@jerry@infosec.exchange hi Jerry. i vaguely recall a post of yours from several weeks / maybe some months? ago, where you said you were going to introduce mandatory
#TOTP /
#2FA for accounts. that alarmed me coz i do not have any TOTP facility atm, & tbh know nothing about this tech at all. as i largely use
#sharkey rather than masto for my daily fediversing these days, i shoved this into the too hard basket, & forgot about it.
today though i chanced across discovering that my long-term password manager,
#keepassxc, also includes a TOTP capability. i've now begun investigating it, though atm i still don't really understand it. this reminded me of that recent? post of yours, so i thought maybe i'd use my masto account for my first TOTP guinea pig. i fell at the first hurdle. the masto settings section for 2FA says: Two-factor Auth
If you enable two-factor authentication using an authenticator app, logging in will require you to be in possession of your phone, which will generate tokens for you to enter.i do not use my phone for anything other than calls + sms. i have no intention to change from using my linux pc for my fediversing & all other interwebzing, to my phone. does this mean then that my infosec.space account is doomed? eg, next time i log out, for whatever reason, i'll no longer be able to log back in, if you have activated mandatory 2FA, & i don't have it?
i'd really hoped that belatedly discovering kpxc [on my linux desktop] has totp might be my solution, but now i'm only more confused. thx.