Google+ open-source construction: database Google+
Showing posts with label database. Show all posts
Showing posts with label database. Show all posts

Friday, June 22, 2012

security_class_101 Day_2

security 101:
Day 2: 
LastPass

LastPass is my cloud based Password data-base management application. I personally use KeePassX for local, and LastPass for my Internet passwords alone. I like different features in either app better. The major advantages to LastPass are the full range of Browser compatibility(IE,Opera, chrome/chromium, safari).  The browsers it does not play well with are:Maxthon, Avant, and a bunch of the Linux web-browsers(epiphany{gnome}midori), while a bunch of Linux browsers are based on the source code of firefox.

I will say that I am reviewing this from a free user perspective. If anyone wants to see a review of the pro, and how yubiKey works with LastPass. Although Hak5 has done a bunch of episodes on using yubiKey's, and LastPass.

LastPass advantages:


~ compliant w/ all of the major operating systems:Linux/mac/windows/BSD(sadly no haiku)



~ has a two factor authentication w/ cards, to perform two factor auth. with the free version.

~ has a security check for checking the strength of your passwords.
(there were three fast screens that flew by encrypting passwords, sending passwords, calculating password strength...)








~share the results to brag to your friend's or like in my case be disappoint by a mere 86%...:~{








~ Imports from almost any format, but doesn't export into many formats.
Import


VS.


export


~  Secure notes for keeping "secret" Lists.
(you can also copy/paste anything in one of thise lists you want.)


~ one click filling of form-data
(although I use AutoKey 2 automate strokes portably from inside a encrypted volume)

~Generate secure Passwords...
The LastPass Password generator, to give you an unlimited amount of random passwords.
 ~ It is my opinion that LastPass strength's lay in Cross-platform/browser, security check you can share with your friend's, a strong encryption focus. You can also use your Last Pass from the local Encrypted Vault. The Vault does work off-Line from your web-browser, but will alert you to off-Line being used. So even if Last Pass is doing maintenance, your still golden. I use my KeePassX local Linux password data-base, to fill in the Master-Password for my LastPass every time I log into most any of my browsers(I like Maxthon/Avant, Midori, and Epiphany as well...:/).

Although I think the main advantage from using any kind of password dataBase, is going to be the ease of use it is for (possibly-incompentent non-tech. users)to enter propperly strong passwords, and to easily change them if they find out their NT was attacked. 

Tuesday, June 19, 2012

security Class101:Day 1 KeePassX && Linux

 Using KeePassX 2 increase your security in Linux

I have been using KeePassX for my passWord data-base manager, for over a year now. That not only means that my pass-words are as long and complicated as possible, and all completely unique. Although I sometimes use web-services like twitter, google, my launchpad Oauth link, or facebook to login to my passwords. I have been switching one of these per week, which makes cracking my passwords, highly unlikely.




I like to make notes during the creation of an account, any information I found out about what types of passwords the data-base supports. I really wish there were simple tags on web-sites when creating passwords so I can know the most complicated I can make the passwords. Which I have found in the past, but it is generally rare.

You can easily install KeePassX on any GNU/Debian/Ubuntu(Linux) by running the command:

$ sudo apt-get install keepassx

<enter>

<PW>

<enter>
(install keepass2 for more M$ compatibility)

I do want to make clear that KeePassX is compatible w/ LastPass, but not many windows/mac based password managers. Since I use only Linux keePassX is perfect for my situation.

I usually keep keePassX on my toolbar dock. In Unity or Gnome-shell just open the application(app), then just right click and select "lock to panel" or similar command in "G-S".

So you may ask why I use keePassX and LastPass. I say that I like having my web-passwords mainly kept in LastPass, while I like the extra options for generating passwords, and there are other passwords that I only keep in my KeePassX data-base. Some of these passwords are: SSHkeys, IceCast Server, LastPass Master-Password(My LastPass Never remembers my Password, so I have 2 copy it in each time), and my public-pvt. OpenGPG keys.

Power-user top:

Ctrl + P generate semi-random password.

You can also check/uncheck options like:

allows you to do custom characters, exclude look-alike characters, make sure the passwords contain char. from different groups.

you compare and tell me. 

Also if you do like me and generate passwords from KeePassX, then all it takes is clicking that "save site" in the box that drops down from LastPass in your browser. From that point onwards you can just click "auto-fill to fill in your pass-words. Then just click the regular "log-in" button to get logged in.

the lock screen. You must unlock, before your next copy/paste. I set my desktop to be very lenient; while my net-book keePassX locks and deletes the paste buffer. 

you could also use a stupid-complicated password in a text file, called a keyFile.


What I highly recommend in getting started w/ a secure pass-word data-base is to make a list of your most often used/needed passwords: Here would be my list:

~Amazon/Ebay/pay-pal
~Google/twitter/Facebook/OpenAuth(my OpenID Link 2 my LaunchpadID)
~del.ic.ious/digg/reddit/stumbleupon/P2PU/identi.ca/linkedIn
~facebook/mySpace/couchSurfing/
~tumblR/wordPress/ping.fm/seismec/everNote(on-line notebook)/diigo(highlighting)
~mint-forums
~liveMocha/typingWeb/lumosity
~digsby/trillian/aol/icq/yahoo!
~last.fm/pandora

That is a lot, but I share a lot of articles on the Net. Most people will probably only need a dozen or so passwords to be satisfied, especially w/ most web apps having facebook, twitter, google, && OpenID link. Along w/ a few like E-bay, Amazon, and Pay-pal. Although I would suggest getting a second factor authentication token for your on-line banking either from your $ site(paypal for example), or get a yubi-key for $20 tied to your LastPass.

read fields for tips. repeat is red, because it does not match the first PW field.

Google+