home.social

#weakmfasucks — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #weakmfasucks, aggregated by home.social.

  1. @Tutanota : rubbish.

    Two WEAK locks may be LESS pointless than one WEAK lock, but they're still pointless. Go read csoonline.com/article/4147134.

    U2F has been superseded by FIDO2 (hardware keys in WebAuthn mode) and Passkeys (example in Dutch: todon.nl/@ErikvanStraten/11628).

    Both WebAuthn methods have advantages and disadvantages.

    If you don't like them, use a trustworthy passwordmanager and:

    • Let it create a unique, random, as long as possible, pw per account

    • Make backups of the pw mngr database

    • Device compromise means "game over"

    • Use Autofill (easy in Android and iOS/iPadOS)

    • If Autofill does not automatically retrieve your credentials, it probably is a fake (phishing) website. Do read troyhunt.com/a-sneaky-phish-ju

    Please stop misinforming people.

    #WeakMFAsucks #Weak2FAsucks #FIDO2 #WebAuthn #Passkeys #AutoFill #KeePassium #KeePassDX

  2. @Tutanota : rubbish.

    Two WEAK locks may be LESS pointless than one WEAK lock, but they're still pointless. Go read csoonline.com/article/4147134.

    U2F has been superseded by FIDO2 (hardware keys in WebAuthn mode) and Passkeys (example in Dutch: todon.nl/@ErikvanStraten/11628).

    Both WebAuthn methods have advantages and disadvantages.

    If you don't like them, use a trustworthy passwordmanager and:

    • Let it create a unique, random, as long as possible, pw per account

    • Make backups of the pw mngr database

    • Device compromise means "game over"

    • Use Autofill (easy in Android and iOS/iPadOS)

    • If Autofill does not automatically retrieve your credentials, it probably is a fake (phishing) website. Do read troyhunt.com/a-sneaky-phish-ju

    Please stop misinforming people.

    #WeakMFAsucks #Weak2FAsucks #FIDO2 #WebAuthn #Passkeys #AutoFill #KeePassium #KeePassDX

  3. @Tutanota : rubbish.

    Two WEAK locks may be LESS pointless than one WEAK lock, but they're still pointless. Go read csoonline.com/article/4147134.

    U2F has been superseded by FIDO2 (hardware keys in WebAuthn mode) and Passkeys (example in Dutch: todon.nl/@ErikvanStraten/11628).

    Both WebAuthn methods have advantages and disadvantages.

    If you don't like them, use a trustworthy passwordmanager and:

    • Let it create a unique, random, as long as possible, pw per account

    • Make backups of the pw mngr database

    • Device compromise means "game over"

    • Use Autofill (easy in Android and iOS/iPadOS)

    • If Autofill does not automatically retrieve your credentials, it probably is a fake (phishing) website. Do read troyhunt.com/a-sneaky-phish-ju

    Please stop misinforming people.

    #WeakMFAsucks #Weak2FAsucks #FIDO2 #WebAuthn #Passkeys #AutoFill #KeePassium #KeePassDX

  4. @Tutanota : rubbish.

    Two WEAK locks may be LESS pointless than one WEAK lock, but they're still pointless. Go read csoonline.com/article/4147134.

    U2F has been superseded by FIDO2 (hardware keys in WebAuthn mode) and Passkeys (example in Dutch: todon.nl/@ErikvanStraten/11628).

    Both WebAuthn methods have advantages and disadvantages.

    If you don't like them, use a trustworthy passwordmanager and:

    • Let it create a unique, random, as long as possible, pw per account

    • Make backups of the pw mngr database

    • Device compromise means "game over"

    • Use Autofill (easy in Android and iOS/iPadOS)

    • If Autofill does not automatically retrieve your credentials, it probably is a fake (phishing) website. Do read troyhunt.com/a-sneaky-phish-ju

    Please stop misinforming people.

    #WeakMFAsucks #Weak2FAsucks #FIDO2 #WebAuthn #Passkeys #AutoFill #KeePassium #KeePassDX