Post AV9TGkZWhdMx1UcPLs by IIVQ@mapstodon.space
(DIR) More posts by IIVQ@mapstodon.space
(DIR) Post #AV41re5227mP63MNJA by alexandria@anarchism.space
2023-04-27T02:51:32Z
3 likes, 2 repeats
A robust alternative to 2FA has to take into account three super common scenarios:- you are in a foreign city and have been mugged, your wallet and phone have been stolen from you- you have dropped your keys down the drain- you are homeless, your phone has just died, and your only computer is a public access library computer running Internet Explorer 6. you are not able to afford a monthly subscription to Bitwarden
(DIR) Post #AV41rfjTtDjIDnIBzk by alexandria@anarchism.space
2023-04-27T02:52:25Z
0 likes, 0 repeats
I really do not give a shit what 2FA solution you think you have, it cannot cope with at least one or more of these scenarios that happen, literally, every day
(DIR) Post #AV41rheElgiuA6r26C by alexandria@anarchism.space
2023-04-27T02:53:03Z
0 likes, 0 repeats
like so many people are responding with their 2FA solution. but no, sorry, it is not robust
(DIR) Post #AV4yEmJdNHh8dlvPea by kkarhan@mstdn.social
2023-04-27T13:47:27Z
0 likes, 0 repeats
@alexandria that basically only allows #iTAN as method, since those can be printed out or stored otherwise.https://en.wikipedia.org/wiki/Transaction_authentication_number#Indexed_TAN_(iTAN)If necessary, the system would generate a new iTAN each time after successful login and demanding it for the next login, and so forth.
(DIR) Post #AV4yEmxgyLjme0fP5k by thatguyoverthere@shitposter.club
2023-04-27T13:51:42.920756Z
0 likes, 0 repeats
@kkarhan @alexandria hotp tokens can also be pregenerated
(DIR) Post #AV4yiLTFkPWe4PWTdA by kkarhan@mstdn.social
2023-04-27T13:56:41Z
1 likes, 0 repeats
@thatguyoverthere @alexandria I mean that makes them "cold storage" [i]TANs as well...
(DIR) Post #AV54S8w1BibgHXdQWW by feld@bikeshed.party
2023-04-27T15:00:51.951397Z
0 likes, 0 repeats
> you are not able to afford a monthly subscription to Bitwardengood thing it's free, so this problem is already solved
(DIR) Post #AV56SqcWxvEng9z2cS by Greg@social.coop
2023-04-27T15:17:00Z
0 likes, 0 repeats
@feld @alexandria bitwarden authenticator is not included in the free version. Also, gotchas aren't a fun reply style.
(DIR) Post #AV56Ss2nfjqS5vHXCi by feld@bikeshed.party
2023-04-27T15:23:29.348618Z
0 likes, 0 repeats
wrong, they're a very fun reply style
(DIR) Post #AV56b5dwzj06aXZtHE by alexandria@anarchism.space
2023-04-27T15:24:23Z
0 likes, 0 repeats
@feld @Greg Ah don't bother with this one greg, they're on hashtag TeamPleroma, it's a lost cause
(DIR) Post #AV56b6JQVWB4fAz0vQ by feld@bikeshed.party
2023-04-27T15:25:12.692631Z
0 likes, 0 repeats
Please tell me what "TeamPleroma" means to you. What lies have you been fooled into believing?
(DIR) Post #AV56b7FD2gOlYO19zU by alexandria@anarchism.space
2023-04-27T15:24:45Z
0 likes, 0 repeats
@feld @Greg At least I know i can straight-up instance block them tho!
(DIR) Post #AV56pQMIlw6ytF9qgy by hj@shigusegubu.club
2023-04-27T15:27:26.435979Z
3 likes, 0 repeats
@feld @alexandria @Greg HA!! Now you know how it feels when randoms on IRC message me about "joining the team"! :smug_marisa:
(DIR) Post #AV5DSw8JAYtGSGpw6y by freemo@qoto.org
2023-04-27T16:42:15Z
0 likes, 0 repeats
@alexandria All 2fa already has provisio s for this. You simply backup securiely the shared secret you use when creating your 2fa. You can store thrm in a password manager and if you loose your 2fa you can thrn just restore it from the backup shared secrets.
(DIR) Post #AV5LZLKjBg11z1DBXE by nonnihil@hachyderm.io
2023-04-27T15:38:17Z
0 likes, 1 repeats
@alexandria Some coworkers of mine ran into the delightful "The industrial site from which you need to log in prohibits all external electronic devices including phones and yubikeys; the 2fa timeout is just a hair shorter than the time required to sprint to the parking lot, get a code from your phone, and sprint back."
(DIR) Post #AV5LeGPCw5pC9EeZMW by dalias@hachyderm.io
2023-04-27T13:06:57Z
1 likes, 0 repeats
@alexandria Don't leave out:- you are a refugee and you just crossed a border.
(DIR) Post #AV5LiqIHRj20bzb2zg by lanodan@queer.hacktivis.me
2023-04-27T18:14:23.573298Z
0 likes, 0 repeats
@dalias @alexandria Reminds me of Paypal apparently not allowing to change your country…
(DIR) Post #AV5XOdmhReItTNxU7U by faisal@social.lol
2023-04-27T20:25:38Z
0 likes, 0 repeats
@freemo @alexandria ok, how do you access that shared secret of pw manager if you have no phone or wallet and are away from home?
(DIR) Post #AV5YbDj1kArkN1nqMq by freemo@qoto.org
2023-04-27T20:39:03Z
0 likes, 0 repeats
@faisal @alexandria You go to the library and download the git repo you have it stored in :)
(DIR) Post #AV9TGkZWhdMx1UcPLs by IIVQ@mapstodon.space
2023-04-29T17:54:02Z
1 likes, 0 repeats
@lanodan @alexandria @dalias It does. Once. I moved from NL to BE (had to send in passport copies) and back a few years later. My paypal is still on Belgium, which is no problem at all in practice except I pay a higher sales tax on European sales.