#multifactor

Donald Roydjr2024
2025-06-01

@ChrisMayLA6

There is a view that in the is actually quite high by international standards - and that the real problem is one of factor proportions - too little as against in particular. To which the answer would be either to attract in or for the to find the itself. One form of suggests that the latter strategy would work well. Interpreting fiscal rules to enable it would make sense!

2025-05-14

Is MFA authenticator anxiety a thing? Is there a name for it?

I always have enough time when I open the authenticator app and put in the code before it times out, but I still get nervous that I will run out of time before the new number appears.

Is there a name for that type of feeling?

#mfa #multifactorauthentication #infosec #multifactor

So I've been trying to figure out the answer to a theoretical problem: what would I do if I was in a foreign country and had my phone and laptop seized / stolen?

I'm not too concerned about the shit on them, but nowadays everything is 2FA. Even my password manager needs second factor auth on a new device, and the second factor is email which... You guessed it needs a second factor. I feel like I'm one lost device from disaster.

How do you go from zero to re-equipped with your logins without access to your own desk and devices?

Would it be insane to post an encrypted binary blob in like a public git repo? Random webpage? What encryption would be sufficient to confidentiality drop an entire password vault, ssh keys, etc into a public space?

(Encryption not my area of expertise)

#2fa #encryption #passwords #keyvault #multifactor #backups #cybersecurity

2024-12-26

Happy β€œGot a New Phone And Spent 90 Minutes Reconfiguring MFA Across 14 Different Platforms day” to those who celebrate!

#mfa #2fa #multifactor

fsniperfsniper
2024-07-14

please tell me I am not the only one reading MFA as Moda-F-Admin every time I see it

Big companies like Santander and Ticketmaster compromised through Snowflake environment breach. cybertalk.org/snowflakes-infos

2024-04-16

Cisco Duo's #multifactor authentication service has been breached: A third-party telephony service provider for Cisco Duo falls prey to social engineering, and the company advises customer vigilance against subsequent phishing attacksβ˜οΈπŸ‘©β€πŸ’» #breach

darkreading.com/cyberattacks-d

2024-03-08

Unveiling the Multifactor Authentication Market: Securing Tomorrow's Digital Landscape 2024 2032

Unveiling the Multifactor Authentication Market: Securing... #multifactor #authentication #market #securing #tomorrow #digital #landscape

sanglobalresearch.com/report/m

2024-02-26

Yet another quick rant about passwords....

The password is such a poor security measure that nearly all accepted and enforced standards state to use a second authentication factor that is NOT a standard. Stop yelling about SMS as a poor second factor unless you also yell about the FIRST factor. Think about it. Kill the password. Hardware tokens coupled with a biometric - two great authentication factors we all accept now, way better than SMS which is way better than the password.

If you're going to argue, bitch, and complain about which non-password authentication methods are best, great. Let's just agree to kill the password

#infosec #multifactor #KillThePassword

2024-02-23

Настройка Π΄Π²ΡƒΡ…Ρ„Π°ΠΊΡ‚ΠΎΡ€Π½ΠΎΠΉ Π°ΡƒΡ‚Π΅Π½Ρ‚ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΠΈ ΠΏΠΎ VPN. ΠšΠΎΠ½Ρ‚ΠΈΠ½Π΅Π½Ρ‚ 4 β€” MultiFactor

ВозмоТности Π·Π»ΠΎΡƒΠΌΡ‹ΡˆΠ»Π΅Π½Π½ΠΈΠΊΠΎΠ² растут ΠΈ ΡƒΠΊΡ€Π°ΡΡ‚ΡŒ ΠΏΠ°Ρ€ΠΎΠ»ΡŒ Π½Π΅ прСдоставляСт слоТности. Одним ΠΈΠ· Π²Π°Ρ€ΠΈΠ°Π½Ρ‚ΠΎΠ² Ρ€Π΅ΡˆΠ΅Π½ΠΈΡ ΠΏΡ€ΠΎΠ±Π»Π΅ΠΌΡ‹ бСзопасности ΠΏΠ°Ρ€ΠΎΠ»Π΅ΠΉ ΠΌΠΎΠΆΠ΅Ρ‚ ΡΠ»ΡƒΠΆΠΈΡ‚ΡŒ систСма ΠΌΠ½ΠΎΠ³ΠΎΡ„Π°ΠΊΡ‚ΠΎΡ€Π½ΠΎΠΉ Π°ΡƒΡ‚Π΅Π½Ρ‚ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΠΈ. Π’ этой ΡΡ‚Π°Ρ‚ΡŒΠ΅ ΠΌΡ‹ ΠΏΠΎΠΊΠ°ΠΆΠ΅ΠΌ, ΠΊΠ°ΠΊ ΠΎΡ€Π³Π°Π½ΠΈΠ·ΠΎΠ²Π°Ρ‚ΡŒ Π΄Π²ΡƒΡ…Ρ„Π°ΠΊΡ‚ΠΎΡ€Π½ΡƒΡŽ Π°ΡƒΡ‚Π΅Π½Ρ‚ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΡŽ ΠΏΡ€ΠΈ ΠΎΡ€Π³Π°Π½ΠΈΠ·Π°Ρ†ΠΈΠΈ ΡƒΠ΄Π°Π»Π΅Π½Π½ΠΎΠ³ΠΎ доступа с ΠΏΠΎΠΌΠΎΡ‰ΡŒΡŽ ΠšΠΎΠ½Ρ‚ΠΈΠ½Π΅Π½Ρ‚ 4 ΠΈ Multifactor.

habr.com/ru/companies/tssoluti

#vpn #multifactor #ΠΊΠΎΠ΄_бСзопасности #аутСнтификация #двухфакторная_аутСнтификация #настройка #настройка_Π°ΡƒΡ‚Π΅Π½Ρ‚ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΠΈ #ΠΊΠΎΠ½Ρ‚ΠΈΠ½Π΅Π½Ρ‚_4

Kevin Dominik Kortekdkorte@fosstodon.org
2023-10-22

One cannot repeat enough that Strong Passwords and Multi-Factor Authentication are the keys to protecting yourself from cyberattacks.
If your favorite service doesn't provide Multi-Factor Authentication in any form, it might be time to switch services (preferably to an Open-Source supporting service provider)
#cybersecurity #multifactor #MFA #cybersecurityawarenessmonth

opendev (closed)opendev@infosec.exchange
2023-04-25

Very strange behavior with #AzureAD, #MultifactorAuthentication and #ActiveDirectory #Migration. Maybe someone has an idea? Any help is much appreciated.

Situation: As usual we sync our #OnPrem ADs (at the moment five of them) with #AAD and use the mS-DS-ConsistencyGuid as the Source Anchor.
Last year we needed to "move" a user from one OnPrem (H) Domain to another (D). We created a new user in Domain H, removed the user in Domain D from the sync, copy/pasted his mS-DS-ConsistencyGuid from Domain D to Domain H and started the sync of the user in Domain H. So the user used the new credentials from Domain H but kept his 365 Data which he generated before with his account from Domain D.
A few weeks before we integrated #Multifactor #Authentication through #Watchguard #Authpoint MFA and activated it for the whole company and every user in every domain. Now as soon as the user changed his password for the first time since the MFA got in place, it was activated for him and the issues began.

Issue: When trying to logging into 365 with Authpoint MFA, the error message explains, that Azure awaits the the #immutableID based on the ObjectGUID of Domain H. But since we copy/pasted the mS-DS-ConsistencyGuid from the old Domain D, this is based on the ObjectGUID from the user of Domain D and so an authentication does not happen. If we change the immutableID to the awaited based on the ms-DS-ConsistencyGuid of Domain H, the user can log into Azure/365, but obviously the sync stops because ms-DS-Cons and immutableID dont match anymore.

So, for one person, that is maybe something you can do very dirty by editing the data in the metaverse, but unfortunately we are running soon a AD migration project where every user will be migrated to another single domain. So for me it seems like we are a few steps away from everything will explode?

Anybody has a hint/idea/solution/anything else? Every help and #boost is welcome and appreciated.

Marcin Paprzyckimarcinpaprzycki@masto.ai
2023-03-09

How can we design #authentication methods that would be efficient and invulnerable to attacks? How would a pattern-based #MultiFactor authentication scheme perform?
Read more in a special issue paper β€œA Pattern-Based Multi-Factor Authentication System” by Pankhuri, Akash Sinha, Gulshan Shrivastava, and Prabhat Kumar published in #SCPE, Vol. 20, No. 1, (ISSN 1895-1767): tinyurl.com/2xepd5db

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst