Introduction to Security Good Practices
dataswamp.org
dataswamp.org
Is there some good plug and play tool for this or something? Id imagine implementing something like this yourself would take quite a bit of time and know how. Are there non-paid solutions out there?
Some bespoke WAF automation setups. You can mix in ML in this to add anomaly detection.
https://aws.amazon.com/blogs/security/automatically-updating...
Yeah, I agree with most of it I think. I use a modified version of "pass" instead of "keepassxc", and I do not have anyone I really trust with pieces of my password. I think having a sentence as your password is the best (very easy to remember, difficult to crack), and you can append random characters to that at the end or wherever. It makes it even better if the sentence is not in English. :)
Thank you for reminding me of QR. There is a tool[1] written in Python that outputs the QR code as ASCII art to the terminal, or to a file as PNG. I will use it more in the future I think. You can get a QR scanner from F-Droid for Android. Be careful of executing "printf 'foo' | qr" though. Hide your processes with "hidepid=2" or something.
You need to take care choosing a QR code reader app for this (and even if you choose a "good" one, be careful every time it updates)...
https://blog.malwarebytes.com/android/2021/02/barcode-scanne...
Android8 and newer and iOS11 and newer should scan QR codes natively from the default camera app. That _should_ be a fair bit safer than some random QR Code app of unknown provenience...
This is a nice summary though, for a personal blog. Props to the author for taking the time to put their thoughts out there.
I would emphasize the "threat model" idea whenever you go down a rabbit hole of security. "What kind of bad actors could try to access my network/data, and how hard do I want to protect against it?"
I used to be more paranoid about storing certain data in the cloud. Why would I put my highly encrypted password safe file on my Google Cloud? The NSA could get it!
Listen, if you're being targeted by the nation-state, you have 99 problems. So always balance that usability with reasonable security that aligns with your realistic threat model.
1) check out bitwarden + aegis - both seem popular as another tools
2) Reinstall your linux desktop instead of upgrading once in a while ( remove worms). Make sure you have all updates regularly.
3) When you are developing be careful with libraries - for example pin your versioning in python in the event you get a bad repo
4) use adware blocker to block malware in firefox
5) with keepassxc use the extra file - for security - call it random.mp3 and do not keep it in the cloud even encrypted
6) keep your otp passwords separate
7) use u2f for your main email account - yuibkey or other cheap alternative.
8) explore ssh using yuikey
9) use personal firewall on laptop
10) Use drive encryption for your laptop - backups need to be all encrypted as well
11) Bonus - have separate email account only for password resets that is very hardened and you don't log in regularly. Maybe with 2 different 2 factor auth on it.
12) Bonus 2 - have separate phone number for 2 factor sms authentication that people can't know about - (voip or tosser phone)