Post #4036931
2026-07-23 02:25 UTC
@TindrasGrove@infosec.exchange Most of us have. We've also internalized a fact from experience: anything _not_ using some form of 2FA will be compromised within a couple of months, and the owner _will not_ be able to recover from it. If you use a public computer make that a week, tops, and likely less than 24 hours. Some forms of 2FA, like SMS or voice call or email, are useless because they're so easy to compromise. The only reliable ones I know of are TOTP or an authenticator app (passkey) on a smartphone, ...
Replies (1)
-
@Epic_Null@infosec.exchange 2026-07-23 13:21
@tknarr@mstdn.social @TindrasGrove@infosec.exchange But if we're talking about registration for an event that is probably at most three weeks away... Why not use a 2fa that can be breached within months? The event will be over by then anyway, so you can just close down that account.