kylewritescode, to BraveBrowser
@kylewritescode@allthingstech.social avatar

Looking for a way to move to #BraveBrowser as my default browser across all my devices. Thing is, I have all my passwords/2FA codes in Keychain.

Does anyone have any suggestions for an open-source solution for a cross-platform password manager with 2FA that will work with Brave?

#Passwords #2FA #Browsers #Security #Tech #Questions

dereulenspiegel, (edited ) to random German
@dereulenspiegel@chaos.social avatar

I am looking for a new app, especially for tokens. Has anyone here experiences with ( https://2fas.com/ ) and knows whether it is secure and good?
Also does anybody has a good migration path away from since that it no longer maintained?
Thanks for all the great recommendations. For multiple reasons I am also seeking something with iOS support.

AgreeableLandscape, to random

Random Website: You need to set up with your phone number!

Me: Why?

Website: In case we get hacked!

Me: I don't really care, no one even knows about this account and it doesn't have my personal information.

Website: You misunderstand, it's so that in case we get hacked, we HAVE your information to leak to the hackers. They worked hard and deserve it! Also we sell your account to ad companies but they're not interested unless they can tie it to a real person.

GrahamDowns, to Banking

I received another email from
, advising me to stop using a password to log into Internet Banking, and switch to scanning a QR code from within the Mobile App. No, Standard Bank, I'm not going to do that. Because it's stupid, and here's why:

The whole reason for me to visit Internet Banking on my computer is because I do not WANT to log into the banking app on my phone. But in order for me to use Internet Banking on my computer, they want me to open the app on my phone, log in, then navigate to the menu item for QR code scanning, and then scan the code I see on my PC monitor. At which point, I may as well use the mobile app. Which I didn't want.

Why can't they just use one of the many many Authenticator apps, like a normal company? I'd be more than happy to open my authenticator app, find Standard Bank, and punch the code in. It's good enough for Google, Microsoft, Github....

ezlin, to random

hm. Do I spend $30 (after shipping) on another #2FA #U2F security key, but this one can store 50 #TOTP (as well as work as a standard #FIDO2 #SecurityKey) entries.

Compared to #yubico #yubikey which is $50 (before shipping) and stores only 32 TOTP.

It'd only be around $22, but it apparently ships from Switzerland?

https://www.token2.net/shop/category/fido2-with-totp

But it's still $20 less than the Yubikey that does the same thing but with less storage.

Oh it's tempting!

Gotta sleep on it. G'night world!

#nerd #geek

nodebb, to security
@nodebb@fosstodon.org avatar

The Two-Factor Authentication plugin that comes bundled with was just updated to v7.4.0. It now notifies you if your account was accessed, but the second factor challenge was not passed. If you see this notification, and it wasn't you, you just might want to change your now-compromised password!

Oft forgotten, this feature provides much needed positive reinforcement that, yeah, works!

bortzmeyer, to random French
@bortzmeyer@mastodon.gougere.fr avatar

Tout le monde a bien changé son mot de passe au RIPE et ET et activé le #2FA si ce n'était pas encore fait ?
#ripeadmin #cybersécuritay

kylewritescode, to infosec
@kylewritescode@allthingstech.social avatar

Is there an easy way that I can transfer my 2FA codes out of Authy and into iCloud Keychain?

#Authy #Keychain #2FA #InfoSec

gcluley, to cryptocurrency
@gcluley@mastodon.green avatar

Security firm Mandiant says it didn’t have 2FA enabled on its hacked Twitter account.

I have questions...

https://grahamcluley.com/security-firm-mandiant-says-it-didnt-have-2fa-enabled-on-its-hacked-twitter-account/

cybersecurity #2fa #mandiant #cryptocurrency #twitter

schizanon, to passkeys
@schizanon@mastodon.social avatar

PassKeys seem like a bad idea. Google backs them up to the cloud, so if your Google account is compromised then all your private keys are compromised. I don't see how that's an improvement over password+2FA at all.

Now security keys I get; keep the private key on an airgapped device. That's good. Hell I even keep my 2FA-OTP salts on a YubiKey.

#passkeys #fido2 #webauthn #yubikey #2fa #otp #authentication #cryptography #security #passwords #passkey #password #securityKey #google

my_actual_brain, to random

I am all in favor of 2FA, but I am kind of afraid to enable it as I fear that I will get permanently locked out of important accounts.

How are you dealing with this?
#security #privacy #2fa #password

bitwarden, (edited ) to Cybersecurity
@bitwarden@fosstodon.org avatar

Two-factor authentication is a great way to protect your Bitwarden vault. Watch this video to learn how to set up : https://www.youtube.com/watch?v=MeKyZP4KIQ0

mauve, to random
@mauve@mastodon.mauve.moe avatar

Ugh. I wish things that required #2FA authenticator apps were required to support having multiple apps. I've been using KeySmith on KDE and I have no way to reuse my data on a second device. 🙃

danie10, to opensource
@danie10@mastodon.social avatar

2FAS is a private, free and open-source two-factor authenticator for Android and iOS, and Desktop Browsers

2FAS is an interesting app as it focusses more on privacy than Google and Microsoft’s 2FA authenticators do (we all know Google and Microsoft love to know where you log in, from where, and when). To this end, the app operates on its own and, if you choose to, ...continues

See https://gadgeteer.co.za/2fas-is-a-private-free-and-open-source-two-factor-authenticator-for-android-and-ios-and-desktop-browsers/

#2fa #opensource #privacy #security #technology

joergi, to security

Security question about 2fa and password changes:

If a website uses 2fa - why is it never asked for before you can reset a password?

If Eve has control over the email of Alice - Eve can at least change the password , so Alice has no access to the website anymore.

Any reasons, why I have never seen a 2fa request before changing the password? Am I missing something?

#security #infosec #2fa

chriscuratolo, to opensource

Can anyone suggest me some opensource alternatives to Google Authenticator for 2FA?

#opensource #privacy #Google #2FA #RightToPrivacy

bortzmeyer, to github French
@bortzmeyer@mastodon.gougere.fr avatar

Paf, #Github qui me sécurise « We're reaching out to let you know that, as announced last year, we have officially begun requiring users who contribute code on GitHub.com to have two-factor authentication (2FA) enabled. »

#2FA #cybersécuritay

scy, to random
@scy@chaos.social avatar

Pondering whether to move my #2FA #TOTP secrets to a #YubiKey.

Pro:
• stored safely on protected hardware
• secret "cannot" be extracted
• can access TOTP codes from an untrusted device, e.g. if my phone's battery is empty

Con:
• backing up the secrets is "not possible"
• having a second YubiKey for redundancy is recommended, but both need to be present when setting up a new secret (or you need to store a copy of the secret somewhere else)
• only has 32 slots (but I only have 23 TOTPs atm)

Taffer, to lemmy
@Taffer@mastodon.gamedev.place avatar

I was going to mess around with Lemmy but I enabled 2FA yesterday, and somehow failed to update 1Password with the 2FA. So, I guess I've lost that account. 🤷

There were no recovery codes offered when I enabled 2FA. Sigh.

#lemmy #2fa

bitwarden, to Cybersecurity
@bitwarden@fosstodon.org avatar

FIDO2 WebAuthn #2FA is now free for everyone! All users can secure their Bitwarden account using a hardware security key or other FIDO2 WebAuthn credential generator. Learn more here: https://bitwarden.com/blog/fido2-webauthn-2fa-in-all-bitwarden-plans

#cybersecurity #passwordsecurity #passwordmanagement #passwordmanager

0x58, to Cybersecurity
Tutanota, to random
@Tutanota@mastodon.social avatar

What a surprise: @bitwarden explains setting up 2fa with Tuta Mail (slide 39)! 😍

👉 https://bitwarden.com/resources/presentations/the-triangle-of-security-success/

And rightly so: Because #encrypted email get even more secure with #2FA and #passwordmanagers 💪

root42, to random
@root42@chaos.social avatar

As #twilio is sunsetting their #authy desktop apps, I am wondering if there are any open source #2fa apps out there that support both desktop and mobile, maybe even Apple Watch...? Twilio still supports the mobile apps, but I don't want to get caught unprepared if they ever drop those, too.

trendless, to security

Sanity check:

2FA via SMS was already risky and unsafe, but hey let's make it even worse by adding the ability to have the code sent to a friend?!

:mastomindblown:

Is it really that hard to setup an authenticator app like Aegis or use the one built into keychain?

hl, to mastodon
@hl@social.lol avatar

I've activated two-factor-authentication on my #Mastodon account. That means you can be 53.42% more certain that the nonsense written here is genuine nonsense by me, and not imitation nonsense.

#security #2FA

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • InstantRegret
  • mdbf
  • ethstaker
  • magazineikmin
  • cubers
  • rosin
  • thenastyranch
  • Youngstown
  • osvaldo12
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • Durango
  • everett
  • tacticalgear
  • modclub
  • anitta
  • cisconetworking
  • tester
  • ngwrru68w68
  • GTA5RPClips
  • normalnudes
  • megavids
  • Leos
  • lostlight
  • All magazines