SlideShare a Scribd company logo
1 of 17
Password Managers
LastPass
OWASP Austin CryptoParty | January 26, 2021
Nice to meet you!
Bertold Kolics
● Question Asker at mabl
● Past roles include developer & tester
● Twitter: @bkolics
● Web: https://bertold.kolics.net
QA Manager, mabl
Passwords? I need more than one?
● In Real Life - physical keys
● Do you need more than one? YES!!!
○ If you lose one, the damage is limited, replace
just one lock
○ If you want to share one, you can limit who has
access to what
● Do you want your locks to be hard to pick? Of course!
Passwords are your keys on the Internet
Keep Them
● Secure
○ away from the eyes of the hackers
● Unique
○ unique key for each door - unique password for each service
● Hard to guess
○ Not just 123456 or your anniversary
○ Internet is open 24/7, ton of information is public about you
○ Don’t make it easy for the bad guys
How Do I Remember them All?
Do Not Remember Them All*
● In Real Life - physical keys
○ do you need more than one?
○ do your locks need to be hard to pick?
● YES - for your own security
○ If you lose one, the damage is limited, replace just one lock
○ If you want to share one, you can limit who has access to what
● Passwords are your keys on the Internet
○ Keep them secure
● Your safe deposit box for the Internet
○ where you can keep your passwords securely
○ and do so much more
● Just one key to rule them all
○ the password to the password manager
○ make it hard to guess
■ more characters the better
■ use special characters, number
Password Managers To The Rescue
● Create a strong password
○ PasswordCard
https://passwordcard.org
○ Diceware - https://bit.ly/diceware
■ roll dice 6 times
■ match them to words
● Practice to memorize it
● Store in your real life safe deposit box
○ No sticky note on monitor
Keep The Master Password Safe
Password managers do even more
● Generate secure, hard-to-guess passwords
● Automatically fill in username and password on websites
● Enable secure sharing with your family or friends
○ never e-mail or text passwords in clear text
● Not just for passwords
○ secure text
○ secure copies of important documents
Lastpass
● Download from https://lastpass.com for the desktop
○ Browser extension for Chrome, Edge, Firefox, Safari
○ Standalone app
● Download from the App Store or Android Store for your phone
● Passwords and other data will be at your fingertips
○ synchronized across devices such as iPhone, Windows laptop
Create strong passwords
● LastPass generates strong passwords for you
and stores them securely
Automatic filling
When you visit the website again it fills out the
credentials automatically
● It detects password changes and make it easy
to update your saved credentials
Detects Password Changes
More than passwords
Store other data safely even photos of
important documents
Sharing, notes
● Share credentials safely with others without
sending passwords in clear-text in emails
● Notes allow you to save additional information
such as recovery codes
Lastpass - recap
● You must not use the same password across multiple sites
● You cannot remember all your passwords
● Use password managers to keep passwords safe
○ The last password you have to remember is
● Free tool for basic usage
○ paid options available for advanced users or family subscription
A word of caution
● Do not forget your master password
● LastPass cannot access your
credentials stored inside your
password vault
Thank you!
Bertold Kolics
Twitter: @bkolics
Web: https://bertold.kolics.net
QA Manager, mabl

More Related Content

Similar to Password Managers - Lastpass

Cybersecurity Awareness Training Presentation v1.3
Cybersecurity Awareness Training Presentation v1.3Cybersecurity Awareness Training Presentation v1.3
Cybersecurity Awareness Training Presentation v1.3
DallasHaselhorst
 

Similar to Password Managers - Lastpass (20)

Securing your digital life - Jason Addie
Securing your digital life -  Jason AddieSecuring your digital life -  Jason Addie
Securing your digital life - Jason Addie
 
Nonprofit technology common problems and some possible solutions
Nonprofit technology common problems and some possible solutionsNonprofit technology common problems and some possible solutions
Nonprofit technology common problems and some possible solutions
 
Securing your Bitcoin wallet
Securing your Bitcoin walletSecuring your Bitcoin wallet
Securing your Bitcoin wallet
 
Simple Computer Tips - Screen Shots, Passwords, etc
Simple Computer Tips - Screen Shots, Passwords, etcSimple Computer Tips - Screen Shots, Passwords, etc
Simple Computer Tips - Screen Shots, Passwords, etc
 
WordCamp Milwaukee 2012 - Aaron Saray - Secure Wordpress Coding
WordCamp Milwaukee 2012 - Aaron Saray - Secure Wordpress CodingWordCamp Milwaukee 2012 - Aaron Saray - Secure Wordpress Coding
WordCamp Milwaukee 2012 - Aaron Saray - Secure Wordpress Coding
 
Two-factor authentication
Two-factor authenticationTwo-factor authentication
Two-factor authentication
 
Everyday computer tips
Everyday computer tipsEveryday computer tips
Everyday computer tips
 
Cybersecurity Awareness Training Presentation v1.3
Cybersecurity Awareness Training Presentation v1.3Cybersecurity Awareness Training Presentation v1.3
Cybersecurity Awareness Training Presentation v1.3
 
Password management for you
Password management for youPassword management for you
Password management for you
 
Scalable, good, cheap
Scalable, good, cheapScalable, good, cheap
Scalable, good, cheap
 
Seven ways to be a happier JavaScript developer - NDC Oslo
Seven ways to be a happier JavaScript developer - NDC OsloSeven ways to be a happier JavaScript developer - NDC Oslo
Seven ways to be a happier JavaScript developer - NDC Oslo
 
Password best practices and the last pass hack
Password best practices and the last pass hackPassword best practices and the last pass hack
Password best practices and the last pass hack
 
Kare technology training
Kare technology trainingKare technology training
Kare technology training
 
Strong business needs strong foundations
Strong business needs strong foundationsStrong business needs strong foundations
Strong business needs strong foundations
 
Email privacy
Email privacyEmail privacy
Email privacy
 
Cybersecurity Awareness Training Presentation v1.0
Cybersecurity Awareness Training Presentation v1.0Cybersecurity Awareness Training Presentation v1.0
Cybersecurity Awareness Training Presentation v1.0
 
WordPress Security
WordPress SecurityWordPress Security
WordPress Security
 
Coding dojo
Coding dojoCoding dojo
Coding dojo
 
Crypto OpSec - How to Securely Store Bitcoin and Other Crypto Assets
Crypto OpSec - How to Securely Store Bitcoin and Other Crypto AssetsCrypto OpSec - How to Securely Store Bitcoin and Other Crypto Assets
Crypto OpSec - How to Securely Store Bitcoin and Other Crypto Assets
 
Pen Testing Development
Pen Testing DevelopmentPen Testing Development
Pen Testing Development
 

More from Bertold Kolics

More from Bertold Kolics (9)

Defensive API programming techniques for Gophers
Defensive API programming techniques for GophersDefensive API programming techniques for Gophers
Defensive API programming techniques for Gophers
 
The Testers' Secret Weapon - Code Reviews
The Testers' Secret Weapon - Code ReviewsThe Testers' Secret Weapon - Code Reviews
The Testers' Secret Weapon - Code Reviews
 
A Tester's Life
A Tester's LifeA Tester's Life
A Tester's Life
 
Taskfile - makefiles are fun again
Taskfile - makefiles are fun againTaskfile - makefiles are fun again
Taskfile - makefiles are fun again
 
Make DevOps inclusive
Make DevOps inclusiveMake DevOps inclusive
Make DevOps inclusive
 
GitHub Actions demo with mabl
GitHub Actions demo with mablGitHub Actions demo with mabl
GitHub Actions demo with mabl
 
Improve quality culture using visualization
Improve quality culture using visualizationImprove quality culture using visualization
Improve quality culture using visualization
 
Funnels of Hiring Test Engineers
Funnels of Hiring Test EngineersFunnels of Hiring Test Engineers
Funnels of Hiring Test Engineers
 
Session Based Testing Made Fun
Session Based Testing Made FunSession Based Testing Made Fun
Session Based Testing Made Fun
 

Recently uploaded

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 

Password Managers - Lastpass

  • 1. Password Managers LastPass OWASP Austin CryptoParty | January 26, 2021
  • 2. Nice to meet you! Bertold Kolics ● Question Asker at mabl ● Past roles include developer & tester ● Twitter: @bkolics ● Web: https://bertold.kolics.net QA Manager, mabl
  • 3. Passwords? I need more than one? ● In Real Life - physical keys ● Do you need more than one? YES!!! ○ If you lose one, the damage is limited, replace just one lock ○ If you want to share one, you can limit who has access to what ● Do you want your locks to be hard to pick? Of course!
  • 4. Passwords are your keys on the Internet Keep Them ● Secure ○ away from the eyes of the hackers ● Unique ○ unique key for each door - unique password for each service ● Hard to guess ○ Not just 123456 or your anniversary ○ Internet is open 24/7, ton of information is public about you ○ Don’t make it easy for the bad guys
  • 5. How Do I Remember them All? Do Not Remember Them All* ● In Real Life - physical keys ○ do you need more than one? ○ do your locks need to be hard to pick? ● YES - for your own security ○ If you lose one, the damage is limited, replace just one lock ○ If you want to share one, you can limit who has access to what ● Passwords are your keys on the Internet ○ Keep them secure
  • 6. ● Your safe deposit box for the Internet ○ where you can keep your passwords securely ○ and do so much more ● Just one key to rule them all ○ the password to the password manager ○ make it hard to guess ■ more characters the better ■ use special characters, number Password Managers To The Rescue
  • 7. ● Create a strong password ○ PasswordCard https://passwordcard.org ○ Diceware - https://bit.ly/diceware ■ roll dice 6 times ■ match them to words ● Practice to memorize it ● Store in your real life safe deposit box ○ No sticky note on monitor Keep The Master Password Safe
  • 8. Password managers do even more ● Generate secure, hard-to-guess passwords ● Automatically fill in username and password on websites ● Enable secure sharing with your family or friends ○ never e-mail or text passwords in clear text ● Not just for passwords ○ secure text ○ secure copies of important documents
  • 9. Lastpass ● Download from https://lastpass.com for the desktop ○ Browser extension for Chrome, Edge, Firefox, Safari ○ Standalone app ● Download from the App Store or Android Store for your phone ● Passwords and other data will be at your fingertips ○ synchronized across devices such as iPhone, Windows laptop
  • 10. Create strong passwords ● LastPass generates strong passwords for you and stores them securely
  • 11. Automatic filling When you visit the website again it fills out the credentials automatically
  • 12. ● It detects password changes and make it easy to update your saved credentials Detects Password Changes
  • 13. More than passwords Store other data safely even photos of important documents
  • 14. Sharing, notes ● Share credentials safely with others without sending passwords in clear-text in emails ● Notes allow you to save additional information such as recovery codes
  • 15. Lastpass - recap ● You must not use the same password across multiple sites ● You cannot remember all your passwords ● Use password managers to keep passwords safe ○ The last password you have to remember is ● Free tool for basic usage ○ paid options available for advanced users or family subscription
  • 16. A word of caution ● Do not forget your master password ● LastPass cannot access your credentials stored inside your password vault
  • 17. Thank you! Bertold Kolics Twitter: @bkolics Web: https://bertold.kolics.net QA Manager, mabl

Editor's Notes

  1. Introduce yourself.
  2. Mary Kate then Darrel