Post AV9TGkZWhdMx1UcPLs by IIVQ@mapstodon.space
 (DIR) More posts by IIVQ@mapstodon.space
 (DIR) Post #AV41re5227mP63MNJA by alexandria@anarchism.space
       2023-04-27T02:51:32Z
       
       3 likes, 2 repeats
       
       A robust alternative to 2FA has to take into account three super common scenarios:- you are in a foreign city and have been mugged, your wallet and phone have been stolen from you- you have dropped your keys down the drain- you are homeless, your phone has just died, and your only computer is a public access library computer running Internet Explorer 6. you are not able to afford a monthly subscription to Bitwarden
       
 (DIR) Post #AV41rfjTtDjIDnIBzk by alexandria@anarchism.space
       2023-04-27T02:52:25Z
       
       0 likes, 0 repeats
       
       I really do not give a shit what 2FA solution you think you have, it cannot cope with at least one or more of these scenarios that happen, literally, every day
       
 (DIR) Post #AV41rheElgiuA6r26C by alexandria@anarchism.space
       2023-04-27T02:53:03Z
       
       0 likes, 0 repeats
       
       like so many people are responding with their 2FA solution. but no, sorry, it is not robust
       
 (DIR) Post #AV4yEmJdNHh8dlvPea by kkarhan@mstdn.social
       2023-04-27T13:47:27Z
       
       0 likes, 0 repeats
       
       @alexandria that basically only allows #iTAN as method, since those can be printed out or stored otherwise.https://en.wikipedia.org/wiki/Transaction_authentication_number#Indexed_TAN_(iTAN)If necessary, the system would generate a new iTAN each time after successful login and demanding it for the next login, and so forth.
       
 (DIR) Post #AV4yEmxgyLjme0fP5k by thatguyoverthere@shitposter.club
       2023-04-27T13:51:42.920756Z
       
       0 likes, 0 repeats
       
       @kkarhan @alexandria hotp tokens can also be pregenerated
       
 (DIR) Post #AV4yiLTFkPWe4PWTdA by kkarhan@mstdn.social
       2023-04-27T13:56:41Z
       
       1 likes, 0 repeats
       
       @thatguyoverthere @alexandria I mean that makes them "cold storage" [i]TANs as well...
       
 (DIR) Post #AV54S8w1BibgHXdQWW by feld@bikeshed.party
       2023-04-27T15:00:51.951397Z
       
       0 likes, 0 repeats
       
       > you are not able to afford a monthly subscription to Bitwardengood thing it's free, so this problem is already solved
       
 (DIR) Post #AV56SqcWxvEng9z2cS by Greg@social.coop
       2023-04-27T15:17:00Z
       
       0 likes, 0 repeats
       
       @feld @alexandria bitwarden authenticator is not included in the free version. Also, gotchas aren't a fun reply style.
       
 (DIR) Post #AV56Ss2nfjqS5vHXCi by feld@bikeshed.party
       2023-04-27T15:23:29.348618Z
       
       0 likes, 0 repeats
       
       wrong, they're a very fun reply style
       
 (DIR) Post #AV56b5dwzj06aXZtHE by alexandria@anarchism.space
       2023-04-27T15:24:23Z
       
       0 likes, 0 repeats
       
       @feld @Greg Ah don't bother with this one greg, they're on hashtag TeamPleroma, it's a lost cause
       
 (DIR) Post #AV56b6JQVWB4fAz0vQ by feld@bikeshed.party
       2023-04-27T15:25:12.692631Z
       
       0 likes, 0 repeats
       
       Please tell me what "TeamPleroma" means to you. What lies have you been fooled into believing?
       
 (DIR) Post #AV56b7FD2gOlYO19zU by alexandria@anarchism.space
       2023-04-27T15:24:45Z
       
       0 likes, 0 repeats
       
       @feld @Greg At least I know i can straight-up instance block them tho!
       
 (DIR) Post #AV56pQMIlw6ytF9qgy by hj@shigusegubu.club
       2023-04-27T15:27:26.435979Z
       
       3 likes, 0 repeats
       
       @feld @alexandria @Greg HA!! Now you know how it feels when randoms on IRC message me about "joining the team"! :smug_marisa:
       
 (DIR) Post #AV5DSw8JAYtGSGpw6y by freemo@qoto.org
       2023-04-27T16:42:15Z
       
       0 likes, 0 repeats
       
       @alexandria All 2fa already has provisio s for this. You simply backup securiely the shared secret you use when creating your 2fa. You can store thrm in a password manager and if you loose your 2fa you can thrn just restore it from the backup shared secrets.
       
 (DIR) Post #AV5LZLKjBg11z1DBXE by nonnihil@hachyderm.io
       2023-04-27T15:38:17Z
       
       0 likes, 1 repeats
       
       @alexandria Some coworkers of mine ran into the delightful "The industrial site from which you need to log in prohibits all external electronic devices including phones and yubikeys; the 2fa timeout is just a hair shorter than the time required to sprint to the parking lot, get a code from your phone, and sprint back."
       
 (DIR) Post #AV5LeGPCw5pC9EeZMW by dalias@hachyderm.io
       2023-04-27T13:06:57Z
       
       1 likes, 0 repeats
       
       @alexandria Don't leave out:- you are a refugee and you just crossed a border.
       
 (DIR) Post #AV5LiqIHRj20bzb2zg by lanodan@queer.hacktivis.me
       2023-04-27T18:14:23.573298Z
       
       0 likes, 0 repeats
       
       @dalias @alexandria Reminds me of Paypal apparently not allowing to change your country…
       
 (DIR) Post #AV5XOdmhReItTNxU7U by faisal@social.lol
       2023-04-27T20:25:38Z
       
       0 likes, 0 repeats
       
       @freemo @alexandria ok, how do you access that shared secret of pw manager if you have no phone or wallet and are away from home?
       
 (DIR) Post #AV5YbDj1kArkN1nqMq by freemo@qoto.org
       2023-04-27T20:39:03Z
       
       0 likes, 0 repeats
       
       @faisal @alexandria You go to the library and download the git repo you have it stored in :)
       
 (DIR) Post #AV9TGkZWhdMx1UcPLs by IIVQ@mapstodon.space
       2023-04-29T17:54:02Z
       
       1 likes, 0 repeats
       
       @lanodan @alexandria @dalias It does. Once. I moved from NL to BE (had to send in passport copies) and back a few years later. My paypal is still on Belgium, which is no problem at all in practice except I pay a higher sales tax on European sales.