Authored by: PlexTrac Author Posted on: October 17, 2019 Are Password Vaults Secure? Password vaults can make our lives convenient and give us comfort in our personal lives, but are they secure? Trusting a company with all your credentials can seem pretty scary – especially to those of us who understand that there is no such thing as a perfectly secure application. Yes, there is risk in using a password vault. Even some of the larger and more well-regarded password vaults have had security incidents. For me, it is about managing risk. I believe that for the vast majority of people, the risks in using a password vault are much less dangerous than the alternative. You can also increase the security of this solution by applying some of the same, common-sense principles that you should be using elsewhere in your life. First, make sure that you choose a very long master passphrase (20+ characters) that has some complexity. It doesn’t need to look like “d8$k24Vs(&3i90q0i6%x7?jsq1wn^DP7Qe2.” Something like “n3v3reatradishn@ch0s1nbed” (never eat radish nachos in bed) provides a reasonable balance of length and complexity with the human need to remember it. Second, only choose a vault that supports two-factor authentication. In the event your master passphrase is compromised, this will at least make it more difficult for an attacker to login to your account. Ensure that you have screen lock timers set for all your devices, and lock your devices manually when leaving them unattended. As you add passwords to your password manager, use the opportunity to change them. Storing your passwords securely doesn’t mitigate the dangers of password re-use! PlexTrac Author At PlexTrac, we bring together insights from a diverse range of voices. Our blog features contributions from industry experts, ethical hackers, CTOs, influencers, and PlexTrac team members—all sharing valuable perspectives on cybersecurity, pentesting, and risk management.
From Risk to Resilience: 5 Steps to Speed Remediation and Protect Your Organization Security teams have one main goal: Avoid breaches. For anyone that works in security, you know this is easier said than done. With an influx of findings and risks coming at you from multiple sources, it can be daunting and time consuming trying to figure out what to fix first. We often see organizations making... READ ARTICLE
How Do I Pentest My LLM? In the world of cybersecurity, AI is the perpetual topic du jour, and more specifically Generative AI. The use of LLMs for all kinds of use cases is the craze and the AI ecosystem continues to move at a rapid pace. When it comes to pentesting, the job of every tester is to keep up... READ ARTICLE
What FedRAMP’s New Vulnerability Management Standard Means for Pentesters and Vuln Managers Breaking Down the New RFC-0012 Standard Under FedRAMP and How It Can Change Your Daily Security Operations If you work in vulnerability management or penetration testing for cloud systems under FedRAMP, buckle up because the new RFC-0012: FedRAMP Continuous Vulnerability Management Standard is going to change how your work is scoped, tracked, and prioritized. The... READ ARTICLE