Editing Talk:1200: Authorization

Jump to: navigation, search
Ambox notice.png Please sign your posts with ~~~~

Warning: You are not logged in. Your IP address will be publicly visible if you make any edits. If you log in or create an account, your edits will be attributed to your username, along with other benefits.

The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then save the changes below to finish undoing the edit.
Latest revision Your text
Line 5: Line 5:
 
The admin account should still be guarded EXACTLY for the ability to install drivers. The driver you don't want to have installed is keylogger stealing your passwords. I mean, you don't have your bank password remembered in browser, do you? Still, auto-logout or auto-lock is important feature. You should also set-up and use separate account for high-risk activities (like opening emails from unknown persons promising naked celebrities ... ok, you actually shouldn't be opening such emails at all, but if you are really curious ...). -- [[User:Hkmaly|Hkmaly]] ([[User talk:Hkmaly|talk]]) 09:06, 17 April 2013 (UTC)
 
The admin account should still be guarded EXACTLY for the ability to install drivers. The driver you don't want to have installed is keylogger stealing your passwords. I mean, you don't have your bank password remembered in browser, do you? Still, auto-logout or auto-lock is important feature. You should also set-up and use separate account for high-risk activities (like opening emails from unknown persons promising naked celebrities ... ok, you actually shouldn't be opening such emails at all, but if you are really curious ...). -- [[User:Hkmaly|Hkmaly]] ([[User talk:Hkmaly|talk]]) 09:06, 17 April 2013 (UTC)
  
:Even if you can log into your bank account, you could not transfer money without authorizing transactions. [[User:BKA|BKA]] ([[User talk:BKA|talk]]) 11:23, 17 April 2013 (UTC)
+
:Even if you can log into your bank accout, you could not transfer money without authorizing transactions. [[User:BKA|BKA]] ([[User talk:BKA|talk]]) 11:23, 17 April 2013 (UTC)
::My bank account website logs me out if I'm inactive for 10 minutes. It doesn't even leave the page up, it switches to a login screen. [[Special:Contributions/24.77.229.71|24.77.229.71]] 14:35, 17 April 2013 (UTC)
 
:I wonder how useful a keylogger would be if you never typed a username or e-mail to go with the password.  Every important account I have has that remembered, and I just type the password.  It sounds like it would be zero context. [[Special:Contributions/76.106.251.87|76.106.251.87]] 15:09, 17 April 2013 (UTC)
 
::Except usernames tend to be reasonably easy to figure.  E-mails certainly are what with folks tending to broadcast their e-mail addresses to everyone.  So passwords, although also often not overly difficult to crack (http://xkcd.com/936/), remain the part not generally known.  Not worrying about a keylogger picking up a password, even "out of context" would be a mistake. [[Special:Contributions/67.51.59.66|67.51.59.66]] 17:11, 17 April 2013 (UTC)
 
:::Also, modern keyloggers (despite still being called keyloggers) also capture screen and mouse movement. They are perfectly able to record a password entered by clicking on keyboard on screen and many other ideas tried to complicate keylogging. -- [[User:Hkmaly|Hkmaly]] ([[User talk:Hkmaly|talk]]) 22:48, 17 April 2013 (UTC)
 
 
 
Actually, for many years popular operating systems such as MS Windows did *not* have separate security for system administration, which made it very popular for the propagation of viruses and other malware. And once it was introduced, it wasn't enforced for many years. Only relatively recently this is happening, and still viruses, trojan horses and botnets thrive, because it is slightly inconvenient for the user to act safe(r). [[Special:Contributions/213.84.74.36|213.84.74.36]] 13:13, 19 April 2013 (UTC)
 
 
 
Not agree with Randall on this one. Laptop stealing is very physical, there are way to keep people from physically able to use our active login session, such as make sure the laptop is physically secured when possible, make sure the screen locked out when we are away (we can automate that using bluetooth detection), etc. Root password protect another kind of attack, generally more clandestine one, such as trojan and rootkit installations, which can be more dangerous as we may not be aware it is there. [[User:Arifsaha|Arifsaha]] ([[User talk:Arifsaha|talk]]) 17:06, 6 May 2013 (UTC)
 
 
 
 
 
Not going to agree. I use lastpass for passwords, have every (important) site protected with 2fac, and firefox wipe all my userdata everytime I close it, so even if a keylogger is installed, or they have physical access to my device, they can't get to my personal information.  So that covers Facebook, Gmail, Paypal, and the Bank. Everything else is encrypted
 

Please note that all contributions to explain xkcd may be edited, altered, or removed by other contributors. If you do not want your writing to be edited mercilessly, then do not submit it here.
You are also promising us that you wrote this yourself, or copied it from a public domain or similar free resource (see explain xkcd:Copyrights for details). Do not submit copyrighted work without permission!

To protect the wiki against automated edit spam, we kindly ask you to solve the following CAPTCHA:

Cancel | Editing help (opens in new window)