mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,4 Tsd.
aktive Profile

#mfa

5 Beiträge5 Beteiligte0 Beiträge heute
Europe<p>MFA: Moldova condemns the actions of the GRU and welcomes British sanctions</p><p>0 The authorities in Chisinau have declared that they fully support the United Kingdom’s decision to sanction three…<br><a href="https://flipboard.social/tags/Europe" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Europe</span></a> <a href="https://flipboard.social/tags/Moldova" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Moldova</span></a> <a href="https://flipboard.social/tags/cyberattack" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cyberattack</span></a> <a href="https://flipboard.social/tags/GRU" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GRU</span></a> <a href="https://flipboard.social/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://flipboard.social/tags/sanctions" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sanctions</span></a> <a href="https://flipboard.social/tags/TheRussianFederation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TheRussianFederation</span></a> <a href="https://flipboard.social/tags/TheUnitedKingdom" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TheUnitedKingdom</span></a><br><a href="https://www.europesays.com/2257805/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">europesays.com/2257805/</span><span class="invisible"></span></a></p>
Europe<p>The new acting U.S. Chargé d’Affaires begins his mandate in Moldova</p><p>0 The new acting Chargé d’Affaires of the United States of America, Kevin Covert, has begun his mandate…<br><a href="https://flipboard.social/tags/Europe" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Europe</span></a> <a href="https://flipboard.social/tags/Moldova" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Moldova</span></a> <a href="https://flipboard.social/tags/EU" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EU</span></a> <a href="https://flipboard.social/tags/KevinCovert" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KevinCovert</span></a> <a href="https://flipboard.social/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://flipboard.social/tags/USA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>USA</span></a><br><a href="https://www.europesays.com/2254479/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">europesays.com/2254479/</span><span class="invisible"></span></a></p>
Benjamin<p>After several weeks of allowing a lot of _endusers_ to use Windows Hello for authentication, I can NOT suggest it any more. People regularly get new laptops and then call the Helpdesk because "it doesn't work anymore" and they can not log in.</p><p><a href="https://toot.berlin/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://toot.berlin/tags/WindowsHello" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WindowsHello</span></a></p>
Bytes Europe<p>The place of the Republic of Moldova is in the European Union, the foreign minister of Belgium <a href="https://www.byteseu.com/1200057/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">byteseu.com/1200057/</span><span class="invisible"></span></a> <a href="https://pubeurope.com/tags/Belgium" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Belgium</span></a> <a href="https://pubeurope.com/tags/eu" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eu</span></a> <a href="https://pubeurope.com/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a></p>
Jonathan Kamens 86 47<p>On <a href="https://federate.social/tags/HackerOne" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HackerOne</span></a>'s rollout of mandatory 2FA:<br>➕ They'll soon require 2FA.<br>➖ They should've done it long ago.<br>➕ They don't allow SMS or email as primary 2FA.<br>➖ They allow SMS for 2FA "recovery," making that the weakest link and canceling out the choice not to allow it as primary.<br>➕ They require you to generate recovery codes.<br>➕ They make you enter both a recovery code and a TOTP code to prove you saved everything.<br>➖ They still don't support WebAuthn. Very much not OK!<br><a href="https://federate.social/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://federate.social/tags/2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2FA</span></a> <a href="https://federate.social/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a></p>
ccinfo.nl<p>Artikel Cybercrimeinfo: <a href="https://www.ccinfo.nl/menu-hulpmiddelen-kwetsbaarheden/tips/2605387_vraag-van-de-week-hoe-veilig-is-jouw-wachtwoord-in-2025-bescherm-je-accounts-tegen-de-nieuwste-cyberdreigingen" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">ccinfo.nl/menu-hulpmiddelen-kw</span><span class="invisible">etsbaarheden/tips/2605387_vraag-van-de-week-hoe-veilig-is-jouw-wachtwoord-in-2025-bescherm-je-accounts-tegen-de-nieuwste-cyberdreigingen</span></a></p><p>Podcast Spotify: <a href="https://open.spotify.com/episode/5utqneIyaHxgBSLMDiaiO8?si=580022c850aa4682" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">open.spotify.com/episode/5utqn</span><span class="invisible">eIyaHxgBSLMDiaiO8?si=580022c850aa4682</span></a></p><p>Podcast Youtube: <a href="https://youtu.be/BWPzZsdfzgs?si=CLHaqzQCmTak5M7A" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">youtu.be/BWPzZsdfzgs?si=CLHaqz</span><span class="invisible">QCmTak5M7A</span></a></p><p><a href="https://mastodon.social/tags/cyberdreigingen" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cyberdreigingen</span></a> <a href="https://mastodon.social/tags/wachtwoordbeveiliging" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>wachtwoordbeveiliging</span></a> <a href="https://mastodon.social/tags/digitaleveiligheid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>digitaleveiligheid</span></a> <a href="https://mastodon.social/tags/cybercrime" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybercrime</span></a> <a href="https://mastodon.social/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a></p>
Scott Wilson<p>My local <a href="https://infosec.exchange/tags/school" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>school</span></a> system, affected by the <a href="https://infosec.exchange/tags/PowerSchoolBreach" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PowerSchoolBreach</span></a> is migrating to a new platform called Infinite Campus.</p><p>How, in the Year of Our Lord 2025, does this system not support ANY KIND of multi-factor authentication???</p><p>But don't worry, according to their website, they absolutely take my security and privacy seriously...</p><p><a href="https://www.infinitecampus.com/security" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">infinitecampus.com/security</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/mfa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mfa</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a></p>
Wintermute_BBS<p><span class="h-card" translate="no"><a href="https://oldbytes.space/@rc2014" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>rc2014</span></a></span> <span class="h-card" translate="no"><a href="https://oldbytes.space/@electron_greg" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>electron_greg</span></a></span> back in school we had a special, modular custom-bus based <a href="https://oldbytes.space/tags/intel8085" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>intel8085</span></a> system to teach us about computers and programming.</p><p>It also had a switch panel and I fondly remember looking up opcodes in a photocopied table so that I knew which value to "toggle" next on the switches before writing it to a memory address. Hands on computing, the real way.</p><p>It was called <a href="https://oldbytes.space/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> (microcomputer für ausbildung - microcomputer for training) and it also ran CP/M and featured a <a href="https://oldbytes.space/tags/Siemens" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Siemens</span></a> <a href="https://oldbytes.space/tags/SPS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SPS</span></a> module (god, I hate SPS). </p><p>It was this system I learned <a href="https://oldbytes.space/tags/intel8085" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>intel8085</span></a> <a href="https://oldbytes.space/tags/assembler" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>assembler</span></a> on.</p><p>P.S.: I guess this baby and the fond memory I have of it made me fall in love with <a href="https://oldbytes.space/tags/rc2014" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rc2014</span></a> decades later ...</p>
hackmac<p>Das OLG Dresden stellt klar, dass das S‑pushTAN‑Verfahren keine starke Kundenauthentifizierung bietet, wenn bereits beim Login sensible Daten verfügbar sind. Die Bank haftet mit, auch wenn der Kunde grob fahrlässig handelte. Ein Login nur mit Benutzername und PIN reicht offensichtlich nicht aus, sobald mehr als der Kontostand angezeigt wird. <a href="https://mastodon.social/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://mastodon.social/tags/OnlineBanking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OnlineBanking</span></a> <a href="https://mastodon.social/tags/ITSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITSecurity</span></a> <a href="https://mastodon.social/tags/pushTAN" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pushTAN</span></a> <a href="https://mastodon.social/tags/2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2FA</span></a> <a href="https://mastodon.social/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://mastodon.social/tags/Banking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Banking</span></a> <a href="https://mastodon.social/tags/Sparkasse" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sparkasse</span></a></p><p><a href="https://www.heise.de/news/OLG-Urteil-S-pushTAN-Verfahren-reicht-nicht-fuer-starke-Kundenauthentifizierung-10477522.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/news/OLG-Urteil-S-pus</span><span class="invisible">hTAN-Verfahren-reicht-nicht-fuer-starke-Kundenauthentifizierung-10477522.html</span></a></p>
hackmac<p>Hacker schlagen im Herzen der russischen Drohnenentwicklung zu! Ein gezielter Cyberangriff auf STC in Sankt Petersburg, einen zentralen Zulieferer für Russlands militärische DJI-Drohnen. Der Vorwurf: STC unterstützt aktiv den russischen Krieg in der Ukraine mit manipulierten DJI-Drohnen. Die Ironie: Eine Organisation, die Kriegsdrohnen "härtet", war intern selbst alles andere als gehärtet. <a href="https://mastodon.social/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybersecurity</span></a> <a href="https://mastodon.social/tags/Cyberwar" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cyberwar</span></a> <a href="https://mastodon.social/tags/SocialEngineering" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SocialEngineering</span></a> <a href="https://mastodon.social/tags/Ukraine" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Ukraine</span></a> <a href="https://mastodon.social/tags/Russia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Russia</span></a> <a href="https://mastodon.social/tags/Drohne" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Drohne</span></a> <a href="https://mastodon.social/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://mastodon.social/tags/Hackerangriff" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Hackerangriff</span></a> <a href="https://mastodon.social/tags/Cybercrime" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybercrime</span></a></p>
Redhotcyber<p>Io non ho mai usato l'antivirus... lo sapete perché? Perché il mio sistema operativo è superiore! È... ehm... oddio, aspetta che si è bloccato tutto mentre aprivo il SUDO.</p><p><a href="https://mastodon.bida.im/tags/redhotcyber" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>redhotcyber</span></a> <a href="https://mastodon.bida.im/tags/meme4cyber" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>meme4cyber</span></a> <a href="https://mastodon.bida.im/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://mastodon.bida.im/tags/hacking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hacking</span></a> <a href="https://mastodon.bida.im/tags/hacker" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hacker</span></a> <a href="https://mastodon.bida.im/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://mastodon.bida.im/tags/infosecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosecurity</span></a> <a href="https://mastodon.bida.im/tags/quotes" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>quotes</span></a> <a href="https://mastodon.bida.im/tags/meme" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>meme</span></a> <a href="https://mastodon.bida.im/tags/comica" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>comica</span></a> <a href="https://mastodon.bida.im/tags/vignette" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vignette</span></a> <a href="https://mastodon.bida.im/tags/citazioni" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>citazioni</span></a> <a href="https://mastodon.bida.im/tags/cybersec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersec</span></a> <a href="https://mastodon.bida.im/tags/sicurezzainformatica" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sicurezzainformatica</span></a> <a href="https://mastodon.bida.im/tags/malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware</span></a> <a href="https://mastodon.bida.im/tags/cybercrime" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybercrime</span></a> <a href="https://mastodon.bida.im/tags/awareness" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>awareness</span></a> <a href="https://mastodon.bida.im/tags/meme" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>meme</span></a> <a href="https://mastodon.bida.im/tags/memetime" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>memetime</span></a> <a href="https://mastodon.bida.im/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://mastodon.bida.im/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://mastodon.bida.im/tags/MultifactorAuthentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MultifactorAuthentication</span></a> <a href="https://mastodon.bida.im/tags/DigitalSafety" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DigitalSafety</span></a> <a href="https://mastodon.bida.im/tags/Infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Infosec</span></a> <a href="https://mastodon.bida.im/tags/ITHumor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITHumor</span></a> <a href="https://mastodon.bida.im/tags/BetterSafeThanSorry" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BetterSafeThanSorry</span></a> <a href="https://mastodon.bida.im/tags/PasswordAddio" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PasswordAddio</span></a> <a href="https://mastodon.bida.im/tags/AwarenessWithASmile" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AwarenessWithASmile</span></a></p>
Europe<p>Moldova expands its presence in Switzerland by opening an honorary consulate in Zurich</p><p>0 The Honorary Consulate of the Republic of Moldova in Zurich, Switzerland, was inaugurated in the presence of…<br><a href="https://flipboard.social/tags/Europe" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Europe</span></a> <a href="https://flipboard.social/tags/Moldova" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Moldova</span></a> <a href="https://flipboard.social/tags/HonoraryConsulate" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HonoraryConsulate</span></a> <a href="https://flipboard.social/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://flipboard.social/tags/switzerland" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>switzerland</span></a> <a href="https://flipboard.social/tags/Zurich" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Zurich</span></a><br><a href="https://www.europesays.com/2220582/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">europesays.com/2220582/</span><span class="invisible"></span></a></p>
Em :official_verified:<p>What is your favorite app for <br>Multifactor Authentication, and why do you like it most? 2️⃣✌️👀</p><p><a href="https://infosec.exchange/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://infosec.exchange/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://infosec.exchange/tags/2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2FA</span></a> <a href="https://infosec.exchange/tags/Authenticator" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authenticator</span></a></p>
Florian Haas<p>What are your thoughts on Aegis Authenticator?</p><p><a href="https://github.com/beemdevelopment/aegis" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/beemdevelopment/aeg</span><span class="invisible">is</span></a></p><p><a href="https://mastodon.social/tags/AskFedi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AskFedi</span></a> <a href="https://mastodon.social/tags/TOTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TOTP</span></a> <a href="https://mastodon.social/tags/2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2FA</span></a> <a href="https://mastodon.social/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a></p>
Bytes Europe<p>The meeting of the Moldovan-Kazakh Economic Cooperation Commission, anticipated for this year <a href="https://www.byteseu.com/1159872/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">byteseu.com/1159872/</span><span class="invisible"></span></a> <a href="https://pubeurope.com/tags/Diplomacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Diplomacy</span></a> <a href="https://pubeurope.com/tags/economy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>economy</span></a> <a href="https://pubeurope.com/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://pubeurope.com/tags/Moldova" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Moldova</span></a> <a href="https://pubeurope.com/tags/TheMoldoKazakhJointCommission" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TheMoldoKazakhJointCommission</span></a></p>
Bytes Europe<p>Claims of law enforcement using force against Russian citizens are baseless: Azerbaijani MFA <a href="https://www.byteseu.com/1158236/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">byteseu.com/1158236/</span><span class="invisible"></span></a> <a href="https://pubeurope.com/tags/Azerbaijan" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Azerbaijan</span></a> <a href="https://pubeurope.com/tags/LawEnforcement" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LawEnforcement</span></a> <a href="https://pubeurope.com/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://pubeurope.com/tags/RepublicOfAzerbaijan" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RepublicOfAzerbaijan</span></a> <a href="https://pubeurope.com/tags/RussianCitizens" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RussianCitizens</span></a></p>
Abimelech B. 🐧🇩🇪| wörk ™️<p><a href="https://fulda.social/tags/microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>microsoft</span></a> versendet jetzt <a href="https://fulda.social/tags/mfa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mfa</span></a> <a href="https://fulda.social/tags/sms" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sms</span></a> als fallback per <a href="https://fulda.social/tags/whatsapp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>whatsapp</span></a> ! 🤬</p>
Erik van Straten<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@tychotithonus" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>tychotithonus</span></a></span> : thank you for responding. I'm not trying to be aggressive but to make the internet safer.</p><p>In your original toot, you wrote: "It's comforting to know that I'm significantly protected from these attempts" while showing phishing messages.</p><p>From <a href="https://blog.talosintelligence.com/how-are-attackers-trying-to-bypass-mfa/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.talosintelligence.com/how</span><span class="invisible">-are-attackers-trying-to-bypass-mfa/</span></a> (a year ago):<br>"In the latest Cisco Talos Incident Response Quarterly Trends report, instances related to multi-factor authentication (MFA) were involved in nearly half of all security incidents that our team responded to in the first quarter of 2024".</p><p>From my own research I know that the number of phishing-sites is exploding. PhaaS makes it easy to take over accounts where weak MFA is used.</p><p>The more people use weak MFA, the more of these sort of attacks we'll be seeing. IOW, the security of weak MFA (TOTP, SMS, number matching) will decrease over time (it does since Alex Weinert wrote this in 2019: <a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/all-your-creds-are-belong-to-us/855124" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">techcommunity.microsoft.com/bl</span><span class="invisible">og/microsoft-entra-blog/all-your-creds-are-belong-to-us/855124</span></a>).</p><p>Furthermore, from the page referenced by you, <a href="https://meta.wikimedia.org/wiki/Steward_requests/Global_permissions#Requests_for_2_Factor_Auth_tester_permissions" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">meta.wikimedia.org/wiki/Stewar</span><span class="invisible">d_requests/Global_permissions#Requests_for_2_Factor_Auth_tester_permissions</span></a>:<br>"Testing this service may result in the loss of your access and is not recommended for inexperienced users."</p><p>TOTP effectively means a unique strong (server supplied) password per account that people can impossibly remember. A TOTP app simply is a disguised password manager.</p><p>There have been lots of incidents where people lost access to multiple MFA-proteced accounts because they lost access to the shared secrets on their phones. Nobody tells people to make sure that backups are made of such secrets, let alone in a secure and privacy-respecting manner.</p><p>Note: a lot of TOTP apps had serious security issues a couple of years ago, as documented by Conor Gilsenan et al. in <a href="https://www.usenix.org/conference/usenixsecurity23/presentation/gilsenan" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">usenix.org/conference/usenixse</span><span class="invisible">curity23/presentation/gilsenan</span></a> (source: <a href="https://infosec.exchange/@conorgil/109542074585730853" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@conorgil/109</span><span class="invisible">542074585730853</span></a>). I doubt that things have significantly improved (Authy was really bad, and at the time, Google's app blocked backups of the shared secrets).</p><p>Here's an, IMO, way better advice: use a password manager that checks the domain name. Use it to generate long random passwords, and make sure that it's (encrypted) database is backed up after every change you make.</p><p>I wrote about the caveats of password managers in, for example, <a href="https://infosec.exchange/@ErikvanStraten/113022180851761038" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113022180851761038</span></a>.</p><p>Recommending people to use TOTP because they use weak passwords is a bad idea IMO: you effectively make them use a password manager (which a TOTP app is, while it does not check domain names) instead of solving the primary problem: weak passwords.</p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@conorgil" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>conorgil</span></a></span> <br> </p><p><a href="https://infosec.exchange/tags/Phishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Phishing</span></a> <a href="https://infosec.exchange/tags/TOTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TOTP</span></a> <a href="https://infosec.exchange/tags/WeakMFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WeakMFA</span></a> <a href="https://infosec.exchange/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://infosec.exchange/tags/2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2FA</span></a> <a href="https://infosec.exchange/tags/Weak2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Weak2FA</span></a> <a href="https://infosec.exchange/tags/ATO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ATO</span></a> <a href="https://infosec.exchange/tags/AitM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AitM</span></a> <a href="https://infosec.exchange/tags/MitM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MitM</span></a> <a href="https://infosec.exchange/tags/Evilginx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Evilginx</span></a> <a href="https://infosec.exchange/tags/PhaaS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhaaS</span></a></p>
Erik van Straten<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@tychotithonus" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>tychotithonus</span></a></span> : can you explain which protection(s) are provided by weak MFA?<br> </p><p><a href="https://infosec.exchange/tags/Phishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Phishing</span></a> <a href="https://infosec.exchange/tags/TOTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TOTP</span></a> <a href="https://infosec.exchange/tags/WeakMFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WeakMFA</span></a> <a href="https://infosec.exchange/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://infosec.exchange/tags/2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2FA</span></a> <a href="https://infosec.exchange/tags/Weak2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Weak2FA</span></a> <a href="https://infosec.exchange/tags/ATO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ATO</span></a> <a href="https://infosec.exchange/tags/AitM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AitM</span></a> <a href="https://infosec.exchange/tags/MitM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MitM</span></a> <a href="https://infosec.exchange/tags/Evilginx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Evilginx</span></a></p>
Strelitzer™<p><span class="h-card" translate="no"><a href="https://troet.cafe/@charlybrown" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>charlybrown</span></a></span> Das nutzt nichts. Die <a href="https://norden.social/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> trägt den Termin bei <a href="https://norden.social/tags/doctolib" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>doctolib</span></a>, <a href="https://norden.social/tags/jameda" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>jameda</span></a> u. a. digitalen Mitessern ein und das war’s dann für dich. <a href="https://norden.social/tags/SMS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SMS</span></a> kommt zum Termin auch noch, wenn du Pech hast. Und das alles ohne deine Einwilligung und <a href="https://norden.social/tags/Datenschutzerkl%C3%A4rung" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Datenschutzerklärung</span></a>.<br><span class="h-card" translate="no"><a href="https://social.tchncs.de/@kuketzblog" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>kuketzblog</span></a></span></p>