Now mastodon has started a bullshit where if I login with a web browser it sends security code to my email address! And there's no way to disable this!
Conversation
Notices
-
Abhiseck Paira :gnu: :gnuhurd: (redstarfish@social.linux.pizza)'s status on Tuesday, 23-Nov-2021 09:21:49 UTC Abhiseck Paira :gnu: :gnuhurd: -
Wandelstock :mastodon: (wandelstock@mastodon.art)'s status on Tuesday, 23-Nov-2021 09:21:34 UTC Wandelstock :mastodon: Maybe switch on 2fa and use an open source authenticator?
Its a small step, but a good one. I use 2fa as much as i can and installed aegis (android) on all my devices.
-
:debian: 𝚜𝚎𝚕𝚎𝚊 :fedora: (selea@social.linux.pizza)'s status on Tuesday, 23-Nov-2021 09:21:35 UTC :debian: 𝚜𝚎𝚕𝚎𝚊 :fedora: Sadly, I cant disable this either for individual users that really need it disabled.
But well, I do think that it is a good thing that people start using 2FA.But it wont make mastodon more popular
-
Tagomago (tagomago@mastodon.social)'s status on Tuesday, 23-Nov-2021 09:21:59 UTC Tagomago @WandelStock @selea @redstarfish What I do. Use KeePassXC or any other TOTP generator and you're done.
-
Tagomago (tagomago@mastodon.social)'s status on Tuesday, 23-Nov-2021 09:51:04 UTC Tagomago @WandelStock @selea @redstarfish How is that?
-
Wandelstock :mastodon: (wandelstock@mastodon.art)'s status on Tuesday, 23-Nov-2021 09:51:05 UTC Wandelstock :mastodon: Exactly. There are password managers with 2fa but that is unsafe
-
sexybiggetje (sexybiggetje@mastodon.social)'s status on Tuesday, 23-Nov-2021 10:22:34 UTC sexybiggetje @tagomago
Because you potentionally store your 2FA code with your password. That makes it essentially a single point of failure. -
Tagomago (tagomago@mastodon.social)'s status on Tuesday, 23-Nov-2021 10:25:06 UTC Tagomago @sexybiggetje @WandelStock @selea @redstarfish
You mean the TOTP seed?
-
Tagomago (tagomago@mastodon.social)'s status on Tuesday, 23-Nov-2021 10:45:01 UTC Tagomago @WandelStock @sexybiggetje @selea @redstarfish Oh yes, now I get it.
-
Wandelstock :mastodon: (wandelstock@mastodon.art)'s status on Tuesday, 23-Nov-2021 10:45:03 UTC Wandelstock :mastodon: @tagomago @sexybiggetje @selea @redstarfish
Some password managers store next to a password also the 2fa, so you can logon with one programm. But because you store 2 ways of identifying in one app you lose the advantage of a second authentication, so it is useless. Best way is to use 2 seperate apps
-