Why do I need to provide authentication when accessing a browser’s built-in password manager?

Why do I have to provide authentication when I want to read a password stored in my own web browser while I have to do nothing to read the same password on a site’s login page?
Is my conclusion correct that asking the user for a PIN is poi… Continue reading Why do I need to provide authentication when accessing a browser’s built-in password manager?

Why removing just one letter form passwords makes it 20x easier to break according to zxcvbn test

Since I am a decent fan of the XKCD no 936 (or actually conclusions and implications it brings), I wanted to test (using try zxcvbn) the complexity and the possiblity of breaking a password like the following one:

My password for Facebook… Continue reading Why removing just one letter form passwords makes it 20x easier to break according to zxcvbn test

Does fingerprint scanning on Microsoft Authenticator increase security?

tl;dr: I have switched phone and operating system: Android 8.0 –> Android 10.0. Phone restored from backup, so all the remaining is the same except for Microsoft Authenticator that now requires fingerprint scan. Does this truly increas… Continue reading Does fingerprint scanning on Microsoft Authenticator increase security?