Elektrine lite

← Feed

@DaveMWilburn@infosec.exchange

Post #4060483

2026-07-24 10:33 UTC

@Viss@mastodon.social @scottwilson@infosec.exchange Just make darned sure that whatever 2FA they use has a backup. Some TOTP apps are better than others at this, but they all need to be paired with some sort of online cloud backup, and the key for that needs to be secured somewhere they can find it. Some TOTP apps will randomly fuck you over. Same with passkeys. If they're going to be stored on yubikeys then you're gonna wanna make sure they have all their accounts provisioned on at least two passkeys, one on their keychain and one backup kept in a safe of some sort. Honestly it's these backup requirements and UX gotchas that make me hesitant about recommending 2FA to a lot of folks. Otherwise they're more likely to be harmed by losing their access everywhere than by getting phished.

Replies (1)

  • @DaveMWilburn@infosec.exchange @Viss@mastodon.social Thank you, Dave. Good advice! This org is a Microslop shop so we have Authenticator which presumably backs up to the cloud. And I’m afraid YubiKeys are a bridge too far (except for the Admins). The users I’m dealing with can’t handle re-entering a password to access email on their phones. Very challenging.

    Open ##4061819