d3ad social login

[d3ad]

tags labelled 'authentication' e

please login to post
@barray on Sat Feb 19 12:43:44 UTC 2022 said: &e
Very interesting #authentication #method using pure #http without #cookies or #javascript ! https://saucecode.bar/posts/06-using-www.. Even #deadsocial uses a single #cookie ! I will need to check it out, but this is potentially extremely cool!
@barray on Sun Feb 13 12:46:21 UTC 2022 said: &e
So, apparently #twofactor #authentication , not only has allowed #youtube #creators to be #hacked by #social #engineering their #phonenumber from #providers , not only has it #locked people out of their #accounts because they lost their #phone , but now it also allows people to be #tracked ! https://politictech.wordpress.com/2022/0.. And this isn't to mention the number of people who *don't* have a #smartphone !
@barray on Wed Nov 24 02:45:29 UTC 2021 said: &e
A great piece of #satire on #multifactor #authentication https://www.mcsweeneys.net/articles/the-.. Damn! We are really not that far from this #future at all...
@barray on Sun Nov 07 05:18:23 UTC 2021 said: &e
Well, this is potentially the thing that gets me to stop using my #google #account entirely: https://trustcoyote.com/blog/2-step-veri.. #twofactor #authentication only serves to #track you and de- #anonymise you. The " #security " it offers has been *repeatedly* #abused - because #simcards and #phonenumbers are *not* within your control and can be arbitrarily re- #assigned ... They make incorrect assumptions about #security because in their little #bubble they all have #contracts
@barray on Mon Aug 23 02:09:09 UTC 2021 said: &e
Very interesting #pam #authentication #security #modification where there is a fake #password to run an additional command: https://github.com/nuvious/pam-duress People are pointing out that it could be useful for forced search scenarios, especially useful if you can #recover from #backup ! I believe that during these times you must also consider the point that your #drive could be #cloned and the #virtual #drive pulled at the right time to prevent anything being written.
@barray on Wed Jun 30 05:15:43 UTC 2021 said: &e
A very big ouch for #westerndigital - they commented out #code that checked the #authentication and this was in turn abused by #hackers to perform the mass wiping attack! https://arstechnica.com/gadgets/2021/06/.. This is why we should all hate #php anyway - it is insanely easy for something like this to happen.