• Activity
  • Votes
  • Comments
  • New
  • All activity
  • Showing only topics in ~tech with the tag "security". Back to normal view / Search all groups
    1. What do you use for 2fa?

      This Lifehacker article recommending Ente Auth reminded me that I am looking to migrate off Authy to something else. I thought I would see what Tilderinos are using: What do you use, and do you...

      This Lifehacker article recommending Ente Auth reminded me that I am looking to migrate off Authy to something else.

      I thought I would see what Tilderinos are using:

      • What do you use, and do you like it?
      • How do you deal with syncing?
      • Do you only generate codes on your phone, or do you use a desktop app too?
      • What questions should I be asking that I didn't ask?
      18 votes
    2. Recommendations about which Android texting app to use?

      Could someone please recommend a text messaging app for Android that is reasonably secure? Verizon is discontinuing their native texting (SMS) app. They recommend switching to Google Messages, but...

      Could someone please recommend a text messaging app for Android that is reasonably secure?

      Verizon is discontinuing their native texting (SMS) app. They recommend switching to Google Messages, but I would not like Google to have access to my entire text messaging history. I tried Signal, but my old messages don't transfer over (minor problem), and almost none of my family are willing to switch to Signal (big problem). When I search for advice, I get a bunch of AI slop articles and advertisements. So I figured I might have better luck asking here: Is there any text messaging app for Android that works well and isn't going to hoover up all my data?

      16 votes
    3. Data security help - SOC2ish

      Hi Tilderinos, I head up a small startup and we're looking to get some support for our data security. Up until now we've worked with small mom and pops that didn't have any requirements, but a few...

      Hi Tilderinos,

      I head up a small startup and we're looking to get some support for our data security. Up until now we've worked with small mom and pops that didn't have any requirements, but a few of our new clients have full data security teams and our infrastructure and policies/protocols aren't up to snuff. We reached out to a few consulting firms and they quotes us between $80-100k to get things set up and run us through a full SOC2 review. As a small company we don't really have that type of budget, more like $40-50k. I stumbled upon Vanta and Drata as alternatives and had meetings with their sales folks last week. Both of their offerings from setting up our protocols to monitoring and getting us through a SOC2 were only $16k.

      Are platform based companies like Vanta or Drata enough to get us off the ground while we're still getting set up? Has anyone worked with them before and have any feelings one way or the other? Should we be signing on with a security consulting company - be it at a lower rate if we can negotiate it?
      This is all quite new to me and any insight folks here can provide would be incredible useful.

      12 votes
    4. Help me ditch Chrome's password manager!

      I've been trying to reduce my reliance on all things Google, and one of the big ones is password management. I've tried several times to make the jump, but every time I start researching options...

      I've been trying to reduce my reliance on all things Google, and one of the big ones is password management. I've tried several times to make the jump, but every time I start researching options I'm overwhelmed by the selection. There are a lot of popular options out there, and I really don't have the time/energy to endure a misstep. So without a clear idea of which manager will check all of my boxes, I end up bailing on the process and keep using chrome's built in option.

      So to start, here's what I like about Chrome:

      • Automatically offers to store passwords without extra clicks
      • Autofills automatically where it can, and gives me an easy choice when it can't
      • Works everywhere I need passwords. (basically everywhere I browse the internet since chrome works everywhere)
      • Minimal overhead. This is hard to beat since Chrome just includes it, so I'm fine with a little extra setup if necessary.

      I used to use keepass portable on a thumb drive (I want to say circa ~2009ish), but it became really inconvenient as my usage shifted more to mobile devices.

      I see this as a first step to also reducing my reliance on Chrome so I can start to consider other browsers. Right now I feel locked in to Google's ecosystem, but I know I can break it up if I don't get too bogged down by choice. Much appreciate any help. :)

      34 votes