home.social

#authenicatorapps — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #authenicatorapps, aggregated by home.social.

  1. @emilion in infosec.exchange/@emilion/1165: you misunderstand me. My point is that Scott's article is yet another one in long row that reads like an advertisement.

    I am not insisting that FIDO or whatever organisation fixes things (regardless whether that is something they can do or not): I am asking for USEFUL information for users to evaluate advantages and their risks.

    A similar example: #TOTP was (and still is) being heavily promoted because people use (and reuse) extremely weak passwords. TOTP does *NOT* fix that problem (apart from the shit that we got, e.g. today's heise.de/en/news/Microsoft-Aut).

    Effectively people are told to use a password manager (the TOTP app) to fix ANOTHER problem, and nobody tells them to make backups of shared secrets (leading to account lockout).#Phishing is likely the biggest problem on the Internet, while TOTP does not fix that (and no, #Evilginx is no longer considered a "sophisticated" attack, from 2019: techcommunity.microsoft.com/bl).

    People who lose trust in security-pro's who state "just use this tech, it's great" are right. We need to do a better job.

    @ScottHelme

    #Passkeys #PasskeyRisks #Passwords #PasswordRisks #PasswordManager #AuthenicatorApps #MicrosoftAuthenticator

  2. @emilion in infosec.exchange/@emilion/1165: you misunderstand me. My point is that Scott's article is yet another one in long row that reads like an advertisement.

    I am not insisting that FIDO or whatever organisation fixes things (regardless whether that is something they can do or not): I am asking for USEFUL information for users to evaluate advantages and their risks.

    A similar example: #TOTP was (and still is) being heavily promoted because people use (and reuse) extremely weak passwords. TOTP does *NOT* fix that problem (apart from the shit that we got, e.g. today's heise.de/en/news/Microsoft-Aut).

    Effectively people are told to use a password manager (the TOTP app) to fix ANOTHER problem, and nobody tells them to make backups of shared secrets (leading to account lockout).#Phishing is likely the biggest problem on the Internet, while TOTP does not fix that (and no, #Evilginx is no longer considered a "sophisticated" attack, from 2019: techcommunity.microsoft.com/bl).

    People who lose trust in security-pro's who state "just use this tech, it's great" are right. We need to do a better job.

    @ScottHelme

    #Passkeys #PasskeyRisks #Passwords #PasswordRisks #PasswordManager #AuthenicatorApps #MicrosoftAuthenticator

  3. @emilion in infosec.exchange/@emilion/1165: you misunderstand me. My point is that Scott's article is yet another one in long row that reads like an advertisement.

    I am not insisting that FIDO or whatever organisation fixes things (regardless whether that is something they can do or not): I am asking for USEFUL information for users to evaluate advantages and their risks.

    A similar example: #TOTP was (and still is) being heavily promoted because people use (and reuse) extremely weak passwords. TOTP does *NOT* fix that problem (apart from the shit that we got, e.g. today's heise.de/en/news/Microsoft-Aut).

    Effectively people are told to use a password manager (the TOTP app) to fix ANOTHER problem, and nobody tells them to make backups of shared secrets (leading to account lockout).#Phishing is likely the biggest problem on the Internet, while TOTP does not fix that (and no, #Evilginx is no longer considered a "sophisticated" attack, from 2019: techcommunity.microsoft.com/bl).

    People who lose trust in security-pro's who state "just use this tech, it's great" are right. We need to do a better job.

    @ScottHelme

    #Passkeys #PasskeyRisks #Passwords #PasswordRisks #PasswordManager #AuthenicatorApps #MicrosoftAuthenticator

  4. @emilion in infosec.exchange/@emilion/1165: you misunderstand me. My point is that Scott's article is yet another one in long row that reads like an advertisement.

    I am not insisting that FIDO or whatever organisation fixes things (regardless whether that is something they can do or not): I am asking for USEFUL information for users to evaluate advantages and their risks.

    A similar example: #TOTP was (and still is) being heavily promoted because people use (and reuse) extremely weak passwords. TOTP does *NOT* fix that problem (apart from the shit that we got, e.g. today's heise.de/en/news/Microsoft-Aut).

    Effectively people are told to use a password manager (the TOTP app) to fix ANOTHER problem, and nobody tells them to make backups of shared secrets (leading to account lockout).#Phishing is likely the biggest problem on the Internet, while TOTP does not fix that (and no, #Evilginx is no longer considered a "sophisticated" attack, from 2019: techcommunity.microsoft.com/bl).

    People who lose trust in security-pro's who state "just use this tech, it's great" are right. We need to do a better job.

    @ScottHelme

    #Passkeys #PasskeyRisks #Passwords #PasswordRisks #PasswordManager #AuthenicatorApps #MicrosoftAuthenticator