Post B16zIAkYH18NzmCIOe by nobody@mastodon.acm.org
 (DIR) More posts by nobody@mastodon.acm.org
 (DIR) Post #B150ToParYkjpPaYD2 by hexa@chaos.social
       2025-12-09T17:42:27Z
       
       0 likes, 1 repeats
       
       #Gandi just "upgraded" me from U2F to E-Mail MFA.U2F binding was removed. E-Mail MFA was put in place instead.No advanced warning, no migration period.Would have gladly upgraded that to #Webauthn had they asked.Strong signal that the "no bullshit" policy is no more.
       
 (DIR) Post #B150TwWchJ84zWwHHE by hexa@chaos.social
       2025-12-09T17:48:20Z
       
       0 likes, 0 repeats
       
       Turns out I have two Passkeys set up in there and they just removed my legacy Yubikey 4 that I keep around for recovery purposes.So why then enable E-Mail MFA for the account? I don't get it.I migrated my personal domains elsewhere already, so whatever.But what would be a reasonable registrar for an org, where (limited) access can be delegated, e..g to manage the delegation, the zone, DNSSEC, but not the payment aspects or selling the domain.
       
 (DIR) Post #B150U51l5QmvMPZFuy by hexa@chaos.social
       2025-12-09T17:51:05Z
       
       0 likes, 0 repeats
       
       On #porkbun I could register without ever configuring a password. The account was set up with passkeys from day one.Also, the pricing they have is very competitive, so a clear recommendation if you want to move anywhere with your private domains.
       
 (DIR) Post #B150ipHzsmrOtSC87k by nobody@mastodon.acm.org
       2025-12-09T18:06:47Z
       
       0 likes, 0 repeats
       
       @hexaPorkbun is US tho...
       
 (DIR) Post #B153MDwgLSTOZ78ew4 by hexa@chaos.social
       2025-12-09T18:36:15Z
       
       0 likes, 0 repeats
       
       @nobody Yeah. Answered here:https://chaos.social/@hexa/115691029299611877
       
 (DIR) Post #B16yYhwSXAetcN5V56 by nobody@mastodon.acm.org
       2025-12-10T16:51:56Z
       
       0 likes, 1 repeats
       
       @hexaIs there a "how to screw up passkeys adoption 101" handbook in circulation that I am not aware of?`(random password, totp) →(email otp,)` on Finnish eBay (tori)
       
 (DIR) Post #B16z7Q4KyddoJzKB8K by hexa@chaos.social
       2025-12-10T16:58:12Z
       
       0 likes, 0 repeats
       
       @nobody This is exactly what Slack does as well.
       
 (DIR) Post #B16zIAkYH18NzmCIOe by nobody@mastodon.acm.org
       2025-12-10T17:00:11Z
       
       0 likes, 0 repeats
       
       @hexaYeah, but Slack has been doing this for ages, so for them the bar is pretty low
       
 (DIR) Post #B16zMBj4aOu2BIQ8A4 by nobody@mastodon.acm.org
       2025-12-10T17:00:54Z
       
       0 likes, 0 repeats
       
       @hexaSlack is like the prime example of what not to do, in every possible regard