#2FactorAuthentication

2025-04-26

I love how the one website that uses a simple four digit #2FactorAuthentication code (which should be plenty for a time-boxed single-use password) is the investment bank asking me to confirm who I am before wiring tens of thousands of dollars. Meanwhile, I need to remember 6-8 digits to type into some random streaming platform that costs $10 a month.

Daniel Fisher(lennybacon)lennybacon@infosec.exchange
2025-01-28
2024-08-12

Here is How To Add 2FA in web apps using Laravel 11. This is amazing tutorial so you could just follow along to do that

laramatic.com/step-by-step-gui

Technoholic.metechnoholic
2024-04-20

Roku is enhancing security measures with new 2-factor authentication following two breaches affecting 600K accounts. us.technoholic.me/QdJ83ga

2024-02-16

What is your preferred method of ? 🔑📱

Tuta offers full support for & to keep your account secure! 🔒

👉 tuta.com/blog/posts/why-u2f-is

Michael EdwardsMichaelLondonSF@mas.to
2023-12-20

Do banks and others realise that "Two factor authentication" no longer works now that text / SMS messages flash up on the screen of a computer, like this.
#bank #lloyds #scam #fraud #2FactorAuthentication

screenshot of a  dialog box asking for a passcode and the sms containing the passcode coming up beside it from a mobile phone - notionally a separate device.
2023-06-21

My bank urges me to use their newest app, "cause it's more secure".

Can someone explain to me, how using an app and #2FactorAuthentication #twofactorauthentication on the same device (the phone) is more secure than using the app/website on a computer and 2FA on the phone?

Do I miss anything? :blobthinking:

(I also asked my bank :blobgrin: no answer so far...)

2023-06-20

I really don't want to go back to Authy but I will if I have to. #2fa #2FactorAuthentication #AppleWatch

2023-06-20

What are people using for a 2FA app these days on their iPhone/Apple Watch? I’m going to have to get rid of Okta Verify because they just discontinued their excellent Apple Watch app. #okta #2FactorAuthentication #2fa #AppleWatch #iPhone

Mysk🇨🇦🇩🇪mysk@defcon.social
2023-06-20

🎬 So this scam #2FA app is using custom product pages of Apple Search Ads to trick users. It has different campaigns per search keywords. When searching for "Microsoft Authenticator", it shows screenshots highlighting "Microsoft". and when searching for "Google Authenticator", it highlights "Google". Watch the video 🤯

It's worth noting that custom product pages need to be approved by App Store Connect and Apple Search Ads.
This app steals 2FA secrets and its model is very suspicious as noted below.

Friendly reminder: Mastodon uses no algorithms for discovering posts. The only way to spread the word is by boosting posts. If you think this post is helpful, boost it to reach others. Thank you 🙏
#Privacy #Apple #iOS #cybersecuritytips #infosec #cybersecurity #security #2FactorAuthentication

Screenshot of Apple Search Ads page:

Manage Today tab ad creative

Understand Today tab ad guidelines

When you create a Today tab campaign in Apple Search Ads
Advanced, your ad creative will be based on a custom product page you select. Your custom product page will need to be approved by App Store Connect before you create a Today tab campaign, and your ad creative will require approval by Apple Search Ads
Mysk🇨🇦🇩🇪mysk@defcon.social
2023-06-19

The rogue 2FA app that steals scanned secrets is now ranked 18 on the German App Store for the productivity category. No wonder! The app disguises as a Microsoft app. It is the top hit when you search for "Microsoft Authenticator" and the developer has updated the screenshots in the ad card to highlight the word "Microsoft". Surprisingly, the product page of the app shows different screenshots with the word "Microsoft" removed.
The app now has 1.2K reviews, as opposed to 18 when we first addressed the app.

🙏 Boosting this post will help spread the word. Thank you!

#privacy #security #2FactorAuthentication #iOS #infosec

Screenshot of the App Store showing the search results for "Microsoft Authenticator". The top hit is an ad for the rogue app that steals secrets. The ad card is crafted to look as if it was an app developed my Microsoft. The screenshots include these titles:

Secure Your Microsoft Account
Authenticator App for MicrosoftScreenshot of the product page of the rogue app on the App Store. The app screenshots are different from the ones that appear in the ad. The screenshots say "Secure Your Online Accounts" instead of the deceitful title that appeared in the ad, "Secure Your Microsoft Account"Screenshot taken about 4 months ago of the App Store showing the rogue app as the top search result when searching for "microsoft authenticator". The ad card doesn't highlight the word "Microsoft"The rogue app is now ranked 18 in the productivity category of the German App Store
archon :rebelverified:archon@infosec.exchange
2023-06-11

Hello, World! This is my #introduction post. I'm me, you're you (at least I hope so), and I'm glad to be here with you.

I talk about politics, #infosec, bad jokes, memes, and the terrible things we're expected to just accept in the name of capitalism and making the rich richer. Black Lives Matter, trans rights are human rights, sex work is work. SWERFs, TERFs, Nazis, and their apologists need not apply.

I'm an infosec generalist, working on securing both back-end infra and client devices. #ZeroTrust, #2FactorAuthentication, #certificates (both TLS and SSH), are major focus areas for me.

I'm also a reasonable #software #developer (just don't ask me to pass a software engineering interview loop) and a pretty good #Linux and #OpenBSD sysadmin. I also know my way around #database systems, preferably #PostgreSQL or #MySQL.

I like to think I'm reasonably competent at what I do. My employer has agreed for over 15 years at this point, for whatever that's worth.

What would I say it is I do here? When I'm not guarding my stapler, I like to read fantasy novels and I play #GenshinImpact and #HonkaiStarRail. I'm also making my way through #TearsOfTheKingdom slowly. No multi-player games for me, not even tabletop anymore, but I might watch if you're streaming.

Evan Engelevanengel
2023-03-06

Why do so few banking apps support TOTP 2 factor authentication? I've found that banking apps either rely on SMS/email for a second factor, or they support TOTP but only through a one-off app that can't be used for other TOTPs. So annoying!

Anyone know of a bank that lets you use Google Authenticator/Aegis/Authy for a TOTP?

Mysk🇨🇦🇩🇪mysk@defcon.social
2023-02-27

A very nice article about the phenomenon of scam authenticator apps

"In fact, an app that uploads your seeds to a server anywhere in the world is either so incompetent that you should stop using it immediately, or so untrustworthy that you should treat it as cybercriminal malware."

#Cybersecurity #Privacy #InfoSec #2FA #2FactorAuthentication

nakedsecurity.sophos.com/2023/

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst