Welcome to MCB! We are the most popular and active paintball forum found on the internet! Thank you for stopping by.
If this is your first visit, be sure to
check out the FAQ by clicking the
link above. You may have to register
before you can post: click the register link above to proceed. To start viewing messages,
select the forum that you want to visit from the selection below.
The new site changes also meant cookie changes. Sorry. Unavoidable. If you're getting logged out, you need to clear your browser cache / data and cookies. Then when you log back in, you will be all set. More HERE on what's happening next.
It gets very frustrating that regardless of the precautions I take, businesses I deal with and even some that I don't will get hacked and spill my info
Anyway, thanks. PW changed to MARRULEZ69420
Originally posted by Phantom1313
now you can loudly shout “I know things” and nobody can argue with you when you wildly wave your masters degree in front to them
This is such a fu%* Erie post because im also baked but I just finished changing PayPal password because I couldn’t remember the password and needed it for the desk top.
When I make payment to A mcarter member for paintball related items it will ask everytime to login the TFA or others paypal login requirement to pay for stuff.. So unless the ph# associatated get comprise then that A bigger issue instead.
Friendly reminder to all - always turn on two-factor (2FA) and use a password manager so that every account gets a unique password. The browser-based manager is fine for low-risk accounts like forums, but use something more secure for anything financial related. My personal recommendations are KeePass if you like to keep things self-hosted or Proton Pass if you don't mind someone else hosting and want better browser integration. Or use all three; browser for low-risk items, Proton for medium risk, and KeePass for high-risk items (e.g. financial accounts)
In that vein, Vaultwarden is also nice - FOSS and self-hosted. Both of those, however, are intrinsically less secure that an encrypted file container like what KeePass uses; even if you toss that file into your cloud provider (or self-hosted cloud) by virtue of it's obscurity. It's the old adage of 'trading security for convenience'. So I'd rank the -warden's as alternatives to Proton Pass for medium security.
I will second Zeta here. Very well said. Although many very good suggestions were given about general safety practices, nothing is 100% safe. If someone really wants your money or your info, they can get it.
Never forget, the almighty credit reporting agency Experian let the info of 200 million people get loose. Chances are, your info is already out there. I’m surprised PayPal hasn’t been hacked yet.
How in the world are password managers safe? Bitwarden, Lastlpass? They get hacked too, right? And when that happens there will be another thread about changing your passwords. I’m never supposed to write my password down but I can give it totally to any 3rd party? Can anyone explain that? Anyone?
Your question is wrong. Using a password manager and having to give PWs to a 3rd party are not mutually inclusive. That's what I was on about above when talking about using KeePass for high-risk accounts. The way it works is that it will create an encrypted file container (e.g. "Zetas Potatos.PDF") that holds your heavily encrypted data safe and obscure. When you open KeePass, you navigate to and open your obscure file container, enter the encryption password or provide a key file, and then it will show your database of passwords. No third parties involved. And if you have concerns about the KeePass app itself, go audit the code as you like - it's free and open source. Many others have audited the code as well, so you can review their work too if you like: https://keepass.info/ratings.html Notably, EU-FOSSA audited the code in 2016 and found no issues.
As for those 3rd parties, I agree with you - there's a huge attack surface area when it's always online and easily identifiable as a PW database. Still, it's safer than using one password for everything and is more obscure than the browser-based PW manager. The convenience is the real draw for them since they can auto-populate your credentials for you. I recommend them for low and medium risk accounts.
It's not meant to stop the Yakuza from getting the off shore account numbers that you funneled their money into, or to prevent you from giving credentials out to a "hacker" sitting in a sweaty office in New Delhi... It's meant to stop the millions of bad actors online from stealing from you or just annoying you through automated attacks that systematically exploit a few known vulnerabilities or exposed credentials.
Myself, and the vast majority of all users, have spent more time dealing with IT because of their own screwups than because of any actual nefarious activity. I'd so much rather be hacked than have to deal with two factor identification on every account I have.
You say that, but try losing all access to the money in your bank account to the point you can't pay the mortgage, any bills or buy groceries.
Wife and I just had someone get into one of our bank accounts, it didn't have any money in it but it was linked to our primary, they used that link to transfer more money than what was in there around. Thankfully they were only transferring into the account that was empty (we suspect the next move would be to transfer out of there into an account they controlled) but because the transfer was in progress when we found it we lost control of everything in the checking account, our savings account was transferred into the checking to try and cover the negative balance, that wasn't enough so we lost everything in both accounts and had to wait for the money to finally clear in the account it was being deposited in before we had any control.
Use a credit card? Turns out I hadn't used my CC in so long that the physical card was broken. By some miracle we had enough gas in both our vehicles to survive the 5 days
TFA would have stopped all this and we got lucky the money was only going from one of our accounts to another.
Sent from my motorola edge 2024 using Tapatalk
I use Tapatalk which does NOT display comments. If you want me to see it, make it a post not a comment.
for anyone doubting the reliability of password managers or similar modern tech such as passkeys ---
1. I completely understand and had similar feelings at one point.
2. Your doubts are generally unfounded ---- the obstacle is your understanding and comfort, not the tech.
Think about a subject you know intimately.
Now picture someone saying to you about that topic ---- "i don't see how it works, so it probably doesn't, I'll pass thank you".
Just kind of makes you crazy eh?
That's password managers.
Plus they're REALLY convenient.
Start one today, and use 2FA
Comment