The Chief Product Officer at Yubico thinks "long passwords" offer little security. 2ee75ee4e4b359576257fc7d3bfc5ec75d358f10e17caf9e668e09cc032af36d That is the SHA256 of the 76-character passphrase to my master backups, plus '!'. Pwn me. I'm waiting.https://twitter.com/appenz/status/1238121735142031360 …
-
-
This Tweet is unavailable.
-
This Tweet is unavailable.
- Show replies
-
-
-
I already have some level of MFA: if you are not physically on the wired lab network (wifi is firewalled off) you can't even touch the SSH port on any of my machines without *also* being VPN'd in.
-
So to get root on the box I'm sitting at now without being physically in my house you need a VPN client cert, a SSH client cert, and a 36-character password. I think that puts me solidly outside "low hanging fruit" territory.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.