Sigh, the amount of misinformation around KRACK is making me want to pull my hair out. "Stop using all WiFi! Never use public WiFi" *groan*
-
Show this thread
-
Also "Android 6.0 devices are totally pwned!" (more like: they're actually more secure than older devices)
1 reply 1 retweet 13 likesShow this thread -
PSA: If you use WiFi mostly to access the Internet and don't have openly accessible devices in your LAN, you are FINE. Keep calm and WiFi on
4 replies 11 retweets 19 likesShow this thread -
Replying to @marcan42
what does “openly accessible devices” mean in this case?
1 reply 0 retweets 0 likes -
Replying to @cmsimike
Like a NAS or something, especially with no authentication. An actual server you don't want others to have access to, and without TLS.
3 replies 1 retweet 1 like -
So what's the best practice nowadays for secure authentication to a home router, printer, or NAS?
1 reply 0 retweets 0 likes -
Replying to @PinoBatch @cmsimike
HTTPS with user/pass (2FA optional). I find I've just been throwing random stuff on the internet behind nginx with Let's Encrypt.
1 reply 0 retweets 0 likes -
My policy is basically, if it's inside HTTPS with a real cert and HTTP Basic auth (gated at nginx level), no reason not to put it online.
2 replies 0 retweets 0 likes
No 2FA yet but I have a design for something to handle that... need to get down to implementing it.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.