A Lemmy original meme
honestly respect for my compatriots creating OC
It’s like a dj tag on a rap track
deleted by creator
Always download the backup 2fa codes. This is when you need them.
Or buy a yubikey and set it up as a backup MFA on at least your email and password manager, then keep it in a fireproof safe.
While this is good advice, best practice is to always get your yubikey in pairs and keep them synchronized. One should remain in your home, in a safe place (as you described) while the other should remain on your person or outside the home (e.g. in a safe deposit box)
It’s more of a pain in the ass for sure, but handles the theft scenario more effectively
Have Android phone
Don’t bother signing into your Google account
Download Canta, Shizuku and f-droid apk and install
Use canta to uninstall every Google app that isn’t strictly required
Chrome, Gmail, Drive
Weather, Launcher, News
Clock, Keyboard, even the damn Calculator
Everything. Canta actually tells you what is and isn’t safe
Replace everything with open source alternatives as you go (don’t forget about a keyboard alternative)
Get APKUpdater to install and update apps that aren’t on f-droid from various sources you can choose
Have hastily degoogled Android phone
Do you not back up your 2FA when you set them up?
People should need to take a test before they can be on the internet.
I’ve never set up 2FA on my google accounts, but knew someone who this happened to which is why I was hesitant to set it up on my own accounts. Didn’t know backing up 2fa was a thing.
This. So many times. OMG!
I was always annoyed with MFA because i didnt like needing multiple devices or applications just to log into one shitty website. Now i have my TOTP stuff stored in keepassxc so it just autofills with zero hassle :)
Its not very “multi” anymore, so its a bit less secure but much easier to use.
I suppose that you could have a separate database for your TOTP secrets, but I think that the autofill already helps with spotting phishing, which I believe is a good trade. If my autofill doesn’t work all of a sudden, I might check the domain name again.
The lion has joined the botnet.
Why doesn’t the bigger app that needs authentication not just eat the smaller app?
Only 8 factor authentication is secure enough.
a memmy original leme
The mastodonian doesn’t concern himself with tls. Unfortunately based on a true story.