#2fa

22 posts · Last used 8d

Back to Timeline
James @james@expressional.social · Aug 06, 2026

I noticed that signing in to Mastodon using 2FA didn't reliably work. Turns out my system clock was ~30 seconds behind that of the actual time (currently GMT +1 for me).

On Linux distributions that have systemd, systemd apparently synchronises your system time with a time server automatically. However, I use Devuan (i.e. Debian but without systemd) so I had to do it manually.

I used htpdate to set the time to a UK time server on pool.ntp.org like this:

sudo htpdate uk.pool.ntp.org

No need to reboot. It's now accurate to GMT+1 to within about half a second. :)

Hashtags: #Devuan #time #system #Linux #2FA #systemd #Debian

0
0
0
Droppie [farcebk] 🐨♀🌈🐧​🦘 @msdropbear42@farcebook.space · Aug 06, 2026
my: bankcredit card ex company1credit card ex company2superannuationmobile phone vendornbn broadband vendor do not use / support #2FA via #MFA #TOTP, & i am tearing my hair out in exasperation at these damn troglodytes. I've even just wasted a coupla hours dealing with my mobile phone vendor who overnight sent out an email that delighted me as it recommended customers setting up our online accounts with them using [direct quote from the fucken email]... MFA is a security method that requires you to prove your identity in two or more different ways, like an additional verification step as part of your login. This might include facial recognition, a dedicated authenticator app, or a unique code sent to your preferred contact method. ...only to eventually find that part of the email is bullshit. jfc, most of these are major companies, some indeed are multi-nationals, yet they still treat security as a joke. utter fuckheads! aaaaaaand yet seemingly not a week goes by without companies getting hacked & thus fucking over their customers 😡🖕
0
0
0
Netzblockierer @Netzblockierer@tech.lgbt · Jul 25, 2026
Replying to @Mae@is.badat.dev
@Mae@is.badat.dev so can I finally mandate PGP-based 2FA (like on dread)? Cuz I won't install a garbage app that won't run on my devices anyway and I won't have TOTP / HOTP available all the time… #PGO #2FA #App #Enshittification #OTP #TOTP #HOTP
0
0
0
Andreas Schmidt @asarts@mastodon.social · Jul 24, 2026
Die neue #TOTP Funktion in #ruccuDB 0.0.3 wirkt für eine Daten Engine auf den ersten Blick vielleicht ungewöhnlich. Gerade darin liegt aber ihr Vorteil: TOTP Secrets werden nahtlos in der Engine verwaltet und verschlüsselt gespeichert. Anwendungen, Plugins oder andere Konsumenten können dadurch ohne eigene Kryptografie eine #2fa Lösung auf Basis von RuccuDB in PHP integrieren. #dev #coding #development
0
0
0
Security Crawler Carl @security_crawler_carl@infosec.exchange · Jul 24, 2026
Replying to @security_crawler_carl@infosec.exchange
CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not. Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot. Reward: You've received a hollow Authenticator Token — pre-drained. #ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)
0
0
0
Sean @seanm@infosec.exchange · Jul 23, 2026
Replying to @tychotithonus@infosec.exchange
@tychotithonus@infosec.exchange speaking of Yubico, it looks like they finally released firmware 5.8. I'm not sure how I feel about all of the GenAI "features" they added. https://www.yubico.com/blog/beyond-the-login-top-3-things-developers-need-to-know-about-yubikey-5-8/ #Yubico #Yubikey #CTAP #2FA #SecurityKey
1
1
0
Droppie @MsDropbear42@blahaj.zone · Jul 19, 2026
@disroot@nixnet.social @disroot@social.weho.st hello, can you pls tell me if #disroot #webmail login can be protected by using #2FA #TOTP?
0
1
1
OffSequence @offseq@infosec.exchange · Jul 17, 2026
CVE-2026-62232 (CRITICAL): getgrav Grav <2.0.4 has a 2FA bypass flaw — attackers knowing a user's password can overwrite the 2FA secret, reducing protection to password-only. Monitor & restrict access. Patch status pending. https://radar.offseq.com/threat/cve-2026-62232-missing-authorization-in-getgrav-gr-604d58721f0c378d #OffSeq #CVE202662232 #2FA #infosec
0
0
0
Droppie @MsDropbear42@blahaj.zone · Jul 14, 2026
@jerry@infosec.exchange hi Jerry. i vaguely recall a post of yours from several weeks / maybe some months? ago, where you said you were going to introduce mandatory #TOTP / #2FA for accounts. that alarmed me coz i do not have any TOTP facility atm, & tbh know nothing about this tech at all. as i largely use #sharkey rather than masto for my daily fediversing these days, i shoved this into the too hard basket, & forgot about it. today though i chanced across discovering that my long-term password manager, #keepassxc, also includes a TOTP capability. i've now begun investigating it, though atm i still don't really understand it. this reminded me of that recent? post of yours, so i thought maybe i'd use my masto account for my first TOTP guinea pig. i fell at the first hurdle. the masto settings section for 2FA says: Two-factor Auth If you enable two-factor authentication using an authenticator app, logging in will require you to be in possession of your phone, which will generate tokens for you to enter.i do not use my phone for anything other than calls + sms. i have no intention to change from using my linux pc for my fediversing & all other interwebzing, to my phone. does this mean then that my infosec.space account is doomed? eg, next time i log out, for whatever reason, i'll no longer be able to log back in, if you have activated mandatory 2FA, & i don't have it? i'd really hoped that belatedly discovering kpxc [on my linux desktop] has totp might be my solution, but now i'm only more confused. thx.
0
1
1
Hannah Grace @hpod16@eupolicy.social · Jul 14, 2026

What's your favourite authenticator app? #2FA #OpenSource #authenticator #apps #EULogin #MicrosoftAuthenticator #Google #Microsoft

Microsoft Authenticator
2.6% (8)
Google Authenticator
4.8% (15)
EU Login
1.9% (6)
Other
90.7% (284)
313 votes Poll closed
View on eupolicy.social
0
0
25
Dendrobatus Azureus @Dendrobatus_Azureus@mastodon.bsd.cafe · Jul 12, 2026
This is the warning message I get for the MFA 2FA multi-factor authentication parameters for the freeBSD forum. Is there anyone here who can tell me where I can post this so that they can look into the issue? @stefano@mastodon.bsd.cafe Please boost for visibility #freeBSD #BSD #MFA #2FA #InfoSec #weak #cryptography #cipher #programming #OpenSource #forum
0
0
0
Goose was not valued :goose: @dusk@todon.eu · Jul 08, 2026
#theOnion does not miss. ❝There’s likely a link here between most Americans only getting 20 or 30 minutes of sleep each night and the amount of their lives now given over to frantically pressing ‘Resend’ after they fail to receive a particular code, then receiving far too many codes and being unable to figure out which one is still valid. Unfortunately, it seems this problem is only getting worse.❞ https://theonion.com/study-97-of-average-americans-day-spent-retrieving-6-digit-codes/ #humor #satire #2FA
10
0
8
Ralf Bergs @r@ruhr.social · Jul 07, 2026
#AirPlus bietet als erste Bank, mit der ich eine Geschäftsbeziehung unterhalte (und ich bin Kunde bei mehreren Dutzend Banken!), #TOTP und sogar #Passkeys. Das ist sehr, sehr lobenswert #Sicherheit #ITSicherheit #2FA #TFA. Ich frage mich, wieso andere Banken das nicht auch machen? (Passkeys allerdings scheinen zurzeit "defekt" zu sein, beim Versuch einen #Passkey zu registrieren, werde ich ausgeloggt...)
0
0
0
Debacle @debacle@framapiaf.org · Jul 07, 2026
Has someone #TOTP one their #SensorWatchPro? Does it work well? I think about adding that #complication and reflash… I'm also on the #openHardware chat: xmpp:openhardware@conference.magicbroccoli.de?join #SensorWatch #2FA #watchMaking #dumbWatch #smartWatch #freeSoftware #chronometry #horology #question #help #lazyverse
0
0
1
nextredblog :unverified: @nextredblog@mastodon.uno · Jul 03, 2026

🐀🛡️ Cybersicurezza in pillole — Password deboli, porta aperta

🐀🛡️ Cybersicurezza in pillole — Password deboli, porta aperta Una password semplice è un invito per gli attaccanti. • Usa password lunghe e uniche • Non riutilizzarle su più servizi • Attiva l'autenticazione a due fattori (2FA) • Affidati a un gestore di password 🔒 Una password robusta protegge i tuoi dati. Una debole può compromettere tutta la tua vita digitale. @sicurezza #Cybersecurity #Password #2FA #Privacy #NextRed
0
1
10
Katzenschrat @katzenjens@social.tchncs.de · Jun 18, 2026
Nachdem ich meine paar Repos von Github exportiert und auf meinen eigenen #Forgejo gepackt habe, ist auch direkt mein #PICOTOTP Projekt dort gelandet. Als eine lange Beschreibung inkl. Code war es doch etwas unhandlich in meiner Loseblatt-Sammlung. Hier findet sich die aufgeräumte Version: https://git.j62.de/katzenjens/picototp #basteln #raspberry #pico #2fa #totp
7
1
2
Martin Steiger 🦋 @martinsteiger.ch@bsky.brid.gy · Jun 08, 2026
Bei #Microsoft ist Schluss mit #2FA per #SMS! ✋🏻 ➡️ Wieso verzichtet Microsoft auf SMS für die Zwei-Faktor-Authentifizierung (2FA)? ➡️ Was taugen die Alternativen #TOTP und #Passkeys? ➡️ Wie geht es weiter bei Microsoft mit 2FA? Jetzt reinhören! 🎧 podcast.datenschutzpartner.ch/404-microsof... DAT404 Microsoft verzichtet au...
0
0
0
Erik van Straten @ErikvanStraten@todon.nl · Jun 03, 2026
Replying to on infosec.exchange
@sophieschmieg@infosec.exchange : *if* the second factor consist of 6 digits and regularly changes (TOTP: usually every thirty seconds), then it is typically worse than 1 in a million chance. Because the client clock may be out of sync with the server clock, typically a time window larger than 30 seconds is used to increase fault tolerance. I suggest you read https://www.oasis.security/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass I remembered that attack, but Pouyan (@i@toot.pouyan.net) had already referenced "AuthQuake" in an earlier toot (https://toot.pouyan.net/notice/B6xuBX6lzrGenpC74y) - but you may have missed that. W.r.t. 2FA: if the server, after entering the user-ID and an incorrect password, responds with "wrong userID or password" - before asking for the 2FA code (or a timing difference reveals that the first factor is either wrong or correct), then the attacker's life gets a lot easier. And if 2FA is reduced to 1FA in "device code" phishing attacks, even passkeys and FIDO2 hardware keys will not prevent account takeovers. Also "password reset" mechanisms may have flaws (upto Instagram's AI assistent being easily convinced by fraudsters). @dangoodin@infosec.exchange @cibyr@omg.wtf.sh #TOTP #TimeWindow #RFC6238 #2FA #Weak2FA #MFA #WeakMFA #BruteForce
0
0
0
Yesterday's Rose @umbraroze@tech.lgbt · Jun 01, 2026
#EpicGames Store: Me: "I've set up both #TOTP #2FA and email 2FA, right?" Epic: "Yep" Me: "And I've specified that I should use TOTP as the primary 2FA option, right?" Epic: "Yep" Me: "Oh goodie. Email is far less preferable, I'm glad this is a modern service and uses TOTP." Epic: "Glad we agree" Me: "Okay, let's do this. Go." Epic: "Sending email for 2FA" Me: "What" [Email lands in spam, too] Me: "What the shit" #videogames #security
0
0
0