- good honest hard-working people continue -- these are people of modest means -- continue to elect these rich c*cksuckers who don’t give a f*ck about them. They don’t give a f*ck about you. They don’t give a f*ck about you. They don't care about you at all -- at all -- at all. And nobody seems to notice, nobody seems to care. That's what the owners count on; the fact that Americans will probably remain willfully ignorant of the big red, white and blue dick that's being jammed up their assholes everyday. Because the owners of this country know the truth: it's called the American Dream, because you have to be asleep to believe it.
mkey je offline   Reply With Quote
Staro 05.04.2025., 20:59   #23
medo
#erase startup-config
Moj komp
 
medo's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 3,500
Ako nije biometrijski treba ti PIN za hw key kao i za smart karticu.
__________________
"It's not a bug, it's a feature!"
1N6pJsvusP7afu23qs1uBscK16wfcG7C8m
medo je offline   Reply With Quote
Staro 05.04.2025., 21:11   #24
mkey
Premium
Moj komp
 
Datum registracije: Sep 2018
Lokacija: tu
Postovi: 3,056
Dakle, opet naljepnica, ovaj put s pinom.
__________________
Citiraj:
Autor George Carlin
But there’s a reason. There’s a reason. There’s a reason for this, there’s a reason education sucks, and it’s the same reason that it will never, ever, ever be fixed. It’s never gonna get any better. Don’t look for it. Be happy with what you got. Because the owners of this country don't want that. I'm talking about the real owners now, the real owners, the big wealthy business interests that control things and make all the important decisions. Forget the politicians. The politicians are put there to give you the idea that you have freedom of choice. You don't. You have no choice. You have owners. They own you. They own everything. They own all the important land. They own and control the corporations. They’ve long since bought and paid for the senate, the congress, the state houses, the city halls, they got the judges in their back pockets and they own all the big media companies so they control just about all of the news and information you get to hear. They got you by the balls. They spend billions of dollars every year lobbying, lobbying, to get what they want. Well, we know what they want. They want more for themselves and less for everybody else, but I'll tell you what they don’t want: They don’t want a population of citizens capable of critical thinking. They don’t want well informed, well educated people capable of critical thinking. They’re not interested in that. That doesn’t help them. Thats against their interests. Thats right. They don’t want people who are smart enough to sit around a kitchen table to figure out how badly they’re getting f*cked by a system that threw them overboard 30 f*cking years ago. They don’t want that. You know what they want? They want obedient workers. Obedient workers. People who are just smart enough to run the machines and do the paperwork, and just dumb enough to passively accept all these increasingly shittier jobs with the lower pay, the longer hours, the reduced benefits, the end of overtime and the vanishing pension that disappears the minute you go to collect it, and now they’re coming for your Social Security money. They want your retirement money. They want it back so they can give it to their criminal friends on Wall Street, and you know something? They’ll get it. They’ll get it all from you, sooner or later, 'cause they own this f*cking place. It's a big club, and you ain’t in it. You and I are not in the big club. And by the way, it's the same big club they use to beat you over the head with all day long when they tell you what to believe. All day long beating you over the head in their media telling you what to believe, what to think and what to buy. The table is tilted folks. The game is rigged, and nobody seems to notice, nobody seems to care. Good honest hard-working people -- white collar, blue collar, it doesn’t matter what color shirt you have on -- good honest hard-working people continue -- these are people of modest means -- continue to elect these rich c*cksuckers who don’t give a f*ck about them. They don’t give a f*ck about you. They don’t give a f*ck about you. They don't care about you at all -- at all -- at all. And nobody seems to notice, nobody seems to care. That's what the owners count on; the fact that Americans will probably remain willfully ignorant of the big red, white and blue dick that's being jammed up their assholes everyday. Because the owners of this country know the truth: it's called the American Dream, because you have to be asleep to believe it.
mkey je offline   Reply With Quote
Staro 05.04.2025., 21:43   #25
xlr
49%winner
Moj komp
 
xlr's Avatar
 
Datum registracije: Sep 2007
Lokacija: PU
Postovi: 9,800
U korporativnon ojruzenju, sto je na kraju sigurnije, pin koji se u pravilu nikad ne mijenja (moze li se na yubikeyu uopce promjeniti bez resetiranja hw keya?) ili pass koji najcesce ima rok trajanja 3-6 mjeseci? Hm hm
__________________
Keep calm and fastboot oem unlock.
xlr je offline   Reply With Quote
Staro 05.04.2025., 21:47   #26
tomek@vz
Premium
Moj komp
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: München/Varaždin
Postovi: 4,350
Citiraj:
Autor mkey Pregled postova
Dakle, opet naljepnica, ovaj put s pinom.

Nije bas tak jednostavno. Passkey je idejno barem dobar koncept - kak se bude u praksi pokazalo vidjet cemo. Pain in the ass bude jedino ako ti krepa uredaj koji sluzi kao "baza" pa kad sve to treba isponova authentificirat i prebacit na novi uredaj. Obican korisnik ce popizdit. Ubikey mozes stekat kolko hoces ali ako nemas valjan otisak prsta mos se fuckat. Vektor napada je time osjetno smanjen barem sa te strane.
__________________
Lenovo LOQ 15AHP9: AMD Ryzen 5 8645HS / 16GB DDR5 / Micron M.2 2230 1TB / Sandisk Extreme Pro 1TB / Radeon 760M + Geforce RTX 4050 / Windows 11 Pro
Acer Aspire V3-574G: Intel i3 5005U / 8GB DDR3 / Seagate 1TB HDD / Geforce GT 940M / OpenSuse Tumbleweed
tomek@vz je offline   Reply With Quote
Staro 05.04.2025., 21:51   #27
Pupo
Nikad sit, uvijek žedan
Moj komp
 
Pupo's Avatar
 
Datum registracije: Jun 2005
Lokacija: Vallis Aurea / ZG
Postovi: 8,173
Citiraj:
Autor xlr Pregled postova
U korporativnon ojruzenju, sto je na kraju sigurnije, pin koji se u pravilu nikad ne mijenja (moze li se na yubikeyu uopce promjeniti bez resetiranja hw keya?) ili pass koji najcesce ima rok trajanja 3-6 mjeseci? Hm hm
Uvijek mozes ic na neki authenticator app. (Da, nije naj naj sigurnije, znam, al je bolje od passworda)
__________________
Sent from AS/400.
Pupo je offline   Reply With Quote
Staro 05.04.2025., 22:05   #28
xlr
49%winner
Moj komp
 
xlr's Avatar
 
Datum registracije: Sep 2007
Lokacija: PU
Postovi: 9,800
Citiraj:
Autor Pupo Pregled postova
Uvijek mozes ic na neki authenticator app. (Da, nije naj naj sigurnije, znam, al je bolje od passworda)
Da, nisam spomenuo, 2FA u principu smatram defaultom ako se koristi password.

I sam imam hw key s pin-om, ali sam u medjuvremenu skuzio da se pin moze promjeniti bez reseta keya. Vjerojatno se onda moze mijenjati i na yubikeyu (ja imam token2 keyeve):
https://www.token2.com/site/page/fid...do2-manage-exe
__________________
Keep calm and fastboot oem unlock.
xlr je offline   Reply With Quote
Staro 05.04.2025., 22:57   #29
mkey
Premium
Moj komp
 
Datum registracije: Sep 2018
Lokacija: tu
Postovi: 3,056
Citiraj:
Autor tomek@vz Pregled postova
Nije bas tak jednostavno. Passkey je idejno barem dobar koncept - kak se bude u praksi pokazalo vidjet cemo. Pain in the ass bude jedino ako ti krepa uredaj koji sluzi kao "baza" pa kad sve to treba isponova authentificirat i prebacit na novi uredaj. Obican korisnik ce popizdit. Ubikey mozes stekat kolko hoces ali ako nemas valjan otisak prsta mos se fuckat. Vektor napada je time osjetno smanjen barem sa te strane.
Ja govorim da, ako je problem laptop s accountom zaštićenim passwordom gdje je password nalijepljen na laptop, je isti problem kod laptopa koji koristi ključ + pin gdje je pin zabilježen na laptopu. Ključ nije rješenje problema lijepljenja lozinke na laptop. Kao što niti neki auth app, koji je podešen da samo traži potvrdu pristupa, nije garancija da neki lumen neće potvrditi, iako sam nije zatražio pristup.
__________________
Citiraj:
Autor George Carlin
But there’s a reason. There’s a reason. There’s a reason for this, there’s a reason education sucks, and it’s the same reason that it will never, ever, ever be fixed. It’s never gonna get any better. Don’t look for it. Be happy with what you got. Because the owners of this country don't want that. I'm talking about the real owners now, the real owners, the big wealthy business interests that control things and make all the important decisions. Forget the politicians. The politicians are put there to give you the idea that you have freedom of choice. You don't. You have no choice. You have owners. They own you. They own everything. They own all the important land. They own and control the corporations. They’ve long since bought and paid for the senate, the congress, the state houses, the city halls, they got the judges in their back pockets and they own all the big media companies so they control just about all of the news and information you get to hear. They got you by the balls. They spend billions of dollars every year lobbying, lobbying, to get what they want. Well, we know what they want. They want more for themselves and less for everybody else, but I'll tell you what they don’t want: They don’t want a population of citizens capable of critical thinking. They don’t want well informed, well educated people capable of critical thinking. They’re not interested in that. That doesn’t help them. Thats against their interests. Thats right. They don’t want people who are smart enough to sit around a kitchen table to figure out how badly they’re getting f*cked by a system that threw them overboard 30 f*cking years ago. They don’t want that. You know what they want? They want obedient workers. Obedient workers. People who are just smart enough to run the machines and do the paperwork, and just dumb enough to passively accept all these increasingly shittier jobs with the lower pay, the longer hours, the reduced benefits, the end of overtime and the vanishing pension that disappears the minute you go to collect it, and now they’re coming for your Social Security money. They want your retirement money. They want it back so they can give it to their criminal friends on Wall Street, and you know something? They’ll get it. They’ll get it all from you, sooner or later, 'cause they own this f*cking place. It's a big club, and you ain’t in it. You and I are not in the big club. And by the way, it's the same big club they use to beat you over the head with all day long when they tell you what to believe. All day long beating you over the head in their media telling you what to believe, what to think and what to buy. The table is tilted folks. The game is rigged, and nobody seems to notice, nobody seems to care. Good honest hard-working people -- white collar, blue collar, it doesn’t matter what color shirt you have on -- good honest hard-working people continue -- these are people of modest means -- continue to elect these rich c*cksuckers who don’t give a f*ck about them. They don’t give a f*ck about you. They don’t give a f*ck about you. They don't care about you at all -- at all -- at all. And nobody seems to notice, nobody seems to care. That's what the owners count on; the fact that Americans will probably remain willfully ignorant of the big red, white and blue dick that's being jammed up their assholes everyday. Because the owners of this country know the truth: it's called the American Dream, because you have to be asleep to believe it.
mkey je offline   Reply With Quote
Staro 06.04.2025., 06:57   #30
tomek@vz
Premium
Moj komp
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: München/Varaždin
Postovi: 4,350
Citiraj:
Autor mkey Pregled postova
Ja govorim da, ako je problem laptop s accountom zaštićenim passwordom gdje je password nalijepljen na laptop, je isti problem kod laptopa koji koristi ključ + pin gdje je pin zabilježen na laptopu. Ključ nije rješenje problema lijepljenja lozinke na laptop. Kao što niti neki auth app, koji je podešen da samo traži potvrdu pristupa, nije garancija da neki lumen neće potvrditi, iako sam nije zatražio pristup.

Točno Zato i postoje ove solucije ali za po doma će to rijetki koristiti. Zato MS pokušava to progurati u Win11 što iako iritantno nije tak bedasto. Ovdje pričamo više o Enterprise svijetu gdje mnogi te loše navike od doma prenose u službeno okruženje što je jedan veliki "no-no". Većina IT-evaca je kolko tolko svjesna toga no u velikim firmama to što spominješ je ogroman problem.
__________________
Lenovo LOQ 15AHP9: AMD Ryzen 5 8645HS / 16GB DDR5 / Micron M.2 2230 1TB / Sandisk Extreme Pro 1TB / Radeon 760M + Geforce RTX 4050 / Windows 11 Pro
Acer Aspire V3-574G: Intel i3 5005U / 8GB DDR3 / Seagate 1TB HDD / Geforce GT 940M / OpenSuse Tumbleweed
tomek@vz je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Odgovori


Uređivanje

Pravila postanja
Vi ne možete otvarati nove teme
Vi ne možete pisati odgovore
Vi ne možete uploadati priloge
Vi ne možete uređivati svoje poruke

BB code je Uključeno
Smajlići su Uključeno
[IMG] kod je Uključeno
HTML je Uključeno

Idi na