Comment on Current account recovery best practices?
youngGoku@lemmy.world 9 months agoI use an email client which saves my password and I don’t need to enter it. But the keepass db can also store your email password for you.
Comment on Current account recovery best practices?
youngGoku@lemmy.world 9 months agoI use an email client which saves my password and I don’t need to enter it. But the keepass db can also store your email password for you.
Darkassassin07@lemmy.ca 9 months ago
That’s the problem.
We’re discussing accessing your accounts without prior access to a pre-authorized device.
If you don’t have a device that’s already signed into your email, you can’t get into your passwords at all. Email is locked with your password db, your password db is locked with your email. Without one or the other already, you’ve locked yourself out of your own accounts.
youngGoku@lemmy.world 9 months ago
Keepass db doesn’t use email 2fa, its just a file you store on your device
Darkassassin07@lemmy.ca 9 months ago
That’s still gaining access through a device that’s already signed in/has your password db.
If you do not have access to a device that’s already signed into your accounts/has a copy of your password db; how do get in?
Presumably you’re smart enough to not have password only auth on a public facing nextcloud instance if it stores your password db…
This is the scenario we are discussing. The fact you store you db on other devices is entirely irrelevant.
youngGoku@lemmy.world 9 months ago
My nextcloud instance uses fail2ban and I use a >32bit strong password.
Assuming I lose my phone and my laptop and my personal computer and my nextcloud instance I would be screwed.
Since I host my own mailserver I would be able to create a new mailserver with a new password though and recover any accounts with a new email.