Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
11/23/2025 3:36:25 PM EDT
You dont know what you dont know.

Apparently my online security is between poor and awful.  The only mfa I use is when I log in somewhere and it texts me back a security code to enter - and that's only where it's mandatory to do so.  My passwords are all similar, but not the same for most things.  Some older stuff (mostly forums) uses the same password for several of them.

The password manager I have is freebie version of last pass that only works on my desktop.

Phone and tablet (both samsung) seem to have their own internal password memory system.

I've read about software like Microsoft authenticator - it says it will give you 10 codes that you need to store securely somewhere like a password manager because they will be required in the event of of a lost phone.  That would be an encrypted file on a password manager isnt it (i.e. password manager has to be capable of storing encrypted files?)  Maybe a side question, but how would these codes be used in recovering a lost phone and why do I need 10 secret codes?

What's the first step here?  There are 2 of us, myself and my wife.  1 laptop (desktop and second laptop being retired), 2 tablets (both Samsung  tab 8), 2 Samsung phones - s20 and s25)

New laptop is running windows 11 home edition and Microsoft 365.


11/23/2025 7:27:18 PM EDT
[#1]
We've settled on BitWarden. Open source, good encryption, and clients available for all platforms.
God's children are not for sale.
11/23/2025 8:08:16 PM EDT
[#2]
My family uses Proton Pass. It’s worth a look.
11/23/2025 8:55:08 PM EDT
[#3]
I use KeepassXC for my password manager. You can use as your TOTP as well if the random code for the QR code is available.

Read my sig and IM me if you have questions.

Protecting privacy will come at a cost. Use encrypted email (Proton), messaging (Signal), and password manager (KeepassXC). Use a vetted VPN only!, Social media is mind poison.
11/23/2025 9:02:49 PM EDT
[#4]
The best handholding you can get on this highly detailed tech stuff is the AI. I plugged your post into perplexity take a look, you should be able to ask it followup questions. Take the same questions to a different one like grok or chatgpt and do it again. Do not disclose anything private while doing this. They are useful but not to be trusted completely. Try to get a good idea how to proceed before committing, since it's a pita to change. Ask questions, and lay out how you will use it and what you want and don't want.
11/23/2025 9:57:39 PM EDT
[Last Edit: KnuckleSandwich][Edited] [#5]
We use 1password, but I am considering switching to proton pass. 1password is really good, although lately autofill on android is somewhat flaky.

For MFA, we use proton authenticator, but honestly Google auth and MS auth are fine as well.
11/24/2025 1:19:50 AM EDT
[#6]
Quote History
Originally Posted By KnuckleSandwich:
We use 1password, but I am considering switching to proton pass. 1password is really good, although lately autofill on android is somewhat flaky.

For MFA, we use proton authenticator, but honestly Google auth and MS auth are fine as well.
View Quote

We use 1password too, but the last Windows version before you had to start using AgileBits's server versus DropBox (or other general cloud solution).  Someday we will need to migrate to an alternate that plays nicely with Windows and Android. (Linux we handle via Wine.)
11/24/2025 1:47:52 AM EDT
[Last Edit: johnh57][Edited] [#7]
Quote History
Originally Posted By heavily_armed:
The best handholding you can get on this highly detailed tech stuff is the AI. I plugged your post into perplexity take a look, you should be able to ask it followup questions. Take the same questions to a different one like grok or chatgpt and do it again. Do not disclose anything private while doing this. They are useful but not to be trusted completely. Try to get a good idea how to proceed before committing, since it's a pita to change. Ask questions, and lay out how you will use it and what you want and don't want.
View Quote
Pretty much what I'm doing.  Trying to plot a course - starting with a decided lack of knowledge.  I've been reading, watching a few YouTube videos, asking ai what this or that acronym stands for.  At present I think I'm far more likely to mess something up causing much grief trying to fix than I am at risk of getting hacked.

The other day I needed to log into my onedrive account on the trap club pc to move a couple league spreadsheets onto my onedrive so I could get some work done on them at home.  Simple right?  I managed to get Microsoft to install myself as an online user account on the computer, install miscrosoft 365 and link it to my personal account, and put all my personal email on the clubs computer.  Took me 2 hours to erase myself off the damn computer, and it still asks if I want to log into my one drive when I go to the local user account on the damn thing. There are any number of people that use that local account, really prefer them not having to decline to log into my onedrive account .  I had to go to another local account with an email client running, and email the 2 files to myself from that account.
11/24/2025 1:44:07 PM EDT
[#8]
Originally Posted By johnh57:
The only mfa I use is when I log in somewhere and it texts me back a security code to enter - and that's only where it's mandatory to do so.  My passwords are all similar, but not the same for most things.
View Quote

Technically speaking, SMS authentication is the weakest form of MFA. Your SIM card can be hijacked or swapped via porting attacks, depends upon your carrier on how hard that is to do. Using an electronic or token authenticator like Google Authenticator or a Yubikey is far more secure.

I also use a similar password schema, which I call 'password tiering'. Stuff like Arfcom is third tier, and most of them share a common password. It's things that I don't care if they get compromised since they have near little effect on me. Fourth tier is throwaway or disposable stuff. Second tier is important and uses a stronger password, and first tier is critically important things where every account gets a unique password and MFA where possible. The policy of requiring a different password for every account is just not feasible, and using a password manager increases your risk of compromise since everything is in one location, and we've seen those get hacked into.

Originally Posted By johnh57:
I've read about software like Microsoft authenticator - it says it will give you 10 codes that you need to store securely somewhere like a password manager because they will be required in the event of of a lost phone.  That would be an encrypted file on a password manager isnt it (i.e. password manager has to be capable of storing encrypted files?)  Maybe a side question, but how would these codes be used in recovering a lost phone and why do I need 10 secret codes?
View Quote

Those are backup codes in the event you lose your phone or the like and need to authenticate into the account. You normally will never use them except as a backup.

Sign up to continue the discussion

Create a free account to share your thoughts, follow topics, and connect with the AR15.COM community.

Already a member? Sign In