thomasdankara [he/him]

  • 0 Posts
  • 4 Comments
Joined 4 years ago
cake
Cake day: July 25th, 2020

help-circle

  • Good post, @fuschiaRuler

    I’d also add that Text-based MFA is insecure. What’s more recommended is TOTP, where you scan a barcode with an app like Authy or Google Authenticator on your phone and then it provides codes to you that you enter in the website. What’s most recommended is hardware based 2FA with a physical token like a yubikey, but this isn’t widely supported yet and requires the purchase of a specific device.

    Everyone (I repeat, EVERYONE) should be using a password manager. Password reuse is a serious problem, and everyone’s guilty of it to some degree - but you need to work hard to make sure you can prevent password compromise. I know it’s annoying, and I know you don’t want to do it, but trust me: it’s worth it. Once you have it set up it can make your life easier by typing in passwords for you, and it makes your online life infinitely more secure. You should absolutely use new, uncompromised, PASSPHRASES for your password manager password, and you need to enable 2FA.