root42, to random
@root42@chaos.social avatar

As #twilio is sunsetting their #authy desktop apps, I am wondering if there are any open source #2fa apps out there that support both desktop and mobile, maybe even Apple Watch...? Twilio still supports the mobile apps, but I don't want to get caught unprepared if they ever drop those, too.

mima, to fediverse

Why does / need an "authenticator app" registered before you can use a hardware key? That doesn't make sense wise.

Yeah I know it's to prevent people from just accidentally getting locked out of their accounts, but there should be an option for to allow this risk. 🤔

lawmurray, to random

Twilio Authy for desktop reaches end of life in March. Now's a good time to check out open source alternatives that won't. For your 2FA needs:

  1. On Gnome, Authenticator: https://apps.gnome.org/Authenticator/
  2. On KDE, Keysmith: https://apps.kde.org/keysmith/
  3. On Android, Aegis: https://getaegis.app/
  4. On Android or iOS, 2FAS: https://2fas.com/

There are more. These won't synchronize between devices automatically, but they all support standard file formats for manual export and import.

flup, to infosec
@flup@mastodon.scot avatar

Desktop is going away in March, not August as previously advertised. We have a migration plan but it’s nowhere near ready. Ouch.

maxleibman, to infosec
@maxleibman@mastodon.social avatar

They call the app Duo because it takes twice as long to do your job.

#Duo #infosec #2FA #2FAFatigue

lemonldapng, to overwatch French
Tutanota, to random
@Tutanota@mastodon.social avatar

What a surprise: @bitwarden explains setting up 2fa with Tuta Mail (slide 39)! 😍

👉 https://bitwarden.com/resources/presentations/the-triangle-of-security-success/

And rightly so: Because #encrypted email get even more secure with #2FA and #passwordmanagers 💪

_ohcoco_, to internet_funeral
@_ohcoco_@mastodon.social avatar

#PSA

How to avoid the '#SIM swapping' scams that are on the rise >>>

This #scam works because it bypasses #text #2FA 😬

https://youtube.com/watch?v=doEojozzDNk&si=93IRxnSUNWMtlj63

kubikpixel, to web
@kubikpixel@chaos.social avatar

Such reports have become more frequent recently. Of course, #web #security is not just simple, but as a provider you should, in my opinion, test it officially to maintain #trust – is #spoutible professional?

«Twitter alternative spouts a massive #leak: Spoutible’s #API coughed up #password's, #2FA info, and tokens that could let attackers take over anyone’s #account

🔓 https://www.theverge.com/2024/2/5/24061997/twitter-alternative-spoutible-vulnerabilty

mattotcha, to privacy
@mattotcha@mastodon.social avatar
jsrailton, to SEC
@jsrailton@mastodon.social avatar

deleted_by_author

  • Loading...
  • publicvoit,
    @publicvoit@graz.social avatar

    @jsrailton Only FIDO2 and Passkeys are protecting against #phishing attacks.

    Caution: #Passkeys might copy your secret into the service provider's cloud for convenience and backup purposes.

    IMHO, #FIDO2 hardware tokens are the only non plus ultra for authentication security since they protect your secrets in hardware without the possibility of "backups" to the cloud.

    #TOTP #2FA #U2F

    0x58, to Cybersecurity
    Codeberg, to random
    @Codeberg@social.anoxinon.de avatar

    Friendly Reminder to #2FA users: Imagine your primary machine fails today. How will you restore your access to your online accounts?

    Please ensure you saved your scratch token somewhere and have working backups of your TOTP app or a backup hardware key.

    Thank you!
    #Backup

    protonmail, to random
    @protonmail@mastodon.social avatar

    Proton for Business got major new features in 2023 – and there’s more on the way.

    📤 SMTP submission
    📨 Automatic email forwarding
    💻 New desktop apps
    🔒 Advanced account protection
    🧑‍💻 Admin controls
    🌐 VPN for business
    🔑 Password Manager

    Read the thread for more details. ⬇️

    protonmail,
    @protonmail@mastodon.social avatar

    We introduced new #admin controls to enforce #2FA and made filter lists available, allowing you to create your own #spam, block, and allow lists for incoming emails.

    🧵7/10

    snafu, to security

    So, in case anyone still thinks that patching and security in general is not so important nowadays: Found already several tries of exploiting the recent critical CVE-2023-7028 vulnerability in the logs of my GitLab instance although it was only published a few days ago.

    Conclusion:
    ✅ Install security updates literally ASAP.
    ✅ Turn on mandatory 2FA for all users.

    slink, to passkeys
    @slink@fosstodon.org avatar

    TIL: browsers now have usb access, for #fido2 #2fa #passkeys and what not.
    sounds like the only question is WHEN this will turn out to be a vector for novel attacks. #infosec

    gcluley, to cryptocurrency
    @gcluley@mastodon.green avatar

    Security firm Mandiant says it didn’t have 2FA enabled on its hacked Twitter account.

    I have questions...

    https://grahamcluley.com/security-firm-mandiant-says-it-didnt-have-2fa-enabled-on-its-hacked-twitter-account/

    cybersecurity #2fa #mandiant #cryptocurrency #twitter

    0x58, to infosec

    So, who's lying and who's doing a PR stunt? :birdsite:​

    If the SEC had failed to enable two-factor authentication — as the statement from X claimed — the agency would be in violation of federal government guidance. A December 2021 advisory from the Cybersecurity and Infrastructure Security Agency urges federal agencies to enforce multi-factor authentication for their social media accounts, among other actions.

    #infosec #cybersecurity #CISA

    https://cyberscoop.com/after-hack-x-claims-sec-failed-to-use-two-factor-authentication/

    0x58,

    It seems #2FA is lacking some deserved love... 💗 The "Mandiant case" 👇

    "Normally, [two-factor authentication] would have mitigated this, but due to some team transitions and a change in X's 2FA policy, we were not adequately protected," the threat intelligence firm said in a post shared on X.

    #infosec #cybersecurity

    https://thehackernews.com/2024/01/mandiants-x-account-was-hacked-using.html

    wuchyi, to fediverse

    I've (perhaps naively) been adding my TOTP #2FA secrets into my #1Password vault for the sake of convenience, but am now looking to switch them out to a separate 2FA app/manager so it's actually 2FA. Can anyone on the #fediverse recommend me one?

    Ideally, I'd love to have these features:

    • Password protected
    • cross-platform apps with sync
    • browser add-ons with auto-fill

    Many thanks in advance!

    #infosec #security #technology

    83r71n, to Cybersecurity

    Mandiant's X account was compromised through a brute-force password attack by a drainer-as-a-service (DaaS)* group. The account lacked two-factor authentication (2FA), which could have mitigated the attack.

    *(DaaS): A Drainer-as-a-Service is a type of cyber attack where hackers sell access to their botnets, which are networks of computers controlled remotely.

    https://thehackernews.com/2024/01/mandiants-x-account-was-hacked-using.html

    gpshead, to SEC

    The U.S. SEC's twitter account “did not have two-factor authentication enabled”. In 2024. For reals.

    SwiftOnSecurity, (edited ) to random

    PUBLIC SERVICE ANNOUNCEMENT:

    There is an increase of account takeovers due to insiders at telco firms simply giving control to people paying them/compromised support staff accounts. Do a check on systems where this single factor would permit an account compromise. And change the configuration. These are opportunistic trawling attacks. This is becoming more common as attackers replicate the success.

    The attacker uses other channels (like people search websites) to enumerate and guess the phone number attached to an online account and then checks against the telco they have control over.

    The insider only briefly temporarily forwards the victim number to a 3rd party then switches it back to normal once they’re in. This is how they stay quiet since most victims will not have leverage or telemetry to understand how they got hacked.

    It was their cell phone provider.

    Make it so account recovery systems require multiple factors and remove telephony-based recovery for VIP accounts entirely.
    Go check your systems now. Go try to access all your stuff like you forgot your password.

    I am very serious. This is based on private knowledge but is compelled by the compromise of the SEC. This is common now.

    mjgardner,
    @mjgardner@social.sdf.org avatar

    @SwiftOnSecurity This sounds like the nightmare scenario for phone-based #2FA and account recovery that we’ve been warning people about for years

    mjgardner,
    @mjgardner@social.sdf.org avatar

    @Shaunkoh @SwiftOnSecurity #Security is a spectrum. Phone number #2FA was never as secure as app-based. But now the former has moved even further toward the “insecure" end of the spectrum.

    majorlinux, to apple
    @majorlinux@toot.majorshouse.com avatar

    I wonder how hard this will hit 2FA usage going forward.

    Authy to sunset desktop apps - Desk Chair Analysts

    https://dcanalysts.net/authy-to-sunset-desktop-apps/

    #2FA #Apple #Authy #Desktop #InfoSec #Microsoft #mobile #PC #Linux #Security #TechNews #DCA

    j_opdenakker, to infosec

    If you know someone who's still using authy for desktop, it's time to give them a heads up to switch to the mobile app: https://www.bleepingcomputer.com/news/security/twilio-will-ditch-its-authy-desktop-2fa-app-in-august-goes-mobile-only/

    #infosec

    simonzerafa,

    @grumpybozo

    I'm currently looking at 2FAS Auth as a replacement for Authy. It's open source so that a good start 🙂

    https://2fas.com/

    # 2SA

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • GTA5RPClips
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • provamag3
  • Leos
  • cisconetworking
  • lostlight
  • All magazines