Taffer, to UX
@Taffer@mastodon.gamedev.place avatar

Zenva's amazing login process continues to amuse (and keep me from looking at the courses I bought).

Now they're doing 2FA by emailing you a code (ARGH, do TOTP or GO AWAY). The email gets flagged by my ISP's filters as spam, and there's a countdown timer. By the time I've rescued it from the spam bucket, the timer is expired.

#zenva #totp #2fa #ux

Belganon, to passkeys French
@Belganon@mastodon.social avatar

, le gestionnaire de de @protonprivacy, prend désormais en charge les . Peu de sites utilisent déjà cette technologie, mais le nombre augmente de plus en plus. Une nouvelle couche de pour vos connections, plus performante et sûr que la

https://proton.me/blog/proton-pass-passkeys

maxleibman, to infosec
@maxleibman@mastodon.social avatar

PLEASE ENTER THE SECURITY CODE PROVIDED VIA SMS. YOU HAVE TWENTY SECONDS TO COMPLY.
#2FA #InfoSec

ED209, a large, heavily-armed, bipedal robot, walking into a boardroom (footage from the film ‘RoboCop’).

sehe, to random
@sehe@fosstodon.org avatar

Byebye #Authy!

I remember the day I switched to Authy because it would not vendor-lockin me for #TOTP codes. Alas, today is the day where I ditched it because Authy - without warning - stopped supporting the desktop app, even hurrying the deadline by 5 months! That was 70% of the total notification window as far as I could tell.

Requiring a mobile device for #2FA #MFA is not quite the same for me, and it can get lost (or stolen) way too easily for my taste.

micheleann, to productivity
@micheleann@eldritch.cafe avatar

Alrighty! 11am and I finally finished logging into everything. Time for a coffee break, right?

#2fa #passwordless #productivity

vam103, to security
@vam103@mathstodon.xyz avatar

Apparently NS&I (the old UK National Savings, as they put it "the government savings bank") have launched two factor authentication, which is good.

Except, it told me to expect a code, you would think through SMS. But no, its a phone call. To make matters worse its from France according to my phone! So of course I thought it had been compromised and wrote to them.

No, apparently they use a French company to do the OTP codes and then mask this with the UK number normally, except when it messes up or I guess your security is so high it does not show it. Actually the reply seemed annoyed that I did not just accept that the UK government bank would use a French company to do their security.

So I do not think much of the " improved security " until I can register a FIDO key or the local code generator as a call from France seems to have lots of points of failure. (Its not that its France specifically, just that it is another country.) Also they should mention this on their website! (Unless missed it).

#nsandi #2FA #security

https://www.nsandi.com/get-to-know-us/security/improved-security

scy, to random
@scy@chaos.social avatar

Pondering whether to move my #2FA #TOTP secrets to a #YubiKey.

Pro:
• stored safely on protected hardware
• secret "cannot" be extracted
• can access TOTP codes from an untrusted device, e.g. if my phone's battery is empty

Con:
• backing up the secrets is "not possible"
• having a second YubiKey for redundancy is recommended, but both need to be present when setting up a new secret (or you need to store a copy of the secret somewhere else)
• only has 32 slots (but I only have 23 TOTPs atm)

Edent, (edited ) to foss
@Edent@mastodon.social avatar

Which open-source TOTP code generator do you use on Android?

#FOSS #Android #2FA #MFA #TOTP

publicvoit, to random German
@publicvoit@graz.social avatar

Wie man eine vertrauenswürdige Authentifizierungs-App auswählt
https://www.karl-voit.at/2023/03/05/TOTP-Auswahl/

... mit einer deutlichen Warnung vor dem !

stux, to Facebook
@stux@mstdn.social avatar

A leaky database spilled codes for the world’s tech giants

A technology company that routes millions of SMS text messages across the world has secured an exposed database that was spilling one-time security codes that may have granted users’ access to their , and accounts.

When reached by email, a Meta spokesperson did not comment. Spokespeople for Google and TikTok did not respond to requests for comment

Via @TechCrunch

https://techcrunch.com/2024/02/29/leaky-database-two-factor-codes/

parigotmanchot, to random French
@parigotmanchot@mastodon.social avatar

: 2FA QR Code Generator - Générateur de QR Code à partir d'un secret 2FA.
Gère les URL type otpauth:// : https://stefansundin.github.io/2fa-qr/

youronlyone, to Cryptomator
@youronlyone@c.im avatar

Services which still blocks your account for supposedly “suspicious activity”, even though you have , is like saying “we don't trust our own system” and/or “we don't trust you, we think you shared your 2FA secret with someone”.

I don't know. If it is the latter, that's user-error and their problem. If we continue solving user-error issues, the end-user will never learn anything.

Is 2FA perfect? Of course not. But it is far less likely for an account to be compromised if 2FA is enabled (without user-error).

So, accounts with 2FA should not be included in the “we temporarily blocked your account because of suspicious activity”. If there was indeed a legitimate unauthorised account access, due to user-error, let the user deal with it and learn from it. Otherwise, what's the use of 2FA?

In the gaming industry, some companies actually do that. If your account has 2FA enabled, they automatically remove your account from IP address checks. This allows the account owner to freely use VPNs without getting banned because of IP jumps. They don't mention it officially, but you can test it. If you disable 2FA and use VPNs, you'll get banned sooner or later (and have to go through a lengthy verification process). If you have 2FA enabled, you're free to use VPNs all you want.

(We're not talking about [gaming] services where they have regional licensing deals. They will indeed ban your account if you use a VPN because it is a restriction due to the regional licensing deals in place.)

I dunno, just . It's a hassle to suddenly see you're temporarily blocked even though you have 2FA enabled anyway. (Some services will even disable your 2FA because they assumed you shared your 2FA secret.)

Sure, there are people who keep a copy of their 2FA secret in unsecure ways. That still falls under user-error. 2FA secrets should not be kept, at least that's how it was designed. If a user wants to keep it, then encrypt it and store it somewhere. For example, use .

^_^

christine, to random
@christine@ruby.social avatar

Anyone else think this is odd, to turn on security key #2fa in #proton mail you have to have the 2FA enabled already with an authentication app? Why can't I just enable the hardware key...

Taffer, to random
@Taffer@mastodon.gamedev.place avatar

Could you please implement TOTP instead of sending an email or SMS code for 2FA?

Signed, everyone.

#2fa #totp

Edent, to random
@Edent@mastodon.social avatar

🆕 blog! “Giving the finger to MFA - a review of the Z1 Encrypter Ring from Cybernetic”
★★★★☆

I have mixed feelings about Multi-Factor Authentication. I get why it is necessary to rely on something which isn't a password but - let's be honest here - it is a pain juggling between SMS, TOTP apps, proprietary apps, and mag…

👀 Read more: https://shkspr.mobi/blog/2024/02/giving-the-finger-to-mfa-a-review-of-the-z1-encrypter-ring-from-cybernetic/

NHBoehm,
@NHBoehm@ioc.exchange avatar

@Edent Thank you for your review.

I seriously considered purchasing a ring.

But, it turns out that the shop does not process purchase requests, resulting in an incomplete page with nothing to click on.
And the support email bounces as nonexistent.

I hope that you would incorporate that information in your review and/or boost this as a real world experience.

#2fa #fido #gadget #MFA #cybernetic

jpmens, to random
@jpmens@mastodon.social avatar

deleted_by_author

  • Loading...
  • erAck,
    @erAck@social.tchncs.de avatar

    @jpmens
    Great. One more way to defeat the TWO factor principle.

    #2FAS #TOTP #2FA

    parigotmanchot, to random French
    @parigotmanchot@mastodon.social avatar

    #Shaarli: GitHub - beemdevelopment/Aegis: A free, secure and open source app for Android to manage your 2-step verification tokens. - Application mobile d'authentification double facteur (2FA).
    Permet d'importer les jetons depuis d'autres applications (accès root) et de sauvegarder automatiquement les jetons. : https://github.com/beemdevelopment/Aegis #totp #hotp #2fa

    smitha, to random
    @smitha@famichiki.jp avatar

    Well, crap, is shutting down its desktop app. I use its mobile one; should I start looking for an alternative just to be safe...? It's obviously not a major revenue stream for Twilio, so...

    katzenjens, to random German
    @katzenjens@social.tchncs.de avatar

    Leider nicht ganz zu Ende gedacht, das Teil. Absolut gute Idee, aber warum ein fest verbauter Li-Ionen Akku?! Mit Batteriefach wäre es ewig nutzbar. https://shop.reiner-sct.com/authenticator/reiner-sct-authenticator-mini

    spideymang, to random Spanish
    @spideymang@mstdn.mx avatar

    🚨🚨Authy, the two-factor authentication (2FA) service, says its desktop apps for macOS, Windows, and Linux will reach end-of-life on March 19, 2024

    A partir del 19 de marzo de 2024, Authy dejará de dar soporte para las aplicaciones de escritorio (Authy Desktop) para Windows, macOS y Linux, dejando únicamente disponibles las de IOS y Android.

    #2FA #Authy #Twilo

    majorlinux, to android
    @majorlinux@toot.majorshouse.com avatar

    Hopefully they won't alter the deal any further.

    Authy moved its desktop EOL to March - Desk Chair Analysts

    https://dcanalysts.net/authy-moved-its-desktop-eol-to-march/

    #Android
    #Apple
    #Authy
    #Google
    #iOS
    #MFA
    #PC
    #Twilio
    #Tech
    #Security
    #InfoSec
    #DCA

    nikunjkumarnakum,

    @majorlinux There are no hopes from proprietary apps if they alter the deal no worries. Try @ente authenticator app it has native desktop and mobile apps good thing is its completely free and opensource. https://github.com/ente-io/auth #authy #authyalternative #foss #2fa #twilio

    SirTapTap, to security
    @SirTapTap@mastodon.social avatar

    Please don't have your 2FA service text me a 6 digit code from a 6 digit phone number. You know exactly what's going to happen.

    #2FA #security

    root42, to random
    @root42@chaos.social avatar

    As #twilio is sunsetting their #authy desktop apps, I am wondering if there are any open source #2fa apps out there that support both desktop and mobile, maybe even Apple Watch...? Twilio still supports the mobile apps, but I don't want to get caught unprepared if they ever drop those, too.

    mima, to fediverse

    Why does / need an "authenticator app" registered before you can use a hardware key? That doesn't make sense wise.

    Yeah I know it's to prevent people from just accidentally getting locked out of their accounts, but there should be an option for to allow this risk. 🤔

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • Durango
  • Youngstown
  • everett
  • slotface
  • rosin
  • cubers
  • mdbf
  • ngwrru68w68
  • anitta
  • GTA5RPClips
  • cisconetworking
  • osvaldo12
  • ethstaker
  • Leos
  • khanakhh
  • normalnudes
  • tester
  • modclub
  • tacticalgear
  • megavids
  • provamag3
  • lostlight
  • All magazines