hachyderm.io is one of the many independent Mastodon servers you can use to participate in the fediverse.
Hachyderm is a safe space, LGBTQIA+ and BLM, primarily comprised of tech industry professionals world wide. Note that many non-user account types have restrictions - please see our About page.

Administered by:

Server stats:

8.9K
active users

#mfa

11 posts11 participants1 post today

[Перевод] OpenAM и Zero Trust: Подтверждение критичных операций

Один из принципов нулевого доверия гласит: никогда не доверяй, всегда проверяй (Never trust, always verify). В этой статье мы рассмотрим, как реализовать соблюдение такого принципа в системе аутентификации на примере продуктов с открытым исходным кодом OpenAM и OpenIG .

habr.com/ru/articles/905824/

ХабрOpenAM и Zero Trust: Подтверждение критичных операцийВведение Один из принципов нулевого доверия гласит: никогда не доверяй, всегда проверяй (Never trust, always verify). В этой статье мы рассмотрим, как реализовать соблюдение такого принципа в системе...

In questa #newsletter parliamo di:
🔴 #Virale vuol dire ancora qualcosa?
🟠 Buon World #Password Day! Tra #MIT, #Hacker, #Infostealer e #MFA. Perchè sono così vulnerabili
🟢 Perché #Tiktok ha preso una multa da mezzo miliardo in #Europa
🔵 #Meta lancia la sua app #IA personale: un assistente vocale che può fare anche da #social
🟣 #AI, come le #BigTech indeboliscono il codice di buone pratiche europeo

@informatica

bit.ly/3GFpP6w

Da zero a digital · 🚀 Da zero a digital » Newsletter n° 109By Open Genova APS

When using I experience one of these 3 behaviors:

1. Immediately logged in (even if is enabled)
2. I’m prompted for an MFA token
3. I’m only asked for my passkey after I’ve entered some amount of other information. Possibly just and email or phone number or sometimes my full login/password where the passkey is acting as an MFA token.

Would be nice if this was consistent. Feels like rolling UX dice every time.

Someone wants in.
I got a request on my #MFA app when I wasn't logging in, so denied the request. But, if I got an MFA request, that means they have my password.
Gotta love MFA! It saves you from most breached password attacks.
Password is now updated--and longer--so I should be good until the next breach.

#MFAEverything for #Security!