publicvoit, to random German
@publicvoit@graz.social avatar

Wie man eine vertrauenswürdige Authentifizierungs-App auswählt
https://www.karl-voit.at/2023/03/05/TOTP-Auswahl/

... mit einer deutlichen Warnung vor dem #GoogleAuthenticator!

#publicvoit #Authenticator #FIDO2 #TOTP #FreeOTP #2FA #Sicherheit

bech, to random
@bech@mstdn.dk avatar

: I’m using the Google Authenticator app but I’d like to replace it. Which 2FA app should I give a try instead? I’d much prefer something open source.

jomo, to infosec
@jomo@mstdn.io avatar

Remember when Google Authenticator started syncing 2FA codes to the cloud? Companies are now getting hacked thanks to this "feature". An attacker gained access to a GSuite account via phishing and could then just use the 2FA codes that were previously only residing on employees phones.

Worth a read: https://retool.com/blog/mfa-isnt-mfa/

itnewsbot, to security
@itnewsbot@schleuss.online avatar

How Google Authenticator made one company’s network breach much, much worse - Enlarge (credit: Getty Images)

A security company is calling o... - https://arstechnica.com/?p=1968685 &it

chikorita157, to infosec
@chikorita157@sakurajima.moe avatar

If you are using cloud sync on Google Authenticator, don’t. The syncing process is unencrypted, which is bad because Google can see them. If Google’s server get hacked, an attacker can gain access to them.

End to End Encryption will eventually come, but I would avoid Google Authenticator and use something else.

https://www.macrumors.com/2023/04/27/google-authenticator-cloud-sync-no-e2e/

ligniform, to infosec
flameeyes, to random
@flameeyes@mastodon.social avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • Leos
  • modclub
  • magazineikmin
  • osvaldo12
  • tacticalgear
  • InstantRegret
  • Youngstown
  • slotface
  • rosin
  • love
  • kavyap
  • ngwrru68w68
  • mdbf
  • thenastyranch
  • megavids
  • DreamBathrooms
  • khanakhh
  • GTA5RPClips
  • cisconetworking
  • everett
  • Durango
  • cubers
  • tester
  • provamag3
  • anitta
  • ethstaker
  • normalnudes
  • JUstTest
  • All magazines