Post #1734519
2026-01-25 17:08 UTC
Replies (30)
-
@number137@mastodon.social 2026-01-25 17:13
@teunvink@mstdn.social
-
@ojs@c.im 2026-01-25 17:15
@teunvink@mstdn.social yeah, something like mypaasword.example.com AAAA IN $IP No one will suspect a thing
-
@benno@bsd.network 2026-01-25 18:05
@teunvink@mstdn.social and if, for some reason you cannot log in: it's DNS!
-
@mirabilos@toot.mirbsd.org 2026-01-25 18:18
@teunvink@mstdn.social ah, I can remember IPv6 addresses badly enough already, and without this, passwords have a separate headspace.
-
@cybso@osna.social 2026-01-25 18:25
@teunvink@mstdn.social That's an... interesting idea 🤔. Especially since you can use the different spellings of IPv6 addresses to increase entropy 😏
-
@rvstaveren@mastodon.online 2026-01-25 20:00
@teunvink@mstdn.social nice, and my password will be proctected from tampering with thanks to DNSSEC and a dictionary attack is impossible thanks to NSEC3 💀
-
@hisold@toot.io 2026-01-25 20:01
@teunvink@mstdn.social I should store my passwords in a DNS resolver.
-
@Foxboron@chaos.social 2026-01-25 20:13
@teunvink@mstdn.social So you are saying I can use DNS as my password manager.
-
@thomrstrom@triangletoot.party 2026-01-25 20:47
@teunvink@mstdn.social I've used UNIX command lines for passwords similarly in the past; I mean, who's going to suspect it when I accidentally type "sudo ls -lad /etc" into a Discord window?
-
@bweller@mstdn.social 2026-01-25 20:49
@teunvink@mstdn.social it is just a really big number
-
@bebehei@cyberplace.social 2026-01-25 21:12
@teunvink@mstdn.social If you use non-canonical forms, you even can hide it "securely" in your DNS zonefile.
-
@IPngNetworks@ublog.tech 2026-01-25 21:18
@teunvink@mstdn.social best advice i've seen all year =)
-
@stibbons@s.scintilla.social 2026-01-25 23:18
@teunvink@mstdn.social :geordi_dislike: lastpass :geordi_like: dig
-
@lanodan@queer.hacktivis.me 2026-01-26 00:30
@teunvink@mstdn.social Yeah, I guess that can work. head -c 16 /dev/urandom | od -An -t x2 | sed -e 's,^ ,,' -e 's, ,:,g' Although with putting it in DNS you'd have to watch out for zero-fills in generated form and stripped-zero in DNS. So I'll stick with head -c 18 /dev/urandom | base64
-
@joat@mastodon.scot 2026-01-26 00:35
@teunvink@mstdn.social I had the same idea but with valid Linux commands. Somebody with a keylogger won't suspect it's a password.
-
@markzero@c.im 2026-01-26 00:57
@teunvink@mstdn.social Just make a bunch of local users corresponding to server logins, put their passwords in their .plans, and finger them. You can even pipe that into commands. *Much* easier than dealing with IPv6.
-
@azonenberg@ioc.exchange 2026-01-26 02:33
@teunvink@mstdn.social I mean I've used uuids as passwords before... Does that count?
-
@FrankauLux@polyglot.city 2026-01-26 07:29
@teunvink@mstdn.social that is certainly one way to ensure wider diffusion 🙄
-
@guenther@chaos.social 2026-01-26 07:31
@teunvink@mstdn.social won't you loose case info when storing it in DNS?
-
@lambert@rheinneckar.social 2026-01-26 09:51
@teunvink@mstdn.social @bert_hubert@eupolicy.social my sincere apologies if this was meant as a joke and I simply didn't get it. But especially the advice to publish the value of your own password—even if it looks like an inconspicuous IPv6 address—in a public database such as the DNS seems to me about as smart as investing your entire fortune in AI stocks. If you have trouble remembering your passwords, you should use more modern alternatives such as passkeys, or use a password manager.
-
@Windfisch@chaos.social 2026-01-26 10:18
@teunvink@mstdn.social @leyrer@23.social feature request: can your password field just resolve the AAAA dns record? saves so much typing time!
-
@gunstick@mastodon.opencloud.lu 2026-01-26 10:38
@teunvink@mstdn.social I actually use assembler code as passwords
-
@7@misskey.id 2026-01-26 12:52
@teunvink@mstdn.social RE-DNS People keep all weird stuff in TXT records
-
@pseudonym@mastodon.online 2026-01-26 22:05
@teunvink@mstdn.social This whole thread is cursed. I approve. #infosec
-
@CRo@norden.social 2026-01-26 22:30
@teunvink@mstdn.social 😂
-
@Ju_@mamot.fr 2026-01-27 07:48
@teunvink@mstdn.social I use URL as passwords sometime for the same copy/paste reason @bortzmeyer@mastodon.gougere.fr
-
@sheogorath@microblog.shivering-isles.com 2026-01-27 12:46
@teunvink@mstdn.social Additionally, always have your passwordsafe ready: https://dns.google/query?name=laptop.passwords.example.com&rr_type=AAAA
-
@rbo_ne@chaos.social 2026-01-27 16:16
@teunvink@mstdn.social Bonushack2: many Chat clients will happily replace random parts of your „password“ with emojis and confuse even more @bert_hubert@eupolicy.social
-
@expiredtoken@mastodon.social 2026-01-27 19:53
@teunvink@mstdn.social Hidden in plain sight, Purloined Letter style, I like it. Caveat: a lot of network admins won't recognize it as an IPv6 address because they don't know what it is.
-
@cheesefox@infosec.exchange 2026-02-03 06:15
@teunvink@mstdn.social @catsalad@infosec.exchange ::1