Online Identities, Passwords, and Passkeys, Oh My (Premium)

I’ve been using a Google Workspace account—paul@thurrott.com—as my primary online identity since before we launched Thurrott.com, and for the most part, I don’t have any major complaints. But there has long been one major downside to this account t… Continue reading Online Identities, Passwords, and Passkeys, Oh My (Premium)

Google Password Manager Improved with Five New Features

Google Password Manager now supports additional authentication methods, password notes, easier importing from other password managers, and more.
The post Google Password Manager Improved with Five New Features appeared first on Thurrott.com.
Continue reading Google Password Manager Improved with Five New Features

How fraudsters undermine text passcodes

Malicious bots are taking new forms – a burst of spam and scam text messages led to 18,000+ consumer complaints at the FCC last year. One of the newest scams – artificial inflation of traffic (AIT) – targets the SMS authentication codes sent by the mob… Continue reading How fraudsters undermine text passcodes

1Password enables passkeys — a new option from passwords

Identity management company 1Password is spinning up a pair of new features that constitute a major shift away from passwords and toward their low-friction replacement: passkeys.
The post 1Password enables passkeys — a new option from passwords appeare… Continue reading 1Password enables passkeys — a new option from passwords

Windows 11: Enforcing password resets for local group users

Admins can force users to reset their respective passwords during their next Windows 11 login by making a few simple changes on a difficult-to-find configuration screen.
The post Windows 11: Enforcing password resets for local group users appeared firs… Continue reading Windows 11: Enforcing password resets for local group users

Penetration tester develops AWS-based automated cracking rig

Building a custom cracking rig for research can be expensive, so penetration tester Max Ahartz built one on AWS. In this Help Net Security interview, he takes us through the process and unveils the details of his creation. What motivated you to underta… Continue reading Penetration tester develops AWS-based automated cracking rig

What are the risks of reusing the same passphrase for FDE, user account, and password manager?

Consider a home user who runs Linux on a laptop with full-disk encryption and uses a cloud-based password manager. Assume the laptop is firewall-protected with no SSH access. It seems reasonable to reuse the same passphrase for the OS user… Continue reading What are the risks of reusing the same passphrase for FDE, user account, and password manager?