#mfa

17 posts · Last used 9d

Back to Timeline
Droppie [farcebk] 🐨♀🌈🐧​🦘 @msdropbear42@farcebook.space · Aug 06, 2026
my: bankcredit card ex company1credit card ex company2superannuationmobile phone vendornbn broadband vendor do not use / support #2FA via #MFA #TOTP, & i am tearing my hair out in exasperation at these damn troglodytes. I've even just wasted a coupla hours dealing with my mobile phone vendor who overnight sent out an email that delighted me as it recommended customers setting up our online accounts with them using [direct quote from the fucken email]... MFA is a security method that requires you to prove your identity in two or more different ways, like an additional verification step as part of your login. This might include facial recognition, a dedicated authenticator app, or a unique code sent to your preferred contact method. ...only to eventually find that part of the email is bullshit. jfc, most of these are major companies, some indeed are multi-nationals, yet they still treat security as a joke. utter fuckheads! aaaaaaand yet seemingly not a week goes by without companies getting hacked & thus fucking over their customers 😡🖕
0
0
0
dilshad @dilshad@infosec.exchange · Jul 31, 2026
Zero to owned: Credential stealer to corporate breach The breach doesn't start with your infrastructure. It starts on a device you don't control. One dataset of 15 million infostealer logs held 687 million cookies, 43.87 million of them still active session tokens that hand over an account without ever tripping MFA. Your second factor doesn't matter if the attacker inherits the session. https://darkwiser.com/blog/zero-to-owned-mapping-the-lifecycle-of-a-credential-stealer-to-corporate-breach #Infostealer #SessionHijacking #MFA #CredentialTheft #dark_web
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 25, 2026
🤖 Hackers are tampering with DNS settings on hotel/conference Wi-Fi equipment to redirect guests to fake Microsoft 365 login pages. The attack captures authentication tokens, enabling account takeover without bypassing MFA. 🔗 https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/ #CyberSec #Phishing #DNS #MFA #InfoSec
0
0
0
Scott Wilson 🌈 @scottwilson@infosec.exchange · Jul 24, 2026
Friends, I need some help and advice. Microsoft recently announced retirement of Microsoft-provided SMS and voice authentication in Entra ID. Of course, "good", you say -- me, too. But I'm working with an organization that has some extremely non-techie employees, and I've got to figure out the easiest path to help them get properly on-boarded with Passkeys. Microsoft Authenticator seems to support Passkeys natively (the key is stored IN MS Authenticator). Is this the best way to do this? My non-techie users are primarily mobile phone users on Exchange Plan 1 (no "fat" client). Help! #passkeys #webauthn #fido #microsoft #mfa #lazyweb #help References: https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/ https://mc.merill.net/message/MC1426371
0
0
0
Michael Gale @miclgael@hachyderm.io · Jun 16, 2026
I don't like #Passkeys over #Passphrase and #MFA (edit: specifically, rotating pin codes via a password manager or dedicated auth app) Am I wrong? or is it the children who are wrong. #Security #Privacy
10
1
3
CoreLabJoe @CoreLabJoe@piefed.ca · Jul 07, 2026

How to Setup Authelia in Docker with SWAG Reverse Proxy (2026)

How Authelia Performs Multi-Factor Authentication Authelia sits between your reverse proxy and the apps behind it, intercepting requests and performing auth checks before forwarding traffic, giving you true MFA that can be integrated with something like Google Authenticator, or Yubikey/Titan key, etc… Stop exposing unsecured apps. Learn how to deploy Authelia in Docker with a KeyDB backend and SWAG to enforce centralized Multi-Factor Authentication. Setting up Authelia can be a bit intensive at first, but very worth the payoff / time and effort! Disclaimers: I’m the author & run this exact setup, in production for myself. It’s a “battle tested” setup, which has been in use for a few years now. Written & verified by a human! The header image is a composite of my Authelia MFA token page & AI generated infographic. NO ADS or affiliate marketing on page! Happy to chat in the comments!
49
13
0
IAMDevBox @iamdevbox@mastodon.social · Jul 13, 2026
Explore how to implement robust multi-factor authentication using TOTP and WebAuthn to enhance your application's security. https://iamdevbox.com/posts/building-multi-factor-authentication-with-totp-and-webauthn/?utm_source=mastodon&utm_medium=social&utm_campaign=blog_post #security #mfa #totp #webauthn
0
0
0
Dendrobatus Azureus @Dendrobatus_Azureus@mastodon.bsd.cafe · Jul 12, 2026
This is the warning message I get for the MFA 2FA multi-factor authentication parameters for the freeBSD forum. Is there anyone here who can tell me where I can post this so that they can look into the issue? @stefano@mastodon.bsd.cafe Please boost for visibility #freeBSD #BSD #MFA #2FA #InfoSec #weak #cryptography #cipher #programming #OpenSource #forum
0
0
0
Paul - Antifa. LGBTQ+ safe. @paulk@writing.exchange · Jul 06, 2026
Interesting when a company offers an option to enter an MFA/2FA access code on the login page, while it's not possible to set up an MFA token in their account system. (They're perhaps still working on that.) #MFA
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 03, 2026
🤖 ConsentFix & ClickFix: OAuth attacks steal Microsoft 365 tokens in seconds. Fake login prompts trick users into granting consent — attacker gets a valid token bypassing MFA, including Microsoft Authenticator. 🔗 https://www.bleepingcomputer.com/news/security/consentfix-and-clickfix-how-microsoft-365-accounts-are-hijacked-in-3-seconds/ #CyberSec #OAuth #MFA #Phishing
0
0
0
Benjamin Schieder @blindcoder@www.bizzfed.de · Jul 02, 2026
Got an email today from a customer who can't log in with their TOTP code. Turns out they scanned the example QR code on the help page instead of following the instructions to get their own QR code. Learn a new way customers act every day. #IAM #CIAM #TOTP #MFA
0
0
0
Hausarzt Praxis Hettstadt @Hausarzt_Hettstadt@sueden.social · Jun 27, 2026
Wir suchen Verstärkung für unser Team. Wir suchen sowohl eine schon ausgebildete MFA als auch bieten wir eine Ausbildungsstelle zur medizinischen Fachangestellten. Bei Interesse einfach per Mail melden. #ausbildung #mfa #hausarzt #allgemeinmedizin
0
0
0
C++ Wage Slave @CppGuy@infosec.space · Jun 27, 2026
Replying to @ryanl@twit.social
@ryanl@twit.social @kris@whereismysupersuit.com @fifonetworks@infosec.exchange #MFA is a good layer in your defence, but people can be tricked into giving one-time passwords away. This trickery takes time (which increases the cost to the scammer) and it often fails, so MFA still has significant value.
0
0
0
Erik van Straten @ErikvanStraten@todon.nl · Jun 03, 2026
Replying to on infosec.exchange
@sophieschmieg@infosec.exchange : *if* the second factor consist of 6 digits and regularly changes (TOTP: usually every thirty seconds), then it is typically worse than 1 in a million chance. Because the client clock may be out of sync with the server clock, typically a time window larger than 30 seconds is used to increase fault tolerance. I suggest you read https://www.oasis.security/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass I remembered that attack, but Pouyan (@i@toot.pouyan.net) had already referenced "AuthQuake" in an earlier toot (https://toot.pouyan.net/notice/B6xuBX6lzrGenpC74y) - but you may have missed that. W.r.t. 2FA: if the server, after entering the user-ID and an incorrect password, responds with "wrong userID or password" - before asking for the 2FA code (or a timing difference reveals that the first factor is either wrong or correct), then the attacker's life gets a lot easier. And if 2FA is reduced to 1FA in "device code" phishing attacks, even passkeys and FIDO2 hardware keys will not prevent account takeovers. Also "password reset" mechanisms may have flaws (upto Instagram's AI assistent being easily convinced by fraudsters). @dangoodin@infosec.exchange @cibyr@omg.wtf.sh #TOTP #TimeWindow #RFC6238 #2FA #Weak2FA #MFA #WeakMFA #BruteForce
0
0
0
BrianKrebs @briankrebs__dup_6@infosec.exchange · Feb 23, 2026
A slick new phishing-as-a-service offering demonstrates just how easily a username+password and a one-time token can be phished. Dubbed "Starkiller," the service uses cleverly disguised links to load the target brand's real website, and then acts as a relay between the victim and the legitimate site -- forwarding the victim's username, password and multi-factor authentication code to the legitimate site and returning its responses. https://krebsonsecurity.com/2026/02/starkiller-phishing-service-proxies-real-login-pages-mfa/ #phishing #MFA #starkiller
102
12
108

You've seen all posts