Tootfinder

Opt-in global Mastodon full text search. Join the index!

@daniel@social.telemetrydeck.com
2025-06-19 21:29:43

Big password leak. Change your passwords for google, Facebook, GitHub, etc right now, and turn on 2FA

@Techmeme@techhub.social
2025-06-16 12:15:38

A whistleblower provides nonpublic data revealing that 1M 2FA SMS messages from June 2023 passed via Fink Telecom, a small Swiss company linked to spy agencies (Bloomberg)

@pygospa@social.linux.pizza
2025-06-13 20:08:40

If you are like me, then you might have installed the #GoogleAuthenticator app, back in the days when it was the only solution out there for #TOTP #2FA.
But that is long ago. Since …

Screenshot of Ente Auth website, reading "Ente Auth: Open source 2FA authenticator, with end-to-end encrypted backups" and a picture showing the Ente Auth UI on an iPhone as well as their mascot: A little duckling holding a shield.
Screenshot of the Aegis Authenticator website reading "Aegis Authenticator is a free, secure and open source app for Android to manage your 2-step verification tokens for your online services." and a picture of their UI on an Android phone (the only platform they support).
@profcarroll@federate.social
2025-05-03 19:16:47

Now that most services have implemented 2FA (multi-factor authentication) we are seeing a new breed of scams that exploit them and trick people into approving requests under the guise of fraud prevention, which is easy to do now that we are bombarded by more secure logins. The next time you get a fraud prevention alert, be quadruple vigilant about how you respond to 2FA requests.

@midtsveen@social.linux.pizza
2025-05-31 19:32:40

@…
"2FA Liberapay does not yet support two-factor authentication."
When!? 🤦
#LiberaPay #Privacy

Screenshot of the Liberapay account settings page showing options for changing the password and a placeholder for two-factor authentication (2FA), which is not yet available on the platform.
@alejandrobdn@social.linux.pizza
2025-06-09 18:36:23

Right, Google Authenticator is out. Aegis is the new owner of the 2FA service. Gradually removing services from Evil Corp.

@profcarroll@federate.social
2025-05-03 19:16:47

Now that most services have implemented 2FA (multi-factor authentication) we are seeing a new breed of scams that exploit them and trick people into approving requests under the guise of fraud prevention, which is easy to do now that we are bombarded by more secure logins. The next time you get a fraud prevention alert, be quadruple vigilant about how you respond to 2FA requests.

@lucario@m.cmx.im
2025-06-13 12:32:02

看到 HackerNews 讨论频繁要求用户输入密码其实会降低安全。我深有此感。
工作用工具十几分钟就要重新认证,虽然公司不允许,但是我直接一个浏览器记住密码了。谁十几分钟给你输一次密码呀,闲的。
对于那些不到一个月就要重新登陆的网站,我也有减少访问的倾向,一想到要输入密码输入 2FA 就压力增大,干脆不去这网站了。Mastodon 就很好,基本不用担心登录频繁失效。

@hey@social.nowicki.io
2025-05-24 16:50:19

@… @… tl;dr: something that replaces login password 2FA credentials