Norobiik · @Norobiik
205 followers · 3249 posts · Server noc.social

"Now, it’s official: You have to pay for the privilege of using Twitter’s worst form of authentication. In fact, if you don’t start paying for ($8 a month on Android; $11 a month on iOS) or switch your account to use a far more reliable authenticator app or physical security key, Twitter will simply turn off your 2FA after March 20th."

Official: will now charge for authentication | | The Verge

theverge.com/2023/2/17/2360507

#birdsite #twitterchaos #2factor #sms #twitter #twitterblue

Last updated 1 year ago

@bryanmsmith use 2FA (yes I know everyone hates it) for everything you can, preferably with an authenticator app or a hardware token like YubiKey instead of saving all your passwords in a 3rd party database that WILL eventually be hacked. This goes double for the password manager in your browser.

#dontshootthemessenger #2factor #staysafeoutthere

Last updated 2 years ago

· @wpalmer
10 followers · 80 posts · Server fosstodon.org

does not have 1-factor login at all anymore? I just tried to log in to a low-security account that I only use for media, on a new device. I know the email address and password, but: no, I am not allowed to log in to my account using only username and password, unless I have access to an already-logged-in device.

Fair enough, I don't like -based logins anyway... But I don't like that apparently an existing account was switched over to an invisible scheme without notice.

#google #password #2factor

Last updated 2 years ago

Rainer Bareiß · @heavy02011
11 followers · 36 posts · Server mastodon.scot

’s SMS Two-Factor Authentication Is Melting Down wired.com/story/twitter-two-fa

#2factor #twitter

Last updated 2 years ago

Sand Fox · @sandfox
22 followers · 97 posts · Server qoto.org
Thomas B. Rücker · @tbr
412 followers · 4964 posts · Server society.oftrolls.com

Very intersting writeup about based on RFC 6238, as also used by Google Authenticator!
unix-ninja.com/p/attacking_goo
TL;DR: Don't use TOTP in its weak default configuration.
If you are forced to (e.g. by using Google Authenticator[!]) be aware of the risk.

#totp #infosec #2factor #authentication

Last updated 6 years ago

Gilgwath · @gilgwath
37 followers · 1059 posts · Server social.tchncs.de

Speaking of authentication: Remember to check back on the services you use and verify that a) you use a strong password b) what apps / services are connected and c) is 2factor auth activated.

#2factor

Last updated 7 years ago

Gilgwath · @gilgwath
37 followers · 1059 posts · Server social.tchncs.de

Why does every bloody service need their own app? I mean yes it is nice that they have two factor. But it would be much nicer to offer some standard way in addition. Something like or /U2F? Something I can backup independently from my phone?

#2factor #totp #fido #techyproblems

Last updated 7 years ago