Weird. Could it be that I'm in a couple of active telegram groups?
Notices by Kev Quirk (kev@fosstodon.org), page 94
-
Kev Quirk (kev@fosstodon.org)'s status on Saturday, 05-May-2018 02:47:21 EDT Kev Quirk
-
Kev Quirk (kev@fosstodon.org)'s status on Saturday, 05-May-2018 02:32:57 EDT Kev Quirk
@DelusionalAI @joseph I've never really used Google photo, so can't really comment on that. I tend to just use the stock gallery app, and my photos auto-backup yo nextcloud.
-
Kev Quirk (kev@fosstodon.org)'s status on Saturday, 05-May-2018 02:31:35 EDT Kev Quirk
@morgel good luck and welcome!
-
Kev Quirk (kev@fosstodon.org)'s status on Saturday, 05-May-2018 02:30:05 EDT Kev Quirk
So I put Telegram X on my phone, and it started chewing through a shed load of battery. Has anyone else experienced this? Is that just normal for Telegram, or is it because I was using the X version?
-
Kev Quirk (kev@fosstodon.org)'s status on Saturday, 05-May-2018 02:22:09 EDT Kev Quirk
@joseph what particular part of tech? I have a number of infosec and opensource, but I don't read many generalist blogs. I also listen to a few great podcasts.
-
Kev Quirk (kev@fosstodon.org)'s status on Saturday, 05-May-2018 02:20:17 EDT Kev Quirk
-
Kev Quirk (kev@fosstodon.org)'s status on Saturday, 05-May-2018 02:17:14 EDT Kev Quirk
@joseph yeah I have a dedicated IP. Nope, I don't check blacklists.
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 13:29:17 EDT Kev Quirk
@lx @sheogorath I know I know I know. As I said in the previous comment, I know the issue, I just didn't explain myself very well...
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 10:55:56 EDT Kev Quirk
@DelusionalAI but what about CAPITAL LETTERS???
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 10:34:42 EDT Kev Quirk
@whonose123 ππππ
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 10:05:09 EDT Kev Quirk
@sheogorath I'm well aware of the context around both issues. The point of the post is to alleviate any concerns that a relatively small project, such as this, is not storing password in plaintext. Obviously I didn't make that clear in the post.
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 10:01:47 EDT Kev Quirk
@6gain @paulfree14 of course, and everything is salted. But I would be remis to not obfuscate some of the hash. The rainbow tables comment was just a flippant remark to inject some humour to the post. π
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 10:00:56 EDT Kev Quirk
@6gain @paulfree14 correct. It was a glitch in local logging.
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 10:00:02 EDT Kev Quirk
@pettter absolutely. Bcrypt and salt. But I'd rather protect things, just in case.
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 09:59:01 EDT Kev Quirk
@paulfree14 it was a bug in their internal logging.
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 09:14:53 EDT Kev Quirk
Both #Twitter and #Github have reported storing passwords in plaintext over the last two days. I wanted to alleviate any concerns - WE DO NOT STORE PASSWORDS IN PLAINTEXT.
Sure, I could just be saying that. So to help prove this to you guys, here is my user account as it appears in the backend database. I have redacted my personal email and half the hash, because rainbow tables, yo.
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 06:43:41 EDT Kev Quirk
@espen possibly, not sure. I received a notification from Twitter, didn't get anything from GitHub though.
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 05:06:30 EDT Kev Quirk
@kmj I actually still use Twitter as I follow a lot of infosec people in there that aren't on here.
Personally, I feel twitter is less dangerous than fb as everything posted is public, and people know that. There isn't the same back channels or convolution, like on fb. Plus, twitter requires way less info from it's users.
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 03:33:12 EDT Kev Quirk
@joseph you can set it to display a notification when it detects an app that you have a password for (just like Lastpass).
-
Kev Quirk (kev@fosstodon.org)'s status on Friday, 04-May-2018 03:07:42 EDT Kev Quirk
@joseph yeah, for the most part it does work really well. You can also set it to check and pop-up a notification to fill when it detects a login. I don't have that turned on though.