Skip to main content

Johan Bové

You keep your passwords and secrets secure in a password manager. But what happens when you lose access to the password manager, or when something bad happens to you and your family needs access to something really important only you knew the secret password for? I use a DiceKey. https://dicekeys.com/

Johan Bové

Who at the European Tech Department came up with this utter nonsense "You cannot change your password yet. You need to wait at least 24 hr between password changes." - What is the reason for this rule except for making the user experiences of this ECAS system intolerable

Johan Bové

Ausweisapp 2 - Online-Ausweisfunktion

Got my European eID card today and got it working pretty well. Next step is to authenticate my openPGP with this official certificate. This is all part of my quest to ban password authentication from this World.

Johan Bové

Before You Turn On Two-Factor Authentication…

Many online accounts allow you to supplement your password with a second form of identification, which can prevent some prevalent attacks. internet, security, syndicated

Johan Bové

Notice on the Freenode IRC network:
> [Global Notice] Today we have become aware of a spate of password reuse attacks targeting freenode accounts and urge you to be vigilant in your communities and ensure you use modern password practices, don't reuse them between different services and never use your dogs name. If you feel you might be a potential target please change your password now. /msg NickServ HELP SET PASSWORD will tell you how.

Johan Bové

Some days I only do "sudo apt-get update && sudo apt-get upgrade -y", enter my password and call it a day.

Johan Bové

DiceKeys creates a master password for life with one roll

Modern cybersecurity, done with properly paranoid best practices, requires meeting some tough demands: Carry a physical two-factor key to plug in and authenticate yourself on a new computer, but if you lose or break that tiny piece of plastic you could be locked out of your accounts. dicekey, passwords, security, syndicated

Johan Bové

How to Stop ‘God Mode’ Abuse

ou might think that as long as you keep your password safe, you’re the only person who can access your online accounts. censorship, internet, syndicated

Johan Bové

We can use web applications in @Beakerbrowser for our own usage safely without having to enter _once_ a password or user-name. Just select the hyperdrive profile you want to use from a dialog and you're good to go.

Johan Bové

I dream of a Digital World without passwords

1 min read

In a perfect World I would be able to access all my digital assets without having to enter a password or even authenticate manually.

One of the best parts of is the fact I only need a secret key file to access my content. The file is literally my access key to all my own SSB stuff.

No need to remember any crazy character combination or even having to register for an email account. I have an SSB and a secret and that’s all that should be necessary.

Having said that, being able to restore my account on with the “recovery phrase” does make sense since mobile operating system have terrible file access management.

Thank you dear community to make this dream become a little more reality.

ps. Since I can authenticate to my PC with my own face (Windows Hello), I really do not need to enter login and password to jump right into Patchwork.

Johan Bové

@Toyota_DE Die "Connected Services" Web App ist cool, aber warum kann ich mein Passwort nicht im online Password Feld einfach einfügen aus mein Passwortmanager? Scheinbar lasst die Seite Einfügen nicht zu. Mal kurz in die React app geschaut und das Event wird blockiert.

Johan Bové

The Bug That Exposed Your PayPal Password - Alex Birsan - Medium

"The response to the captcha validation request is meant to re-introduce the user into the authentication flow. To this end, it contains a self-submitting form with all the data provided in the user’s latest login request, including their email and plain text password."

Johan Bové

Almost locked me out of my own PC because of a forgotten pin code on my Yubikey Nano. Note to self: make a backup of the pin code next time and perhaps not use it for my critical systems, especially since I'm already using other authentication mechanisms. Btw, locked myself out of my Kraken account too in the same way. Didn't make a "master password" there and now I can't access it. Not that I was using it for anything...

Johan Bové

What’s the point of ’s “log out and safe password” and why is it the default "Logout" option? I say it's because you’re not really logging out and Facebook keeps you. It’s not even safe, since anyone with access to your unlocked phone or computer can simply log in without entering the and pretend happily to be you.