home.social

#authenticator — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #authenticator, aggregated by home.social.

fetched live
  1. Tried to configure proper #2FA on my company's service provider site, as it's set to SMS as default. Found just one button to "configure authenticator app". It displays #QRcode without any code to manually copy.
    Not good, my preferred interface for #YubicoAuthenticator is cli, because I want to properly set touch and touch in it currently works weirdly in phone app.

    So my nerdy ass scanned that code using generic barcode scanner on phone, copied revealed URL containing secret, pasted it to Markor file which was later copied via #Syncthing to my work laptop :blobCat_giggle:

    I just cannot use things as intended...

    #yubikey #nerd #authenticator

  2. Tried to configure proper #2FA on my company's service provider site, as it's set to SMS as default. Found just one button to "configure authenticator app". It displays #QRcode without any code to manually copy.
    Not good, my preferred interface for #YubicoAuthenticator is cli, because I want to properly set touch and touch in it currently works weirdly in phone app.

    So my nerdy ass scanned that code using generic barcode scanner on phone, copied revealed URL containing secret, pasted it to Markor file which was later copied via #Syncthing to my work laptop :blobCat_giggle:

    I just cannot use things as intended...

    #yubikey #nerd #authenticator

  3. OpenSource Tipp 6: #psono von esaqa GmbH
    Ein vollumfänglicher #OpenSource PWM aus Deutschland.

    📱 für #Linux, iOS, Android (+ Mac & Windows), 💽 für #Firefox, Chrome, Edge.

    #Authenticator, #Passwörter (speichern, erstellen, bewerten, überprüfen), Notizen, Zertifikate.

    Vor allem für Unternehmen, Organisationen, Vereine eine Option dank Adminfunktion, Sharen von PW, Multiuser, etc. Der Quellcode ist offen und psono zum #selbsthosten vorgesehen, kann aber auch als #Cloud Variant genutzt werden

  4. Looking for some #security help for someone who's not on Mastodon, suggestions welcome.

    #Hotmail (#Outlook) account with #2FA activated, using the MS #Authenticator app. Getting unexpected authenticator notifications/challenges.

    Is there a way to stop these? It seems just entering the corresponding email address without a password already triggers authenticator. After searching I figure one cannot set it up so password has to be entered correctly first, before sending 2FA request. 1/2

  5. Looking for some #security help for someone who's not on Mastodon, suggestions welcome.

    #Hotmail (#Outlook) account with #2FA activated, using the MS #Authenticator app. Getting unexpected authenticator notifications/challenges.

    Is there a way to stop these? It seems just entering the corresponding email address without a password already triggers authenticator. After searching I figure one cannot set it up so password has to be entered correctly first, before sending 2FA request. 1/2

  6. #MicrosoftAuthenticator: Kritische #Sicherheitslücke ermöglicht Token-Diebstahl
    heise.de/news/Microsoft-Authen

    Ich habe das auch mal auf meinem Artikel "Wie man eine vertrauenswürdige Authentifizierungs-App auswählt" karl-voit.at/2023/03/05/TOTP-A dazugenommen.

    Wenn man von dem Vorfall Generelles ableiten möchte, bleiben eigentlich nur noch Hardware-Tokens für #FIDO2 übrig, wenn man #Phishing ausschließen möchte.

    Sogar #Passkeys helfen leider nicht (mehr): karl-voit.at/FIDO2-vs-Passkeys/

    #Authenticator #TOTP #FIDO2 #publicvoit #20230304_TOTPAuswahl #MFA #2FA #20241005_FIDO2VsPasskeys #Authentifizierung #Sicherheit

  7. #MicrosoftAuthenticator: Kritische #Sicherheitslücke ermöglicht Token-Diebstahl
    heise.de/news/Microsoft-Authen

    Ich habe das auch mal auf meinem Artikel "Wie man eine vertrauenswürdige Authentifizierungs-App auswählt" karl-voit.at/2023/03/05/TOTP-A dazugenommen.

    Wenn man von dem Vorfall Generelles ableiten möchte, bleiben eigentlich nur noch Hardware-Tokens für #FIDO2 übrig, wenn man #Phishing ausschließen möchte.

    Sogar #Passkeys helfen leider nicht (mehr): karl-voit.at/FIDO2-vs-Passkeys/

    #Authenticator #TOTP #FIDO2 #publicvoit #20230304_TOTPAuswahl #MFA #2FA #20241005_FIDO2VsPasskeys #Authentifizierung #Sicherheit

  8. Just had to "hack" two (2) #MS365 tenants, due to #Authenticator being completely goosed on my mobile phone, it had never worked 100% after MS forced its use last year (my other colleague with admin access was on holiday and away from UK ) - luckily the way #Microsoft had it previously running was half-arsed enough that I was able to still access user admin page (but not Entra, and security info) which allowed me to escalate an existing user to Global Admin and then use that to reset my own accounts #MFA and then add those back to Authenticator...

  9. Just had to "hack" two (2) #MS365 tenants, due to #Authenticator being completely goosed on my mobile phone, it had never worked 100% after MS forced its use last year (my other colleague with admin access was on holiday and away from UK ) - luckily the way #Microsoft had it previously running was half-arsed enough that I was able to still access user admin page (but not Entra, and security info) which allowed me to escalate an existing user to Global Admin and then use that to reset my own accounts #MFA and then add those back to Authenticator...

  10. What feels like a thousand times Microsoft #Authenticator this year alone. 🤬🤬🤬

    Why don't you just die, #Microsoft? You software is buggy, your services suck, you have no taste or respect for privacy and you just stink! #rant

  11. What feels like a thousand times Microsoft #Authenticator this year alone. 🤬🤬🤬

    Why don't you just die, #Microsoft? You software is buggy, your services suck, you have no taste or respect for privacy and you just stink! #rant

  12. So Google has locked people into their Google Authenticator mobile apps. You no longer have the option to transfer accounts (saving as JSON or text). You can export and import to another Google Authenticator via QRCodes, but not to another application. After some interweb searches, there are some CLI tools to read, decode and present in text the secret code to import, one by one, the QRCodes that Google Authenticator generates for exports. That’s very inconvenient when you have plenty of accounts. Is there any other way than the manual way? #Bitwarden Authenticator could support these locked down QRCodes? Maybe time for a PR to add support to import from Google Authenticator…

    #authenticator #codes #export #import #apps #linux

  13. So Google has locked people into their Google Authenticator mobile apps. You no longer have the option to transfer accounts (saving as JSON or text). You can export and import to another Google Authenticator via QRCodes, but not to another application. After some interweb searches, there are some CLI tools to read, decode and present in text the secret code to import, one by one, the QRCodes that Google Authenticator generates for exports. That’s very inconvenient when you have plenty of accounts. Is there any other way than the manual way? Authenticator could support these locked down QRCodes? Maybe time for a PR to add support to import from Google Authenticator…

  14. Eigentlich wollte ich vom Google Authenticator zu Authy wechseln. Dann hab ich gelernt, dass das gar nicht mal so gut sein soll. Ich hab dann jetzt stattdessen den Authenticator von @ente gewählt.
    #did #dut #2fa #authenticator

  15. Eigentlich wollte ich vom Google Authenticator zu Authy wechseln. Dann hab ich gelernt, dass das gar nicht mal so gut sein soll. Ich hab dann jetzt stattdessen den Authenticator von @ente gewählt.
    #did #dut #2fa #authenticator

  16. »Microsoft respektiert Ihre Privatsphäre«. So jedenfalls tönt der Consent-Banner unmittelbar nach dem Start der Microsoft Authenticator-App (Version: 6.2601.0189). Gleichzeitig werden im Hintergrund Telemetrie-Daten an »eu-mobile.events.data.microsoft.com« übermittelt. Microsoft versteht Datenschutz halt schon immer etwas anders. 😜

    #microsoft #authenticator #datenschutz #dsgvo #privacy

  17. »Microsoft respektiert Ihre Privatsphäre«. So jedenfalls tönt der Consent-Banner unmittelbar nach dem Start der Microsoft Authenticator-App (Version: 6.2601.0189). Gleichzeitig werden im Hintergrund Telemetrie-Daten an »eu-mobile.events.data.microsoft.com« übermittelt. Microsoft versteht Datenschutz halt schon immer etwas anders. 😜

    #microsoft #authenticator #datenschutz #dsgvo #privacy

  18. What I want from Microsoft Azure Authenticator:

    • To pop up the input keyboard consistently every time so I'm not locked out from being able to authenticate

    What I get:

    • To scan my thumprint after I scan my thumprint

    #azure #authenticator #JustGiveUpAndUseRfc6238

  19. What I want from Microsoft Azure Authenticator:

    • To pop up the input keyboard consistently every time so I'm not locked out from being able to authenticate

    What I get:

    • To scan my thumprint after I scan my thumprint

    #azure #authenticator #JustGiveUpAndUseRfc6238

  20. @admin Danke für den Hinweis, die App #enteauth macht wirklich einen guten Eindruck! Die sind sogar hier im #fediverse unter @ente vertreten.
    Also, nutzt alle den kommenden #diday um euch eine neue #authenticator App zu holen!

  21. TIL that AuthenticatorPro has moved to github.com/stratumauth/app and is no longer on F-Droid.

    I anyone uses original build, please migrate.

    #otp #fdroid #authenticatorpro #authenticator

  22. TIL that AuthenticatorPro has moved to github.com/stratumauth/app and is no longer on F-Droid.

    I anyone uses original build, please migrate.

    #otp #fdroid #authenticatorpro #authenticator

  23. Biometric Yubico (Yubikey Bio) keys! let's go. An upgrade from our Yubikey 5. And some slight changes on how we authenticate for stuff everywhere.

    Project underway! #cybersecurity #fido #2fa #authenticator #IT #sysadmin

  24. Biometric Yubico (Yubikey Bio) keys! let's go. An upgrade from our Yubikey 5. And some slight changes on how we authenticate for stuff everywhere.

    Project underway! #cybersecurity #fido #2fa #authenticator #IT #sysadmin

  25. @Framasoft

    Alors un truc que j’aime avec @protonprivacy #authenticator, c’est que tu peux installer 2 instances, une sur ton ordi et une autre sur ton téléphone et les synchroniser : si tu rencontres un problème (casse, perte, incendie), tu peux toujours continuer à te connecter à tes comptes protégés en 2FA.

    (et par ailleurs, on peut récupérer très facilement avec Proton tous les comptes authentifiés par Glougle et donc se passer d’eux)

  26. @Framasoft

    Alors un truc que j’aime avec @protonprivacy #authenticator, c’est que tu peux installer 2 instances, une sur ton ordi et une autre sur ton téléphone et les synchroniser : si tu rencontres un problème (casse, perte, incendie), tu peux toujours continuer à te connecter à tes comptes protégés en 2FA.

    (et par ailleurs, on peut récupérer très facilement avec Proton tous les comptes authentifiés par Glougle et donc se passer d’eux)

  27. While I love the idea of #passkeys I continue to find the ecosystem of them too siloed. #sms #2fa continues to grow among the stupid, like governments and banks. Meanwhile, my Android #totp #Authenticator app has more entries than I can easily count. Finding the right now... difficult. Will it even sort alphabetically? Or by MRU? Or??? I wonder what alternative apps exist.

  28. While I love the idea of #passkeys I continue to find the ecosystem of them too siloed. #sms #2fa continues to grow among the stupid, like governments and banks. Meanwhile, my Android #totp #Authenticator app has more entries than I can easily count. Finding the right now... difficult. Will it even sort alphabetically? Or by MRU? Or??? I wonder what alternative apps exist.

  29. Deze zondag iets goeds doen voor je #privacy en tegen #bigtech? Stap over naar Proton. Met deze link krijg je twee weken gratis bij een abonnement. Stap over op #mail, #agenda, #vpn, #authenticator en andere tools!

    pr.tn/ref/3YCH4QBC

  30. Damn, #Yubikey migration almost complete...

    It's like most people dependent on smartphones for #2FA logins everywhere, but much worse. Smartphone usually has one #authenticator app, everything visible in one place, Yubikeys have various modules inside and I use most of it for many different things.
    Authenticator part here is the easiest one, at least I have nice list of accounts/services to display with one simple command. But I have to remember U2F enabled services myself... Or check how many files I encrypted with GPG, or where I could use ssh keys...
    Oh, and I use also pam-u2f and have FIDO LUKS login configured...
    :blobCat_anxious_sweat:

    Seriously, user could become even more dependent in more complex ways...

    Why the hell these things don't just support firmware updates?!

  31. May I make you aware of #FreeOTP, a #FOSS #authenticator #app by #RedHat. It is completely free of charge (no ads, no spying), completely open source, available on pretty much every #mobile OS, and it takes up only 1 MB of the storage in your #smartphone! That is 20 times less than Google's authenticator! I have been using it for many years and never had a single problem with it. If you are not already using another authenticator app, I can totally recommend this little pearl.

    freeotp.github.io/

  32. just a chill reminder to check out Ente Auth - 2FA Authenticator.. 🙂 @ente

    link below:
    ente.io/auth/

    #2FA #Authenticator #EnteAuth #Secure #Privacy #OpenSource

  33. En #authenticator, pour remplacer Gloogleuh, vous conseillez quoi ?

    J'ai vu que celui de Proton importe directos les codes déjà installés, mais j'écoute toutes les suggestions.

  34. Gibt es eigentlich etwas bekloppteres als den #Microsoft #Authenticator? Dieses "wir wollten es nicht so wie die anderen machen, können es aber auch nur schlechter"?

    In der App eine Zahl anzeigen lassen und dann einen Browser drüberlegen, in dem man diese Zahl eingeben soll. Ihr spinnt doch. #Drecksverein #Arschlochfirma