• 0 Posts
  • 73 Comments
Joined 1 year ago
cake
Cake day: June 19th, 2023

help-circle




  • I’m gonna go with no, because of containerization and permission management. On your computer, any program can do pretty much anything, unless you explicitly take measures against this. On a smartphone, you get a lot of control over your apps. In newer Android versions you can even completely disable cameras and microphones (even if only in software).

    I would use a throwaway account and avoid giving Google any personal data tho. Of course they could still figure stuff out, but it’s harder and unreliable, not to mention super-duper illegal (at least in the EU), so I kinda doubt they go the extra mile.





  • I’m just gonna go ahead and say it: 16 Characters are sufficient and 20 pretty damn secure.

    That is assuming they do stuff right and there are no vulnerabilities, which they won’t and there are. However they may manifest, they are a greater concern at 16+ characters, especially if they don’t offer 2FA.

    The reason is that even if machines become powerful enough that 16 characters can be bruteforced, which they can’t atm, you can effectively defend everything against bruteforce attacks by other means. Including but not limited to limiting login attempts, salts and pepper, multiple encryption layers etc.

    With just a salt pepper you can make a 16 char password effectively a 24 char password… Or a 2.000.000 char password. Assuming it is not stolen alongside that is.

    Edit: Changed ‘salt’ to ‘pepper’.