#authn

2025-04-03

Default passwords (in this case voicemail PIN) strike again! There are many #AuthN systems around that support sending OTPs by a phone call as an alternative/fallback to SMS (and is an accessibility requirement). Unfortunately, they can't account for this attack vector.
(Oh, and use Signal, not Telegram)
#Identity #Security
gbhackers.com/hackers-hijack-t

Augustine Correaindcoder@fosstodon.org
2025-03-10

Excited to be speaking at @fossasia
🚀 This year, I'm diving deep into Identity and Access Management (#IAM) for #OSS.

All are welcome and I encourage all knowledge levels to attend: Don't be intimidated by "advanced security"! I'm breaking down complex concepts into easy-to-understand explanations, with a historical perspective to give context.

1️⃣Explore #AuthN #AuthZ 🔐
2️⃣ @keycloak Primer 🌐
3️⃣Best Practices for #OSS 🛡️

#FOSSAsia2025

The image is a promotional badge for the FOSSASIA Summit 2025, which will be held at True Digital Park in Bangkok from March 13-15. The badge features a QR code, the event's name, location, and dates at the top. Below this, it states that FOSSASIA Summit is Asia's leading open source technology conference. The badge highlights Augustine Correa, a Microsoft MVP for Developer Technologies and AI Platform, as a speaker. Augustine Correa's talk is titled "Who are you?" and will cover Identity and Access for Cloud Native OSS Projects.

Interesting attack method. "They are merging, wonder if they screwed up transfer? Yup."

theregister.com/2024/07/15/squ

#squarespace #dns #authn

Kyle Andersonkandersonus
2024-04-27

“At this point I think that will fail in the hands of the general consumer population. We missed our golden chance to eliminate passwords through a desire to capture markets and promote hype.”

fy.blackhats.net.au/blog/2024-

Big sadge 😭

2024-03-07

Dans son guide "Recommandations relatives à l'authentification multifacteur et aux mots de passe", l'ANSSI nous explique que l'authentification forte doit mettre en oeuvre un protocole cryptographique et résister aux attaques par rejeu, et aux attaques de l'homme du milieu.... Puis s'en va nous donner des exemples d'authentification forte...

Dans cette liste, on y retrouve TOTP...

Les TOTP sont parfaitement vulnérables aux attaques par rejeu, une fois interceptés par un site de hameçonnage. Ils sont également parfaitement attaquables par MITM...

En outre, on retrouve dans la liste FIDO2.

FIDO2 est attaquable par MITM si l'on ne met pas en oeuvre la mesure dite de "channel binding" ou "token binding". À ma connaissance, cette fonctionnalité n'est prise en charge par aucun navigateur. Même Chrome l'a retiré.

groups.google.com/a/chromium.o

Ils sont beaux, les guides #ANSSI depuis quelques années... ​🥱​

#infosec #authn #webauthn

2024-02-23

Edit : Cette communauté est formidable <3 Merci à toutes et tous celleux qui se sont proposé.es !

Besoin d'aide pour une relecture

J'ai rédigé ces derniers temps un cours "Identité et méthodes d'authentification" pour une grande école parisienne. Niveau Bac+5.

Ce cours sera ultérieurement publié en licence libre (probablement CC-0 ou CC-BY).

Je dois donner ce cours mercredi. Est-ce qu'un gentil ou une gentille fédinaute compétent.e ou pas sur le sujet spécifique aurait le temps de relire ce que j'ai produit ce week-end et me faire un retour ? Ca fait environ 20 pages de texte brut police 12, alinéa simple.

#authn #authentification #u2f #fido2 #webauthn #identity #keycloak #cours #infosec #secnumcloud

2023-11-10

Neither @protonmail nor @Tutanota support passkeys as a password-less authentication method, and at least @protonmail does not support security key/passkey only 2FA. (I don't know if @Tutanota does)

I mean, these providers are supposed to be top-notch secure email providers. Why are they so far behind? Any serious alternatives? Paying customer here.

#email #smtp #fido2 #passkeys #authn

2023-08-07

I'm looking for an open source #IAM provider with good recommendations... I'm considering Auth0 (out of laziness), but definitely not interested in AD or Google direct - does anyone know a good open-source tool to use for authentication? Hosting my own is fine, but rolling my own is re-inventing the wheel a bit too much.

Federation supported or not, either fine.

Some listed here: medevel.com/5-iam-enterprise/ such as #KeyCloak and #OpenIAM

#Auth #Authr #Authn #Security #Angular

2023-07-12

maybe i'm getting old, but i feel the recent trend towards #passwordless with #passkeys / #authn might be a bad idea.

passwords (with all their problems) are a low-tech thing. depending on the people having access to a high-end device with their keys seems highly rich-tech-bro-in-the-western-world

B̷̻̠͊͛̀̽e̷͈̪̮̙͋͌̈́n̵̢̲̥̳̔ :rebel: :donor: :verified_paw: :verified_paw:aircooledcafe@infosec.exchange
2023-05-17

#Passkeys question, I have Yubikeys set as the second factor on numerous accounts. What if I want to use passkey for those accounts stored on a Yubikey, will using passkey mean I need an OTP code or have to use a different Yubikey? Or will passkeys eliminate the second factor as it has seemed to do with my Google account, I just signed in using a passkey and wasn't asked for my second factor. I should have really done far more reading on this matter.
#Fido2 #authN

Everything Open Conferenceeverythingopen@fosstodon.org
2023-04-19

As we recap our fantastic #EverythingOpen talks, next up is William Brown @firstyear from @SUSE who walks us through #passkeys for #web #authn, showing us their ambiguities, how they work, what their limitations are, and what we need to be thinking about when we implement them.

Another fabulous talk from William.

youtube.com/watch?v=V-7zMIgGO1

damienboddamienbod
2023-04-15

I will be speaking about application security at the Azure Bootcamp Switzerland in Bern, a technology conference focusing on the Microsoft Azure Cloud. I really recommend this. Please come a say hello, would love to meet you, really looking forward.

azurebootcamp.ch/

Thanks for organizing Manuel Meyer Stefan Johner Stefan Roth

2023-03-17

Hee hee - one of my favorite uses for ChatGPT is asking it to describe topics in the style of a pirate.

"Ye see, as a pirate, the most important thing is to make sure we trust the person we're dealing with. We don't want no scallywags or imposters stealin' our booty or getting the better of us!"

#chatgpt #infosec #authn #piratetalk #meme

Meme: A photo of a modern sailor dressed as a pirate with a parrot on his shoulder and the caption: "Information Security: Keeping the pirates out of your data."
2023-03-16

Working on a project with non-InfoSec folks I was reminded that not everyone's gotten the message. All the contributors were accessing the collaboration platform with the admin's credentials ('cause it was easier than creating separate accounts). #sigh

#infosec #authn #authz #fail #meme

Meme: Three characters from the 1960s TV show "Hogan's Heroes" facepalming with the caption, "Triple Facepalm: When you realize you shouldn't share passwords."
Everything Open Conferenceeverythingopen@fosstodon.org
2023-03-02

Next in our #EverythingOpen Speaker Spotlight series, because we know you're all #nightowls - is @firstyear William Brown, who's presenting:

"Web #authn, #passkeys and you - the future of #authentication"

2023.everythingopen.au/schedul

2023-02-20

Qqn sait où on peut trouver plus d'info sur le protocole en "double anonymat" que le gouv veut déployer en mars pour restreindre l'accès à certains sites, dont les sites porno ?
J'ai vu un schéma et moralement, ça ressemble a du "sous-privacy pass", mais je voudrais bien étudier la spec ou le code.

#cryptography #france #pornography #privacypass #sécurité #security #authz #authn

damienboddamienbod
2023-02-14
Joey de Villa 🪗AccordionGuy@mastodon.cloud
2022-12-23

Here’s my first video chat with ChatGPT about authentication, authorization, and building Android and iOS apps that use Auth0/Okta for login. Does ChatGPT gets the answers right? Yes for some, categorically NO for others.

ChatGPT did me a solid, though — it wrote the YouTube description of the video for me. Thanks, ChatGPT! 🤖

#ChatGPT #AI #security #cyber #cybersecurity #OAuth #OIDC #authN #authentication #authorization #login

youtube.com/watch?v=rfkgdorO-8

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst