Aaron アーロン (@acapaaron)
Posted
0 replies · 0 reposts · 0 likes
I used to recommend http://haveibeenpwned.com as a service to help figure out whether or not the password you're using has been compromised, or weather your account details were released and exist in a database. Recently, however the service has announced a partnership with the #FBI and I'm not wild about the FBI. Namely because they've dropped the ball on serious matters that should have been looked into when it came to prominent people. SO! What do you do instead of using #haveibeenpwned? I don't recommend any service now! You should be using a #password manager that stores it's database locally on your computer. I use #keepassxc along with the #Brave browser plugin that goes along with it. Then you should be at minimum setting up 2factor #authentication on ALL of your online accounts. #Gab included! I use #TOTP and 2fas app on my #Android phone to handle this. You want to use app based 2factor authentication and NOT text message or event based. The reason for this is because you can be #SIM jacked, and literally all phone carriers seem susceptible to this. When your 2 factor auth is in an app, an attacker needs physical access to your phone in order to get the one time pass codes. This holds true even for the #Google Authenticator App which I'm no longer recommending people use because #Woke Google. Even Google has enough sense to not defeat the TOTP security in their app and let the creds to generate the one time passcode leave the phone they're on. https://haveibeenpwned.com/