Showing posts with label 2fa. Show all posts
Showing posts with label 2fa. Show all posts

Monday, February 20, 2023

First World Security Problems

from here and here

This is probably going to be an unpopular opinion in certain circles, but Twitter erecting a barrier in front of the laziest form of 2 factor authentication isn't that big a deal. Not only because there are more secure options that are still free for the people who really need 2FA, but also because the vast majority of people don't really need it. In fact, the vast majority of people aren't even using 2FA right now. 

While it would be good if everyone was using 2FA for things like their bank or their email account, it is a foolish consistency to think we need it for everything.

Monday, October 3, 2022

MULTI FACTOR!

from here and here

I have had enough of these multifactor snakes on this multifactor plane.

Monday, July 4, 2022

But it's "for your security"

from here and here

Twitter and Facebook have both been caught misusing the 2FA details for ad targeting and they are probably not alone.

There are many ways that online sites could have chosen to implement two factor authentication. It stretches credulity to think that they just happened by accident to choose the one that benefits their advertising businesses.

No, I think any security benefits were actually a secondary concern and that's why the online world has settled on a technology that is actually inferior from a security perspective.

Monday, May 30, 2022

No cell phone number for you!

from here and here

Twitter isn't even the first company to get caught misusing security contact information for ad targeting, but at least they're paying the price for misusing our info

Thursday, November 11, 2021

Security for the Horde

from here

WoW has had 2 factor authentication since 2008 (if not earlier). They used a hardware token but have switched to a software token. Banks, meanwhile, were slow to adopt 2FA, and the best you seem to be able to hope for is SMS based authentication.

Monday, May 10, 2021

There better not be any ads after that

from here

While paying for Internet service is a technical requirement for using websites, paying for a phone is not - as evidence I point to all the sites I can currently use without a phone. If Google starts requiring a phone in order to log in then I can't see how to continue calling the service free, regardless of whether the money is going to them (although, considering how many phones are Android, it seems likely they're getting their cut).

Thursday, March 25, 2021

Credential Stuffing: The Dangers of Reusing Passwords Online


Watch on YouTube

A great explainer about account security that was apparently put out as an advertisement. You're not expected to buy anything, though. It seems someone struck on the idea of using the advertising facility at YouTube to expose people to security awareness training, which is actually quite brilliant.

Thursday, April 23, 2020

Bio-mutt-ric authentication

found on Acid Cow

I've heard of smell-o-vision, and even the smell-o-scope, but the smell-o-phone is a new one on me.

Wednesday, March 6, 2019

I be they "take your privacy and security seriously" too

from here

If you follow many InfoSec pros on Twitter you've probably heard of at least one example of this recently, but I gather it's not an isolated incident so I'll refrain from singling a single entity out when many are to blame.

Tuesday, March 5, 2019

Who could have possibly seen that coming?

from here

After the umpteenth privacy controversy, why are we still using Facebook? Oh, right, they automate emotional labour.