home.social

#secureauthentication β€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #secureauthentication, aggregated by home.social.

  1. @pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

    1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
    *AND*
    2️⃣ TLS channel binding (enforcing known endpoints).

    (Apart from those, both serving endpoint AND client MUST be trustworthy).

    🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
    a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
    b) Continuously decreasing certificate lifetime.

    🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

    * Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

    😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

    😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

    @cendyne @soatok @chazh

    #AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

  2. @pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

    1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
    *AND*
    2️⃣ TLS channel binding (enforcing known endpoints).

    (Apart from those, both serving endpoint AND client MUST be trustworthy).

    🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
    a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
    b) Continuously decreasing certificate lifetime.

    🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

    * Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

    😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

    😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

    @cendyne @soatok @chazh

    #AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

  3. @pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

    1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
    *AND*
    2️⃣ TLS channel binding (enforcing known endpoints).

    (Apart from those, both serving endpoint AND client MUST be trustworthy).

    🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
    a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
    b) Continuously decreasing certificate lifetime.

    🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

    * Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

    😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

    😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

    @cendyne @soatok @chazh

    #AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

  4. @pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

    1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
    *AND*
    2️⃣ TLS channel binding (enforcing known endpoints).

    (Apart from those, both serving endpoint AND client MUST be trustworthy).

    🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
    a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
    b) Continuously decreasing certificate lifetime.

    🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

    * Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

    😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

    😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

    @cendyne @soatok @chazh

    #AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

  5. πŸ” Modern Password Security Threats: Protecting Your Digital Identity πŸ•΅οΈβ€β™€οΈ πŸ›‘οΈ 🚨

    Cybercriminals use sneaky techniques to crack passwords and gain access to accounts. Here are the most common attacks:

    βš’οΈ Brute Force – Tries every possible password
    πŸ“– Dictionary Attack – Uses common words & phrases
    🌈 Rainbow Table – Cracks password hashes
    πŸ‘€ Shoulder Surfing – Spies on you while typing
    ⌨️ Keylogging – Records everything you type
    🎯 Password Spraying – Tests common passwords on many accounts
    🎭 Social Engineering – Tricks you into revealing passwords
    🎣 Phishing – Fake emails & websites steal your login
    🎟️ Credential Stuffing – Uses leaked passwords from breaches
    πŸ•΅οΈ Man-in-the-Middle – Intercepts data over networks

    πŸ›‘οΈ Stay Safe! Use strong, unique passwords, enable 2FA, and beware of phishing scams.

    Which attack surprised you the most? Let’s discuss in the comments! ⬇️

    ⚠️ This content is shared strictly for educational and informational purposes only. πŸ“š All information is provided to help individuals and organizations better protect themselves against security threats. πŸ”’ The techniques discussed are presented solely to improve awareness and defensive measures, not to facilitate any unauthorized access. βœ…

    #PasswordSecurity #CyberSecurity #DataProtection #SecureAuthentication #IdentityProtection #InfoSec #PhishingAwareness #CyberDefense #MFA #DigitalSafety

  6. πŸ” Modern Password Security Threats: Protecting Your Digital Identity πŸ•΅οΈβ€β™€οΈ πŸ›‘οΈ 🚨

    Cybercriminals use sneaky techniques to crack passwords and gain access to accounts. Here are the most common attacks:

    βš’οΈ Brute Force – Tries every possible password
    πŸ“– Dictionary Attack – Uses common words & phrases
    🌈 Rainbow Table – Cracks password hashes
    πŸ‘€ Shoulder Surfing – Spies on you while typing
    ⌨️ Keylogging – Records everything you type
    🎯 Password Spraying – Tests common passwords on many accounts
    🎭 Social Engineering – Tricks you into revealing passwords
    🎣 Phishing – Fake emails & websites steal your login
    🎟️ Credential Stuffing – Uses leaked passwords from breaches
    πŸ•΅οΈ Man-in-the-Middle – Intercepts data over networks

    πŸ›‘οΈ Stay Safe! Use strong, unique passwords, enable 2FA, and beware of phishing scams.

    Which attack surprised you the most? Let’s discuss in the comments! ⬇️

    ⚠️ This content is shared strictly for educational and informational purposes only. πŸ“š All information is provided to help individuals and organizations better protect themselves against security threats. πŸ”’ The techniques discussed are presented solely to improve awareness and defensive measures, not to facilitate any unauthorized access. βœ…

    #PasswordSecurity #CyberSecurity #DataProtection #SecureAuthentication #IdentityProtection #InfoSec #PhishingAwareness #CyberDefense #MFA #DigitalSafety