Tootfinder

Opt-in global Mastodon full text search. Join the index!

@zachleat@zachleat.com
2025-12-03 17:15:48

@… it doesn’t do 2FA with GHA, fwiw 😅

@zachleat@zachleat.com
2025-12-02 23:17:32

@… I wouldn’t expect so (but I couldn’t say 100%). Sounds like you made a config error somewhere? I locked down npm publishing access to require 2FA and disallow tokens and deleted my tokens from GitHub Settings too — I’d also check your Actions yml to make sure the token isn’t being used there

@ayn@trunk.lol
2025-10-01 23:31:19

This improvement of grabbing 2fa codes from third-party app notifications is super useful when my main number is on google voice.

@Techmeme@techhub.social
2025-10-14 01:15:39

Researchers detail "Pixnapping", a new covert attack to steal 2FA codes and other private data on Android; Google's September patch only partially mitigates it (Dan Goodin/Ars Technica)
arstechnica.com/security/2025/

@ELLIOTTCABLE@functional.cafe
2025-09-23 07:10:48

… then what the fuck is the point, Ubisoft?
I despise when corporations participate in the security theatre of having "2FA", but then *requiring* some sort of strictly-less-restrictive "backup" login option.
1. if 2FA can be added … but account-recovery-via-a-simple-e-mail cannot be disabled (pointless.)
2. OATH/FIDO 2FA available, but cannot be enabled unless you add your cell number as a fallback (SIM swap, anyone? pointless.)
3. and, perhaps mos…

screenshot from a Ubisoft settings page, saying "Removing your phone number will deactivate 2-step verification via Authenticator app."
@kubikpixel@chaos.social
2025-10-04 15:55:07

»Grossunternehmen machen 2FA falsch:
Zwei-Faktor-Authentisierung ist eine der besten Sicherheitsmassnahmen für unsere Accounts im Netz. Viele Grossunternehmen setzen aber 2FA zum Nachteil der Kunden falsch ein«
Danke für den Artikel @…, ich habe ihn erst jetzt entdeckt. Leider verstehen mMn viele Firmen die IT nicht ganz wie sie die einsetzen. Es…

@azonenberg@ioc.exchange
2025-10-27 15:12:25

Security annoyance of the day: Mandatory 2fa that then gives you an option to trust a device for the next 7 days.
Frequent enough to be annoying, but lacks the e.g. anti-phish protections of doing it every time. Worst of both worlds.

@lil5@social.linux.pizza
2025-11-27 18:15:04

Ask a SaaS product what backup solutions they use and if they store it at a different company, you get nothing, no reply.
#hanko #HankoAuth #SaaS
Please have faith in Bezos
Shame…

@ayn@trunk.lol
2025-10-01 23:31:19

This improvement of grabbing 2fa codes from third-party app notifications is super useful when my main number is on google voice.

@Techmeme@techhub.social
2025-10-27 11:50:50

X plans to retire the Twitter.com domain, prompting users to re-enroll their security keys for 2FA, and will lock accounts that are not updated by November 10 (Will McCurdy/PCMag)
pcmag.com/news/using-a-securit

@fennek@cyberplace.social
2025-09-17 09:51:20

I do not understand how #2FA on my company laptop works. At random, far-apart times a nondescript dialogue pops up out of nowhere asking me to enter a number in the authenticator app.
Why not ask for the second factor when I log into Windows (the first time of the day)? At least when there is no (known) network?
It also feels like it would not be terribly hard to produce something like…

@eichkat3r@hessen.social
2025-10-12 10:33:37

ich hasse 2FA

@nohillside@smnn.ch
2025-10-17 07:07:45

Was ist eine „gefälschte E-Mail-Adresse“? Und wie schützt 2FA dagegen, dass Dritte ein Account mit der eigenen Wohnadresse eröffnen?
srf.ch/sendungen/kassensturz-e

@Techmeme@techhub.social
2025-09-23 21:55:52

GitHub outlines plans to secure npm following multiple supply-chain attacks, including deprecating legacy classic tokens and migrating users to FIDO-based 2FA (Xavier René-Corail/The GitHub Blog)
github.blog/security/supply-ch

@adlerweb@social.adlerweb.info
2025-09-08 19:08:40

Kleines Upsi bei #NPM: Ein Entwickler ist auf Phishing reingefallen und hat so Angreifern Zugang zu diversen Paketen verschafft. Unter Anderem so was kleines wie debug. Insgesamt haben die bekannten Pakete 2.6 Milliarden(!) Downloads pro Woche(!!).
Wie war das nochmal mit sinnvollen Signaturen und - idontknow - Passwortmanagern/2FA, was auf eine Domain gebunden ist?

@jkmartindale@mastodon.social
2025-09-06 19:51:28

guy in my DMs trying to convince me that 2FA is secretly a ploy to steal personal information because *checks notes* microsoft bad

@csessh@social.linux.pizza
2025-11-06 14:38:08

SMS 2FA: exists
Me: paying just to login to banks😭