securitytxt.org
password-manager-resources
Our great sponsors
securitytxt.org | password-manager-resources | |
---|---|---|
21 | 10 | |
51 | 3,549 | |
- | 1.5% | |
5.1 | 8.1 | |
3 months ago | 5 days ago | |
HTML | JavaScript | |
MIT License | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
securitytxt.org
-
Ask HN: The middle ground for email selfhosting
Lemme guess, Well-known Security?
- RFC 9116: A File Format to Aid in Security Vulnerability Disclosure
-
My server is being attacked
If you see at the end of attack carefully, you'll see /.well-known/security.txt which already explained by securitytxt.org. That means, there's an either non-profit or for-profit organization that proactively find your site's vulnerability and trying to help you. For the for-profit organizations, usually they just give you information what vulnerability but you have to pay in order to get the solution.
-
New Security Tactic
I would laugh if I saw this in a security.txt file.. make it happen.
-
Prosecutor won't charge reporter who uncovered database flaw
as defined on https://securitytxt.org/ “When security risks in web services are discovered by independent security researchers who understand the severity of the risk, they often lack the channels to disclose them properly. As a result, security issues may be left unreported. security.txt defines a standard to help organizations define the process for security researchers to disclose security vulnerabilities securely.”
-
If it's illegal to "attack" websites without permission, how does bug bounty hunting work?
There are quite a lot of websites that implement the security. txt already. See https://securitytxt.org for more information about that
- I found an exploit in a website. What should I do?
- Nach Datenleck: Hausdurchsuchung statt Dankeschön
-
What is Security.txt and Why Do I Need It?
There are additional optional fields available for encryption, acknowledgements, canonical references, and more. You can find out more about this at the official security.txt website.
-
Why oh Why does it take so long for purchase security texts to arrive?
here it is: https://securitytxt.org/
password-manager-resources
-
Why does Apple’s “Strong Password” not meet most websites’ criteria
FWIW, Apple asks users to tell them the password requirements to websites they notice the "Strong Password" feature doesn't work correctly.
-
How to use iCloud Keychain, Apple's built-in and free password manager
The password complexity rule set is open source, you can contribute requirements for specific sites: https://github.com/apple/password-manager-resources
- With Safari 15, it's now dead-easy to switch from LastPass to iCloud Keychain
-
1Password for Mac Moving to Electron
If it‘s worth the effort to you, you can try amend the password rules here: https://github.com/apple/password-manager-resources/blob/mai...
-
Supreme Court, in a 6–2 ruling in Google v. Oracle, concludes that Google’s use of Java API was a fair use of that material
And JavaScript
-
security.txt
You might be thinking about:
https://github.com/apple/password-manager-resources
or the related:
https://github.com/w3c/webappsec-change-password-url
But mainly if you are responsible for a system and you're willing to do work to improve security your first focus should be "implement WebAuthn so my users can stop worrying about passwords entirely" not "I wonder if more complicated password handling would help somehow?"
-
Let me tell Settings that multiple sites have the same password because they are same site (to avoid false warnings which decrease usefulness of the entire thing)
There is the Apple Password Manager Resources GitHub project, which seemingly is used for certain iCloud Keychain intelligence, such as shared Password Backends. You could open Pull Requests there to make your suggestions.
-
1Password X extension doesn't allow password configuration?
Back in August 2020, 1Password X v1.21.0 added support for Apple’s Password Manager Resources repository, which includes a curated crowd-sourced list of 160 sites’ password requirements, with more added frequently. For any site on that list, the password generator in 1Password X automatically generates a strong password that fits the website’s criteria. I hope that makes it to 1Password apps soon – it’s really useful and an awesome improvement. The list of supported sites will grow over time! Since the requirements are set by the site, user-facing digits/symbols sliders wouldn’t work.
- Collaborate on resources to make password management better
-
New to 1P - Some questions about family/shared vaults
Back in August 2020, 1Password X v1.21.0 added support for Apple’s Password Manager Resources repository, which includes a curated crowd-sourced list of 160 sites’ password requirements, with more added frequently. For any site on that list, the password generator in 1Password X automatically generates a strong password that fits the website’s criteria. I hope that makes it to 1Password apps soon – it’s really useful and an awesome improvement. The list of supported sites will grow over time! Since the requirements are set by the site, user-facing digits/symbols sliders wouldn’t work.
What are some alternatives?
uprove-javascript-sdk - The U-Prove JavaScript SDK implements the client-side of the U-Prove Cryptographic Specification, and is a companion to the U-Prove C# SDK. It can be used to write web clients interacting with U-Prove services. For more information about the U-Prove technology, please visit http://www.microsoft.com/uprove.
foundationdb - FoundationDB - the open source, distributed, transactional key-value store
countwords - Playing with counting word frequencies (and performance) in various languages.
hummingbird - Hummingbird compiles trained ML models into tensor computation for faster inference.
coremltools - Core ML tools contain supporting tools for Core ML model conversion, editing, and validation.
atlas-design - Atlas Design System serves the Microsoft Developer Relations design & engineering teams. Supporting web properties such as Documentation, Learn, Q&A, and Azure.com.
ServiceTalk - A networking framework that evolves with your application
security.txt
health-cards - Health Cards Framework: implementation guide and supporting material
msquic - Cross-platform, C implementation of the IETF QUIC protocol, exposed to C, C++, C# and Rust.
docker - Docker - the open-source application container engine
leocad - A CAD application for creating virtual LEGO models