This is awesome, I just read the entire thread and think it's all really good. Keepass is insane.
I have one question and two comments
Quote:
Originally Posted by ThePolygraph
Thanks a lot for producing these videos funkyworms, they really are so informative! I was pleased to see that I already take some of the precautions you recommend, but there are a few things I'm not clear on:
No-Script
I don't have a clue about how scripts work, but I'd like to understand this better. You mentioned that if one were to use Firefox with No-Script it would be pretty much impossible to get infected from browsing YouTube. But then you allowed (white-listed) the youtube & ytimg domains. Does this mean that if a dangerous script were on that page, it would be listed as something other than those two?
Also, since I installed No-Script, I have only been to a handful of sites but have had to allow scripts at most of them. Right here for example, when typing this post, I had to white-list 2+2 before I could use the bold/italics buttons in the editor. As I'm not an expert on these things and, if I need to keep 'allowing' all the sites I want to visit then isn't it just like a novice who uses a personal firewall and clicks 'allow allow allow'?
I don't mean this to sound like an argument haha. It's just that if I have to allow scripts at every forum, every site that has embedded videos, every site that uses flash etc, then it basically comes down to 'allow everything, but don't visit suspicious sites' which is just like saying 'don't install trash and you won't need to use something like Comodo'. Hopefully I have misunderstood how this works, and will be tutored shortly! I mentioned the firewall thing here because, for some time, I was doing exactly what you said - using Comodo and after deciding that I will install something, then just clicking 'allow allow allow' which is pretty damn pointless lol.
Can you elaborate on this? This is my exact sentiment. When I saw you accept ytimg in your video my first thought was "How does he know it's safe?" I installed noscript a long time ago and got rid of it because I was just clicking yes to everything unless it was on a sketchy site, and now I just don't go to those kinds of websites.
My two comments are
1.) I think not storing your stars PW is a good idea. Keepassing it means it won't stay in the clipboard for more than x seconds(12 by default) and if you have people over and forget it's a lot easier for someone to just see if you have a poker program, run it and gain access to your account. Obviously if you're using other means of security(pin etc) the chances are almost non-existent but I still don't see the harm. (unless this is what you meant by storing it lol)
2.) u r awesome and your avatar is amazing
in any case A+ would read again, my hulu password is 108 bits <3
EDIT: Oh yeah, I feel it
it can not be emphasized how important it is to back up your keepass DB
If your HD fails or you can't boot because of some lame Windows **** or your cyberlife is ******! IMO store it on a seperate HDD as well as a thumb drive and I feel if you're going to get a safety deposit box and put your PW in it, you might as well throw a backup in there, too.