toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

234
active users

#authenticatorapp

0 posts0 participants0 posts today
adingbatponder<p>One of the most important functions on my computer is the GNOME <a href="https://fosstodon.org/tags/Authenticator" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authenticator</span></a> app. Without it I cannot even access many of the services I use daily. I need to reinstall my <a href="https://fosstodon.org/tags/NixOS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NixOS</span></a> machine to move to <a href="https://fosstodon.org/tags/flakes" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>flakes</span></a> and clean up some messy command-line installs. Is there a way to restore the authenticator app after reinstall so it works for all services, without having to revisit each site and re-enroll the <a href="https://fosstodon.org/tags/2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2FA</span></a> manually? Can this be achieved via a flake that manages <a href="https://fosstodon.org/tags/secrets" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>secrets</span></a>? <a href="https://fosstodon.org/tags/authenticatorapp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authenticatorapp</span></a></p>
Radgryd<p>Thanks everyone for all the recommendations! The reason I wanted to stop using Authy was because they were breached last year and they're also closed-source.</p><p>If someone is thinking of moving away from Authy the following seem to be the most-liked on Fedi, going by the replies: Ente, Aegis, FreeOTP+ and 2FAS. All of them are free and open source.</p><p>I chose Ente because it also works cross-platform. <a href="https://mstdn.games/tags/Authy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authy</span></a> <a href="https://mstdn.games/tags/AuthenticatorApp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AuthenticatorApp</span></a></p>
Radgryd<p>I want to move away from Authy. Dear Fedi, safest authenticator app? Go. <a href="https://mstdn.games/tags/AskFedi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AskFedi</span></a> <a href="https://mstdn.games/tags/Authy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authy</span></a> <a href="https://mstdn.games/tags/AuthenticatorApp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AuthenticatorApp</span></a></p>
Erik van Straten<p>"The world is under siege. This is not news. State-sponsored cybercriminals and a growing army of newbies using powerful tools from the dark web are exploiting every weak link in our cybersecurity chains, which is first and foremost our users."</p><p>Aldus John Gunn in <a href="https://www.bleepingcomputer.com/news/security/mfa-failures-the-worst-is-yet-to-come/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/mfa-failures-the-worst-is-yet-to-come/</span></a>.</p><p>John Gunn heeft gelijk. Het internet is veel te onveilig en niemand die daar iets tegen doet.</p><p>Terwijl websites steeds anoniemer worden, moet *U* steeds betrouwbaarder authenticeren (<a href="https://www.security.nl/posting/872694/VK+verplicht+vanaf+juli+%27robuuste%27+online+leeftijdsverificatie+voor+pornosites" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">security.nl/posting/872694/VK+</span><span class="invisible">verplicht+vanaf+juli+%27robuuste%27+online+leeftijdsverificatie+voor+pornosites</span></a>). Aanvankelijk gebruikmakend van hersenloze technieken, zoals het opsturen van een scan van uw paspoort. Alsof degene die zo'n kopie in handen krijgt (op legale of illegale wijze) niet *OOK* kan bewijzen dat zij of hij u is. </p><p>Echter:</p><p>BINNENKORT HOEFT ZO'N SCAN NIET MEER!</p><p>Dan krijgt "iedereen" namelijk "geheel vrijwillig" een elektronisch paspoort op haar of zijn telefoon. Wat zou *DAAR* nou mis mee kunnen gaan?</p><p>Ik waarschuw er al heel lang voor dat het internet veel te onveilig wordt. Maar dat is tegen dovemansoren, of zo'n artikel wordt simpelweg weggecensureerd. Zélfs als je zo'n artikel met verifieerbare feiten onderbouwt - middels links naar pagina's van VirusTotal (een dochterbedrijf van Google).</p><p>(Mijn artikel valt overigens nog hier te lezen - voor zolang als dát duurt (Big Tech duldt geen kritiek): <a href="https://archive.is/3UwWn" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">archive.is/3UwWn</span><span class="invisible"></span></a> - zie ook <a href="https://infosec.exchange/@ErikvanStraten/113837934294209517" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113837934294209517</span></a>). </p><p>John Gunn gaat verder met:</p><p>"Multi-Factor Authentication (MFA), once celebrated as an unbreakable defense, is crumbling under the weight of its outdated technology. Phishing attacks, ransomware, and sophisticated exploits are bypassing legacy MFA with astonishing ease."</p><p>Ook daar waarschuw ik al jááren voor.</p><p>Fix: <a href="https://www.security.nl/posting/840236/Veilig+inloggen" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">security.nl/posting/840236/Vei</span><span class="invisible">lig+inloggen</span></a> (eigenlijk ben ik gek dat ik nog naar die site verwijs, waar ik al vele jaren -voor nop- aan bijdraag; stank voor dank).</p><p>Daarin ook "plaatjes" waarin te zien is waarom 2FA/MFA middels SMS of "Authenticator" app geen zier helpt tegen AitM (Attacker in the Middle of MitM: <a href="https://en.wikipedia.org/wiki/Man-in-the-middle_attack" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">en.wikipedia.org/wiki/Man-in-t</span><span class="invisible">he-middle_attack</span></a>) aanvallen; u bent kansloos als u alle informatie op een nepwebsite invoert.</p><p>Hetzelfde risico loopt u straks met uw EDIW - nog een veilige dag gewenst.</p><p><a href="https://infosec.exchange/tags/Calimero" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Calimero</span></a> <a href="https://infosec.exchange/tags/Censuur" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Censuur</span></a> <a href="https://infosec.exchange/tags/GoogleIsEvil" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GoogleIsEvil</span></a> <a href="https://infosec.exchange/tags/UBentHetProduct" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>UBentHetProduct</span></a> <a href="https://infosec.exchange/tags/BigTech" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BigTech</span></a> <a href="https://infosec.exchange/tags/AitM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AitM</span></a> <a href="https://infosec.exchange/tags/MitM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MitM</span></a> <a href="https://infosec.exchange/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://infosec.exchange/tags/2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2FA</span></a> <a href="https://infosec.exchange/tags/TOTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TOTP</span></a> <a href="https://infosec.exchange/tags/AuthenticatorApp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AuthenticatorApp</span></a> <a href="https://infosec.exchange/tags/eID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eID</span></a> <a href="https://infosec.exchange/tags/EDIW" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EDIW</span></a> <a href="https://infosec.exchange/tags/EUDIW" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EUDIW</span></a> <a href="https://infosec.exchange/tags/LeeftijdsVerificatie" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LeeftijdsVerificatie</span></a> <a href="https://infosec.exchange/tags/Authenticatie" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authenticatie</span></a> <a href="https://infosec.exchange/tags/Impersonatie" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Impersonatie</span></a> <a href="https://infosec.exchange/tags/IdentiteitsFraude" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IdentiteitsFraude</span></a></p>
ITSEC News<p>Beware rogue 2FA apps in App Store and Google Play – don’t get hacked! - Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are eith... <a href="https://nakedsecurity.sophos.com/2023/02/27/beware-rogue-2fa-apps-in-app-store-and-google-play-dont-get-hacked/" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">nakedsecurity.sophos.com/2023/</span><span class="invisible">02/27/beware-rogue-2fa-apps-in-app-store-and-google-play-dont-get-hacked/</span></a> #2-factorauthentication <a href="https://schleuss.online/tags/authenticatorapp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authenticatorapp</span></a> <a href="https://schleuss.online/tags/authenticator" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authenticator</span></a> <a href="https://schleuss.online/tags/cryptography" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cryptography</span></a> <a href="https://schleuss.online/tags/tommymysk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tommymysk</span></a> <a href="https://schleuss.online/tags/dataloss" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dataloss</span></a> <a href="https://schleuss.online/tags/malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware</span></a> <a href="https://schleuss.online/tags/mysk_co" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mysk_co</span></a> <a href="https://schleuss.online/tags/totp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>totp</span></a> <a href="https://schleuss.online/tags/2fa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2fa</span></a></p>