• Welcome to ASR. There are many reviews of audio hardware and expert members to help answer your questions. Click here to have your audio equipment measured for free!

Beware the scam...

Precisely these types of biometric security measures have been tricked often enough—even at an industrial level.
And how many movies involving severed thumbs and index fingers, or gouged-out eyeballs, does one have to watch to realize that, from a personal standpoint, this isn't exactly the best security method? ;) :facepalm:
Exactly. "Death and taxes" is still valid, and will probably stay valid forever.
 
There's no best method. But I prefer to add layers of security so that the complexity to crack open my passwords is high. Eg. a memorised complex password, combined with a biometric scheme, combined with encrypted storage, combined with multiple vaults, etc.
 
I think AudioKarma may be down. I got in this morning but kept getting 503 errors. Now I can't even log in anymore. They have been having issues for some time now. Seems like maybe now it is completely broken.
 
Can not even reach AudioKarma anymore. They are having some serious problems. Not sure if whoever runs that site has any idea what the hell is going on frankly. Here is the latest error, which makes no sense at all...
Screenshot at 2026-05-24 22-24-02.png
 
The entire site has been super flaky lately after they did some "upgrades" and also started using CloudFlare. The only way that it was even partially usable was with the help of an extension called CacheBuster. But what a pain to constantly have to use that. Oh well. I don't even know if they have any idea what is going on since it is now unreachable for me. Might have to see if I can get to it on the phone...
 
Nope. Can't even get to it by phone. I thought maybe the site was down but when I checked it is saying it's just me. So weird. Like I can't get to it from my IP address. I think maybe CloudFlare has gone amok.
 
More on password quality.


ps. got nothing to do with Bitwarden, it's just something I work with a lot.
I have a question. I looked at the chart that categorizes password strength. All the passwords listed were pretty much random characters. It seems the only determinant for strength is number of characters. What about say a 25 character password that contains actual random words that nobody could guess? Is that more secure than say an 8 character totally random one like in the chart?
 
I have a question. I looked at the chart that categorizes password strength. All the passwords listed were pretty much random characters. It seems the only determinant for strength is number of characters. What about say a 25 character password that contains actual random words that nobody could guess? Is that more secure than say an 8 character totally random one like in the chart?
Good question. I think random characters with non-alphabetical ones mixed is the best way for a password. But this depends on the algorithms of the cracking software. And on this I have no idea nor information.
 
I have a question. I looked at the chart that categorizes password strength. All the passwords listed were pretty much random characters. It seems the only determinant for strength is number of characters. What about say a 25 character password that contains actual random words that nobody could guess? Is that more secure than say an 8 character totally random one like in the chart?
The advantage of these random password strings is that they can't be guessed by using words. They also look like garbage when sniffed from communication. But that's not security, just added obscurity. Either way they are managed, so can use the random string extra security.

For something created with words it's important that humans are predictable and have tendencies. A long password of 3 words somewhere found on material on the desk - not that good. But create something long that has no easy hints, add some numbers, maybe one special char - that is very secure. After all we also need some (few) passwords that we can memorize and write easily.
 
BTW, when I got hacked over there on ASR, I also came across the email address of that hacker. So I actually emailed the con artist and asked him why he hacked my account. That was after I got my account back. He responded and it ended up in my Spam folder. He said "That's just the way it is. So that I can scam people". I simply blocked him after that. It was amusing and pathetic at the same time. He just straight up admitted to his scam. He said that I should get a new account and post about it, which I actually did before I restored my account. So that was interesting as well. I knew what to do, didn't panic and jumped into action. And it worked. Oh, and I reported his email address to a site that tracks scammers on the net. I forgot which one it was but I reported that email.

It is pretty crazy the tools that these scammers have. But they would not scam if there were not people who need to get scammed. One really has to do their due diligence these days. That is why I like to deal with places like Ebay. Because there are rules and protections there. Getting onto an audio forum and deciding to buy from another member... Maybe most of the time that works. Until that member is not really a member but a scammer...

I get it now... When I was not a member over there I could still use the forum but did not have access to the marketplace. When I recently became a member that allowed the scam to proceed. Something which I never even thought about...
 
I see this am am reminded of the biggest password security flaw I have: An inability to get my wife or son to use a password manager.
 
I see this am am reminded of the biggest password security flaw I have: An inability to get my wife or son to use a password manager.
You could install them a fake ransomware screen as a screensaver, that might help ;)

 
Have you tried them on Passkeys?
I haven’t, in part because of shared accounts and the inability to passkey share. I saw recently that 1password does passkey sharing within family accounts for shared accounts. I am going to try it and force the issue.
 
The most common way accounts are hacked these days is through "Infostealer" malware on PCs (often accidentally picked up from free software downloads, game mods, fake updates, or email attachments). This malware does not care about your password or your email (even Private Relay, HideMyEmail or whatever). Instead, it quietly steals your session cookies from your browser and exports them to the hacker. @coonmanx might have compromised more than just the AudioKarma login.
 
I haven’t, in part because of shared accounts and the inability to passkey share. I saw recently that 1password does passkey sharing within family accounts for shared accounts. I am going to try it and force the issue.
A lot of sites will let you register more than one passkey though, so you can each register your own passkey - or more than one if you want a backup, use more than one platform etc.
 
We have had a number of account take overs like that here. Luckily there is not much they can abuse other than posting spam. Strong passwords and two factor authentication is necessary to reduce the risk of these things.

And related, put a block on your phone number transfer at your mobile carrier. People have been known to hijack your phone number and then get into your account using 2FA!
 
Back
Top Bottom