Recent comments in /f/LifeProTips

degovial t1_j1o75pq wrote

These "hacking" attempts don't come from brute force, but come from database leaks, most of the times... or social engineering. Creating strong passwords helps against brute force technics and decrypting encrypted databases that were leaked.

Big or small, no one gives a fuck... just use 2FA and sleep better at night lol.

5

krkrkrkk24 t1_j1o5mi3 wrote

Password manager 😁 Lastpass literally got hacked a few days ago releasing into the wild users' passwords vaults only encrypted with the master password which can easily be brute forced if weak as well as unencrypted URLs the specific user has visited, just write all your passwords down.

5

keepthetips t1_j1o4xyk wrote

Hello and welcome to r/LifeProTips!

Please help us decide if this post is a good fit for the subreddit by up or downvoting this comment.

If you think that this is great advice to improve your life, please upvote. If you think this doesn't help you in any way, please downvote. If you don't care, leave it for the others to decide.

1

nsa_reddit_monitor t1_j1o4ln6 wrote

I use Keepass, it has a standard format for password databases so a lot of tools and apps exist to read a Keepass database. I make sure (via various methods) that all my computers and phones and backups have a copy of my password database.

I only have the Keepass password memorized, and a couple of my computers use that password for their full-disk encryption (because if you get past that, I'm screwed regardless of if you have my passwords). Basically, unless you take down my computers, my phones, and a couple backups in undisclosed locations, I won't lose any of my passwords.

So I don't even know my bank or email login. Worst case, I can just go to the bank and have them reset it in person. And my email is hosted on a private server I own (in an undisclosed location), so I could physically go to the datacenter and plug a keyboard in to regain access.

3

Grievuuz t1_j1o31xs wrote

I don't wanna butt into the conversation, but I do feel the need to correct you.

The internet currently has 4.9 billion users.

Absolutely no fucking chance that more than half of them even know what a keylogger is.

None.

12

Mataskarts t1_j1nzvga wrote

2fa sorta eliminates the pure malware risk unless somehow you get both your phone AND PC infected with the same one designed solely to get steam accounts.

But yeah phishing and social engineering are by far the most common ways of "hacking" or stealing steam accounts. If you can't bypass the systems - just ask the user nicely for all the info instead. Or threaten their family, that works too.

3

Izzetmaster01 t1_j1nzmo9 wrote

You realise that most people on the internet aren't technologically illiterate. I don't have a key logger. Otherwise I would be complaining about all of my accounts. It just doesn't matter for steam for whatever reason. You're just coming to a really silly assumption

−10

Necrowanker t1_j1nzj95 wrote

You're right but people should still be aware that their accounts can still be breached through other methods, such as certain kinds of malware and phishing attacks. 2fa helps so much but it's not invincible

2