• 0 Posts
  • 33 Comments
Joined 2 years ago
cake
Cake day: June 9th, 2023

help-circle
  • that’s like calling strong randomly generated passwords 1.5FA.

    with proper MFA, even if you steal my password (database), you won’t be able to steal my account, as you’re missing the second factor. with classic otp this is just a single use number you enter on the potentially compromised system, but if you get the seed (secret) stolen, valid numbers can be generated continuously.

    password managers (should) protect against reuse. MFA protects against logins on untrusted and potentially compromised systems/keyloggers if they’re not extracted live. password managers with auto fill and phishing resistant MFA can prevent phising, although the password manager variant is still easily bypassed when the user isn’t paying enough attention, as it’s not even that uncommon for login domains to change. obviously there are also other risks on compromised devices, like session cookie exfiltration, and there is a lot of bullshit info around from websites, especially the ones harvesting phone numbers while claiming to require it for 2FA just to gaslight users.










  • you asked why it happens so often, I provided a possible explanation.

    just yesterday we had a similar case where a usb ethernet adapter wouldn’t work on a locked device due to a similar issue, even if that one may be more logical.

    especially when you have to follow an outdated password policy where people have to change their passwords at regular intervals you’ll have such cases more frequently than when they only need to set it once until a suspected compromise.









  • example@reddthat.comtoFediverse@lemmy.worldMatrix 2.0 Is Here!
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    1 year ago

    just this week I’ve had multiple random matrix accounts start a chat with me to post an Imgur link with some Hitler bs. I assume they just chose random members of one or more fediverse related public matrix rooms to send that to. they probably just do this with random public rooms and the fediverse relation didn’t matter.