this post was submitted on 06 Dec 2023
150 points (96.9% liked)

[Outdated, please look at pinned post] Casual Conversation

6575 readers
1 users here now

Share a story, ask a question, or start a conversation about (almost) anything you desire. Maybe you'll make some friends in the process.


RULES

Related discussion-focused communities

founded 2 years ago
MODERATORS
 

These are the same companies that don't support second factors, only have their app as a second factor, or only SMS second factor. Is it too much to ask for smart card or token (yubikey) support?

you are viewing a single comment's thread
view the rest of the comments
[–] l_b_i@yiffit.net 6 points 1 year ago (2 children)

A password manager does nothing to stop Social engineering and human factors on the provider side.

[–] aodhsishaj@lemmy.world 0 points 1 year ago (1 children)

Just automate it and gate it behind a strong passphrase and 2 factor the vault you use

https://github.com/Bubka/2FAuth

https://www.makeuseof.com/what-is-password-vault/

https://nerdschalk.com/8-best-self-hosted-password-managers/

https://www.hashicorp.com/resources/painless-password-rotation-hashicorp-vault

I know hashicorp has ruffled some feathers with the new terraform licensing but vault is still free and self hosted.

[–] l_b_i@yiffit.net 3 points 1 year ago (1 children)

I think your missing the point. It doesn't matter how good an individuals security practices are if the system itself has bad security architecture.