this post was submitted on 21 Jan 2024
17 points (100.0% liked)
Cybersecurity
5728 readers
141 users here now
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]
Notable mention to [email protected]
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Ask whether people are happy using the generator app on their phone, and provide phones to anyone who isn't comfortable with using their own device for that.
You'll probably end up with two or three authenticator apps, since some sites want to have their own app instead of using TOTP.
To pile on this, you can point people to public Auth apps that aren't linked to your workplace. This might reduce suspicions about you installing work apps on their phones.
What about using a password manager to store 2FAs for apps and websites and then a security key for the password manager 2FA?
I'm not too happy with this solution. Not extremely bad, but technically, both password and the second factor are stored in the same place, which makes this similar in security to just using a long, random password with a password manager.
This is the way.