• Gork@lemm.ee
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    Why doesn’t the bigger app that needs authentication not just eat the smaller app?

  • unexposedhazard@discuss.tchncs.de
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    2 months ago

    I was always annoyed with MFA because i didnt like needing multiple devices or applications just to log into one shitty website. Now i have my TOTP stuff stored in keepassxc so it just autofills with zero hassle :)

    Its not very “multi” anymore, so its a bit less secure but much easier to use.

      • jj4211@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        2 months ago

        Realistically speaking, MFA most importantly is to get away from the “something you know” factor since that is generally more vulnerable. Even if it is a single factor, it’s a better factor.

        Also enables people to meaningfully have multiple factors if they choose. The password managers generally require a master passphrase and/or unlocking through something like “Windows Hello”

      • unexposedhazard@discuss.tchncs.de
        link
        fedilink
        arrow-up
        0
        ·
        2 months ago

        Yeah basically, but MFA is honestly not that needed if you use a password manager, secure passwords and URL based autofill. MFA was invented to protect plebs that use bad passwords and easily fall for phishing sites.

        • stonedtemplepilot@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          2 months ago

          It’s still good practice even if your password is secure. That way bad actors would still need your MFA code if your data ever gets leaked or stolen.

          • unexposedhazard@discuss.tchncs.de
            link
            fedilink
            arrow-up
            0
            ·
            2 months ago

            Yeah but in that sense my method still fulfills that requirement. They would need to actually get access to my locally stored kdbx file and my master key. If they get that then everything is fucked anyways.

    • RobotZap10000@feddit.nl
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      I suppose that you could have a separate database for your TOTP secrets, but I think that the autofill already helps with spotting phishing, which I believe is a good trade. If my autofill doesn’t work all of a sudden, I might check the domain name again.

  • Nyadia (she/they)@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    2 months ago

    Have Android phone

    Requires Google account to use

    Enable 2FA on Google account

    2FA requires me to have access to my phone

    Phone dies

    Get new phone

    Must sign in to Google account to set up new phone

    Need access to old phone to set up new phone

        • neatchee@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          2 months ago

          While this is good advice, best practice is to always get your yubikey in pairs and keep them synchronized. One should remain in your home, in a safe place (as you described) while the other should remain on your person or outside the home (e.g. in a safe deposit box)

          It’s more of a pain in the ass for sure, but handles the theft scenario more effectively

    • Venus_Ziegenfalle@feddit.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Have Android phone

      Don’t bother signing into your Google account

      Download Canta, Shizuku and f-droid apk and install

      Use canta to uninstall every Google app that isn’t strictly required

      Chrome, Gmail, Drive

      Weather, Launcher, News

      Clock, Keyboard, even the damn Calculator

      Everything. Canta actually tells you what is and isn’t safe

      Replace everything with open source alternatives as you go (don’t forget about a keyboard alternative)

      Get APKUpdater to install and update apps that aren’t on f-droid from various sources you can choose

      Have hastily degoogled Android phone

    • hansolo@lemm.ee
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Do you not back up your 2FA when you set them up?

      People should need to take a test before they can be on the internet.

      • Nyadia (she/they)@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        I’ve never set up 2FA on my google accounts, but knew someone who this happened to which is why I was hesitant to set it up on my own accounts. Didn’t know backing up 2fa was a thing.