And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
Ideally yes, but let's not let the perfect become the enemy of good. If that's what available right now, it should still be used and recommended.
Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
21–30 of 301 posts
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#22And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#23So many hacks lately, it's hard to believe that it's a coincidence ?
I don't know if you are implying that it's related to the war or something. Sadly, I am more of the belief that it's a trend. I think we will see much more of it.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#24What inelegant phrasing.
Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for your profile, there's no benefit to the user to have an old account with lots of karma. Just keep re-rolling with strong random passwords and you have nothing to lose.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#25And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#26And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…
Nobody should ever suggest you use TOTP or SMS 2fa to prevent phishing.
> 6 years ago "ok but you need to use different passwords on each site"
Really the only one that matters in practise. TOTP is basically just a work around to get users to actually do this.
Edit: i would also add this is a corporate environment where its reasonable to be more picky. And webauth really is the best (only?) Solution to phishing.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#27>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#28And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
Is this similar to how hardware wallets show the true addresses on their displays?
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#29Earlier quoted context omitted.
10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…
This isn't really the way that advice played out: Nobody should ever suggest you use TOTP or SMS 2fa to prevent phishing. > 6 years ago "ok but you need to use different passwords on each site" Really the only one that matters in practise. TOTP is basically just a work around to get users to actually do this. Edit: i would also add this is a corporate environment where its reasonable to be more picky. And webauth rea…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#30Earlier quoted context omitted.
I don't know if you are implying that it's related to the war or something. Sadly, I am more of the belief that it's a trend. I think we will see much more of it.
"to the war", I smeel a singularity. Can you be more specific, to which war exactly are you refering to? https://en.wikipedia.org/wiki/List_of_ongoing_armed_conflict...