Kevin Karhan :verified: · @kkarhan
1478 followers · 106924 posts · Server mstdn.social

#sms #itan

Last updated 1 year ago

Kevin Karhan :verified: · @kkarhan
1464 followers · 105748 posts · Server mstdn.social

@thatguyoverthere @BrodieOnLinux

Just use a pencil or pen to tick out those you used.

Sarcasm aside, they also allow and encourage me to store my recovery codes seperately, thus they can also allow me to do the same with to , and with they mitigate or at least vastly reduce the success rate of shouldersurfers gaining valid TANs...

#itan #2fa #tans #problemsolved

Last updated 1 year ago

Kevin Karhan :verified: · @kkarhan
1464 followers · 105748 posts · Server mstdn.social

@thatguyoverthere @BrodieOnLinux Let's just say that if wants to mandate they need to make it even more accessible than is.

If I can't fit it on an boot floppy and keep it fully airgapped on paper without knowing time and date, it's shit.

If banks accept to do million-euro transactions than Github can so too...
mstdn.social/@kkarhan/11096567

#itan #os1337 #Git #2fa #GitHub

Last updated 1 year ago

Kevin Karhan :verified: · @kkarhan
1464 followers · 105748 posts · Server mstdn.social

@thatguyoverthere @BrodieOnLinux

Also yes, all implementations will cross out all used TANs and the last 2-5 are used to auth a new iTAN sheet...

And the best part of it: those can be perfectly seperated and don't need anything but paper and ink to put them on.

Personally, I do want my shit to be so secure that I can't backdoor it at gunpoint without the ability to commit asset denial towards the attacker...

Call me weird, but I'd be dead for over a decade if I wasn't that cautious...

#itan

Last updated 1 year ago

Kevin Karhan :verified: · @kkarhan
1464 followers · 105748 posts · Server mstdn.social

@10volt @thatguyoverthere @BrodieOnLinux

are numerized, pre-generated TANs that get requested for randomized 2FA...
en.wikipedia.org/wiki/Transact

And no, / & - are NOT practical for numerous reasons I CANNOT disclose...
mstdn.social/@kkarhan/11097593

#tan #sms #hotp #totp #itan

Last updated 1 year ago

Kevin Karhan :verified: · @kkarhan
1461 followers · 105572 posts · Server mstdn.social

@thatguyoverthere @BrodieOnLinux I've yet to see any vulns re: |s...

They worked fine two decades ago and they work fine to this day...

If they don't like 8-digit numerals they could just go with the wholse like I did here...
github.com/kkarhan/misc-script

#base64 #itan

Last updated 1 year ago

Kevin Karhan :verified: · @kkarhan
1461 followers · 105572 posts · Server mstdn.social

@BrodieOnLinux it means that if doesn't support any good - capable like , a lot of folks won't use it at all!

Espechally since they don't support EVERY NATION AND NETWORK nor can one expect to have a dedicaded and secure phone number for that!

#itan #2fa #offline #GitHub

Last updated 1 year ago

Kevin Karhan :verified: · @kkarhan
1355 followers · 94588 posts · Server mstdn.social
Itan · @SolamenteItan
219 followers · 3903 posts · Server masto.es
Kevin Karhan :verified: · @kkarhan
945 followers · 53964 posts · Server mstdn.social

@dalias @alexandria

and:
- you're forced to flee someplace and everyone around you will try to KOS you if they identify you.

Again: or rather is the next best option.
mstdn.social/@kkarhan/11027108

#itan #tan

Last updated 1 year ago

Kevin Karhan :verified: · @kkarhan
945 followers · 53964 posts · Server mstdn.social

@alexandria that basically only allows as method, since those can be printed out or stored otherwise.
en.wikipedia.org/wiki/Transact

If necessary, the system would generate a new iTAN each time after successful login and demanding it for the next login, and so forth.

#itan

Last updated 1 year ago

MLS Takes · @mlstakes
277 followers · 147 posts · Server mstdn.party

@dkiesow I think they can win but need to be decisive in front of goal. will also be playing for everything.

#itan

Last updated 2 years ago

Markus Malecki · @mmalecki
9 followers · 437 posts · Server mastodon.social

photos

#itan #thai #truck

Last updated 3 years ago

Markus Malecki · @mmalecki
9 followers · 437 posts · Server mastodon.social

photos

#itan #thai #truck

Last updated 3 years ago

Senioradmin · @Haydar
568 followers · 6012 posts · Server social.tchncs.de

Drei Monate vor dem Ende immer noch kein Wort von meiner Bank dazu, dass abgeschafft wird. Alternativen werden nicht beworben. Irgendwo auf den Webseiten versteckt gibt es einen Antrag zum ausdrucken zum mTAN Verfahren, welches heute aber auch nicht mehr als sicher gilt. Andere Alternativen gibt es nicht.

#itan

Last updated 5 years ago