Search
Items tagged with: password
#Research finds 12,000 ‘Live’ #API Keys and ßPasswords in #DeepSeek's #Training Data
#ai #technology #security #privacy #fail #password #Problem #cybersecurity #news #Software
Research finds 12,000 ‘Live’ API Keys and Passwords in DeepSeek's Training Data ◆ Truffle Security Co.
We scanned Common Crawl - a massive dataset used to train LLMs like DeepSeek - and found ~12,000 hardcoded live API keys and passwords. This highlights a growing issue: LLMs trained on insecure code may inadvertently generate unsafe outputs.trufflesecurity.com
In today's episode of 'website security theatre' we present the US Government's "TreasuryDirect" site.
They don't just disable copy-and-paste into the password field, they disable *keyboard entry* into the password field. You are required to click buttons on this virtual keyboard in order to enter your password. Kudos to them for making high-entropy random passwords difficult to use!
Oh, and the password is also case-insensitive, probably because implementing shift-key support in the virtual keyboard would have been too complex.
#Password #SecurityTheatre
They don't just disable copy-and-paste into the password field, they disable *keyboard entry* into the password field. You are required to click buttons on this virtual keyboard in order to enter your password. Kudos to them for making high-entropy random passwords difficult to use!
Oh, and the password is also case-insensitive, probably because implementing shift-key support in the virtual keyboard would have been too complex.
#Password #SecurityTheatre
Hallo !Friendica Support
wenn ich meine E-Mail Adresse für meinen Account ändern möchte - kann ich diese zwar eintragen, aber ich erhalte dann die Meldung "Falsches Passwort" ohne das ich eine Aufforderung zur eingabe eines Passwortes erhalten habe.
Ist die ein Bug oder habe ich da etwas übersehen?
#change #email #password #bug
wenn ich meine E-Mail Adresse für meinen Account ändern möchte - kann ich diese zwar eintragen, aber ich erhalte dann die Meldung "Falsches Passwort" ohne das ich eine Aufforderung zur eingabe eines Passwortes erhalten habe.
Ist die ein Bug oder habe ich da etwas übersehen?
#change #email #password #bug
If you mean "online" #password storage then yeah, #bitwarden. My family uses #passwdsafe + #syncthing (also offline) though.
By the way #nextcloud seem to have a new pwstore but haven't checked its security yet.
By the way #nextcloud seem to have a new pwstore but haven't checked its security yet.