Non-repudiation and the joy of knowing you've been hacked
1–10 of 30 posts
Re: Non-repudiation and the joy of knowing you've been hacked
#2Re: Non-repudiation and the joy of knowing you've been hacked
#3Re: Non-repudiation and the joy of knowing you've been hacked
#4Does obtaining the original Google authenticator QR code actually let you impersonate the authenticator? I was hoping it was a one-time shared secret only used for the authenticator to identify itself to the server for bootstrapping purposes and that a used QR code would be worthless.
Send it to the email account that will be protected by two-factor authentication using the key, and it won't really matter.
Re: Non-repudiation and the joy of knowing you've been hacked
#5The idea that a serious compromise will present a clear path back to a specific ssh key that got used by the attackers and that you'll possibly be able to stop it just by turning off that key is pretty laughable. But then again, so is protecting your core infrastructure with 1.5 factor android soft tokens. Google isn't even willing to make it sound like especially strong protection for your gmail account. How much fo…
Re: Non-repudiation and the joy of knowing you've been hacked
#6Re: Non-repudiation and the joy of knowing you've been hacked
#7Is that really common? I've never seen it.
Re: Non-repudiation and the joy of knowing you've been hacked
#8"if your company uses SSH, chances are you have one Unix Login that all your admins/employees share" Is that really common? I've never seen it.
Re: Non-repudiation and the joy of knowing you've been hacked
#9"if your company uses SSH, chances are you have one Unix Login that all your admins/employees share" Is that really common? I've never seen it.
Re: Non-repudiation and the joy of knowing you've been hacked
#10"if your company uses SSH, chances are you have one Unix Login that all your admins/employees share" Is that really common? I've never seen it.