PasswordResearch.com

2.6K posts

PasswordResearch.com banner
PasswordResearch.com

PasswordResearch.com

@PwdRsch

Archive of authentication and password security news gathered by Bruce K. Marshall. See https://t.co/9uAr4djFQ9 or new updates on https://t.co/BDjgaZEXXC

Wichita KS, USA Entrou em Ekim 2012
305 Seguindo2.3K Seguidores
Tweet fixado
PasswordResearch.com
PasswordResearch.com@PwdRsch·
OWASP released v4.0 of the Application Security Verification Standard (ASVS) in March, listing security practices for orgs to design, code, and test apps against. github.com/OWASP/ASVS There was substantial content change in the authentication section, so I'll comment on it.
English
2
18
28
0
PasswordResearch.com
PasswordResearch.com@PwdRsch·
@_BSidesKC Thank you to the organizers, speakers, and volunteers for putting on the con! Nice to see the local community gather to share, learn, and have some fun.
English
1
3
5
0
PasswordResearch.com
PasswordResearch.com@PwdRsch·
@spazef0rze I haven't done much lately to keep it updated, but certainly have logged a lot of hours trying to gather good info in the past. Thanks for the recognition!
English
0
0
1
0
Jonah
Jonah@jwerre·
@PwdRsch Do you do Security Consulting?
English
1
0
0
0
PasswordResearch.com retweetou
Per Thorsheim
Per Thorsheim@thorsheim·
Virtual #PasswordsCon CFP is live: passwordscon.org/cfp/ Please submit NOW! Streaming on November 23-24. Pre-recorded or live talks, with live Q&A sessions. (please RT!)
English
2
29
25
0
@baybedoll@infosec.exchange
@[email protected]@Baybe_Doll·
Me: trying to stuff cats through a small crack in a door @jmgosney : hey babe, it's kitdential stuffing Me: ... Him: ... Him: get it? Kitdential stuffing?
English
1
1
5
0
PasswordResearch.com retweetou
Michal Špaček
Michal Špaček@spazef0rze·
"Study found little benefit to 6-digit PINs as compared to 4-digit PINs. Participants tended to select more-easily guessed 6-digit PINs when considering the first 40 guesses of an attacker. Current PIN blacklists ineffective" @Philipp_Markert et al. 👏 …s-pin-can-be-easily-guessed.github.io
English
0
1
10
0
PasswordResearch.com retweetou
Per Thorsheim
Per Thorsheim@thorsheim·
Blocking email as username login would be efficient to prevent credential stuffing / password spraying for:
Mons, Norway 🇳🇴 English
4
2
0
0
PasswordResearch.com retweetou
Troy Hunt
Troy Hunt@troyhunt·
Just blogged: Enhancing Pwned Passwords Privacy with Padding troy.hn/2Tn0z9T
English
2
13
40
0
PasswordResearch.com retweetou
Per Thorsheim
Per Thorsheim@thorsheim·
Time to submit for the #Ground1234 (#PasswordsCon) track people! I'll get back to some specific topics I'd like to see covered this year, but "Is 2FA worth it?" from a user/business perspective is one of them, & if you have deployed NIST SP800-63B we want to hear from you!
BSides Las Vegas@BSidesLV

The #BSidesLV CFP is now officially open! The possibilities are endless, as there are several tracks covering dozens of topics for you to talk about. Got something to teach or share? You have until April 15 to submit your talk or training idea to: cfp.bsideslv.org

English
0
5
7
0
PasswordResearch.com retweetou
Black Lives Matter
Black Lives Matter@conorgil·
#infosec #acadmictwitter Is anyone aware of any academic or industry literature that audits the security of TOTP #2FA app, like Authy, Microsoft Authenticator, LastPass Authenticator, Duo Mobile, etc?
English
2
3
5
0
PasswordResearch.com retweetou
Ricky Mondello
Ricky Mondello@rmondello·
We’ve published an explainer about an idea to harden SMS-delivered one-time passwords by allowing senders to associate the codes with a website. We’ve been talking about the idea with some folks at Google, and would like more feedback. github.com/WebKit/explain…
English
14
64
202
0
PasswordResearch.com retweetou
John Opdenakker
John Opdenakker@j_opdenakker·
What’s the more secure option of these? also interested in the motivation* *I know there are much better options but that’s not what I’m asking for. Retweets appreciated #Infosec
English
58
71
71
0