The Chief Product Officer at Yubico thinks "long passwords" offer little security. 2ee75ee4e4b359576257fc7d3bfc5ec75d358f10e17caf9e668e09cc032af36d That is the SHA256 of the 76-character passphrase to my master backups, plus '!'. Pwn me. I'm waiting.https://twitter.com/appenz/status/1238121735142031360 …
-
-
Replying to @marcan42
76 characters? You have me beat. Most of my root passwords are UUIDs or derived from them - I figure 124 bits of /dev/urandom is enough.
1 reply 0 retweets 2 likes -
Replying to @azonenberg @marcan42
Of course, since I also have SSH password login disabled, even cracking it won't do you any good unless you have local console or an SSH client certificate session to "su" from...
1 reply 0 retweets 2 likes -
Replying to @azonenberg
Ah, but you see, on my most sensitive machine I use *both* key *and* password login (yes, you can do that with SSH). :-)
1 reply 0 retweets 3 likes -
This Tweet is unavailable.
-
This Tweet is unavailable.
Replying to @Wxcafe @azonenberg
I put my key in a Yubikey (yeah, I know... probably finding something else now) so u2f would be somewhat redundant.
8:43 AM - 12 Mar 2020
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.