1984

1984

  1. 2 weeks ago
    Anonymous

    my first experience with 2FA was when I was a WoWfag in like 2008 and got an authenticator for my account. It was a little keychain fob thing, you pressed a button and it gave you a six-digit code. I would have no objection to a site or service that did that. My objection to 2FA is sites using it as a thinly-veiled excuse to tie the account to a phone number. SMS is insecure in the first place, and I don't want businesses to have my phone number at all if possible.

    • 2 weeks ago
      Anonymous

      >I don't want businesses to have my phone number at all if possible.
      This. I never had problems with spam until I started using a couple sites that force 2fa.

    • 2 weeks ago
      Anonymous

      Authenticator apps are a thing, though some still force phone number as a "recovery method"

    • 2 weeks ago
      Anonymous

      GIVE US YOUR PHONE NUMBER! IT'S FOR YOUR SECURITY!!!!!! NO WE DONT CARE IF YOU CHANGE PHONES NUMBERS OR SOME OTHER SHIT HAPPENS THAT MAKES YOU LOSE YOUR PHONE NUMBER! THATS NONE OF OUR PROBLEM!

    • 2 weeks ago
      Anonymous

      >thinly-veiled excuse to tie the account to a phone number
      Exactly this. I will not use a service, app or whatever that requires this shit. If they have a feedback section I tell them I dont have a phone so I cant use their shit.

      • 2 weeks ago
        Anonymous

        See:

        You're yet another joke in this thread that doesn't understand TOTP

        Fucking moron

    • 2 weeks ago
      Anonymous

      >2FA
      >SMS is unencrypted since forever
      >iMessage probably works (on some companies OTP/codes) meanwhile RCS is spotty and may not work depending on your APN and SIM capabilities, while RCS may also eat your encrypted 2FA SMS OTP/codes for breakfast (it is usually broken at night time your time zone, saving bandwidth? lol)
      >4G call is "somewhat okayish encrypted" however OTP codes aren't sent this way, since it costs more to do calls
      >but also most phones do not support VoLTE / 4G call since the IMS is broken most of the times and most ISPs only IMEI whitelist their available "postpaid" phone plans for VoLTE, thereby making the theoretical call OTP code insecure anyways since it's 2G/3G
      >most "authenticator" apps are botnet as fuck
      >2FA is actually just a thinly-veiled KYC+datamining+(credit)profiling, it is likely that your information would be leaked anyways, even more vector for your total compromise
      >complete and utter compromise when the OTP code over insecure SMS included the device's user agent which banking apps sometimes do to notify logins, this lets hackers imitate your user agent and compromise more accounts later

      this

      • 2 weeks ago
        Anonymous

        You're a literal dribbling moron lmao

        TOTP doesn't use SMS

      • 2 weeks ago
        Anonymous

        With this level of retardation it's hard to say if you're joking or not

    • 2 weeks ago
      Anonymous

      you can literally migrate TOTPs to devices like this (some have their own cameras + a GPS for exclusively scanning TOTP QR codes offline)

      You're a literal dribbling moron lmao

      TOTP doesn't use SMS

      ^ this, you dont need a phone for any of this shit, you can do TOTPs on an air-gapped device, other than the initial QR with the secret key being intercepted.

    • 2 weeks ago
      Anonymous

      most websites actually work users never used SMS 2FA, because it is surprisingly expensive to send SMS to people regularly. multiple orders of magnitude more than emails or similar. and even more when your users include third-worlders with oligopolistic mobile carrier markets
      the problem is 99.9999999% of people just can't be arsed to use TOTP because the user experience is ass. how do you expect normies to safekeep their TOTP secrets when Google's own retarded app for it didn't bother syncing them until very recently? This is the onyl reason why shit like Authy got popular for example
      These days it's getting better at last, with passkeys in particular hopefully saving us from all this shit in the future
      (and don't mention security keys, they're great but are multiple layers of autism further away from what the average dumbass can handle)

  2. 2 weeks ago
    Anonymous

    what service?

    • 2 weeks ago
      Anonymous

      Github, you vill use ze phones

      • 2 weeks ago
        Anonymous

        move to codeberg or sourcehut

      • 2 weeks ago
        Anonymous

        I won't do what you say so you can just suck it chump.

      • 2 weeks ago
        Anonymous

        Retard, you don't need to use a phone

      • 2 weeks ago
        Anonymous

        it should remain optional, but honestly, TOTP is good, open tech. there's no reason to not use it.

        Bitwarden browser plugin handles TOTP for you.

        • 2 weeks ago
          Anonymous

          Honestly, just for not loosing the totp keys bitwarden is worth the 10$ price it costs.

          • 2 weeks ago
            Anonymous

            yeah, but I self-host anyway. still, a good product. I think they strike good balance between being community-friendly and making their business work.

        • 2 weeks ago
          Anonymous

          Isn't having your totp in the same app as your passwords kinda defeating the purpose though?? in any case, my issue is now setting up all the totp keys again, massive pain in the ass.

          • 2 weeks ago
            Anonymous

            yes, it may defeat the purpose in some cases. in general, three factors of authentication are
            >something are (login, biometrics)
            >something you know (password)
            >something you own (auth token)
            having TOTP and passwords in password manager basically rolls the last two into one, when someone gets hold of your master password, or a leak happens which publishes both these factors.

      • 2 weeks ago
        Anonymous

        SourceHut

      • 2 weeks ago
        Anonymous

        just made a new account and I can't remember 2fa even being mentioned

      • 2 weeks ago
        Anonymous

        You don't need a phone for TOTP auth you retard, you can use KeePassXC on your favorite troonix desktop.

    • 2 weeks ago
      Anonymous

      github

      https://i.imgur.com/vxiKvVp.png

      1984

      just use aegis authenticator, you can back up your keys in plaintext if you so want and use them anywhere including your desktop with autistic cli tools like oathtool

      my first experience with 2FA was when I was a WoWfag in like 2008 and got an authenticator for my account. It was a little keychain fob thing, you pressed a button and it gave you a six-digit code. I would have no objection to a site or service that did that. My objection to 2FA is sites using it as a thinly-veiled excuse to tie the account to a phone number. SMS is insecure in the first place, and I don't want businesses to have my phone number at all if possible.

      you literally do not need to give them your phone number because they support TOTP 2FA apps

      • 2 weeks ago
        Anonymous

        What's your credentials exactly, Dr. Shekelberg?

      • 2 weeks ago
        Anonymous

        >apps
        I don't want an app
        I don't want anything I do to depend on a phone
        dedicated device or nothing. no phones, ever.

        • 2 weeks ago
          Anonymous

          keepassxc supports totp too
          https://keepassxc.org/docs/KeePassXC_UserGuide#_adding_totp_to_an_entry

          • 2 weeks ago
            Anonymous

            >t. juice

            • 2 weeks ago
              Anonymous

              You can generate a code with oathtool
              You don't know what TOTP is.
              It doesn't require network access, or any sort of authentication aside from a shared secret given to you which is used to generate one time passwords and then confirming that your code generator works when it asks you to give a 6 digit code.

              oathtool --totp -b "[your secret key]"

            • 2 weeks ago
              Anonymous

              ?

            • 2 weeks ago
              Anonymous

              >t. autist

          • 2 weeks ago
            Anonymous

            Came here to recommend this. Specifically installed it because Github wouldn't let me log in if I didn't enable this shit, never used it before and I found it really convenient.

      • 2 weeks ago
        Anonymous

        >github
        works on my machine

      • 2 weeks ago
        Anonymous

        >just use [thing]
        I don't want to, passwords work fine

  3. 2 weeks ago
    Anonymous

    >github
    i dont get why people still use that shithole.

  4. 2 weeks ago
    Anonymous

    I moved to codeberg
    at the very least they dont have 2Fa

  5. 2 weeks ago
    Anonymous

    I'm going to fucking scream. You do not need a phone for 2FA.

    • 2 weeks ago
      Anonymous

      I know how you feel, but it's not OP's fault, you can be forgiven for thinking 2FA TOTP is some proprietary botnet shit where your keys are now stuck on your phone tied to your google account or some shit because they literally do promote it this way and the most visible apps when you search for a TOTP app are exclusively proprietary phone apps that require a goddamn login.

      • 2 weeks ago
        Anonymous

        hahaha naggers hahaha lmao i hate naggers fuck naggers hahaha nagger nagger nagger lmao nagger fucking naggers nagger nagger nagger nagger hahahaha nagger

        nah just kidding, i love naggers

        • 2 weeks ago
          Anonymous

          >t. wigger

    • 2 weeks ago
      Anonymous

      I just upgraded my F-91W and it supports TOTP now, I wish I had a use for it.

  6. 2 weeks ago
    Anonymous

    I was pretty angry when robinhood started forcing me to use totp 2fa but then it made a lot of sense and now I'm angry my regular bank doesn't support it.

  7. 2 weeks ago
    Anonymous

    [...]

    fact: companies have used 2fa to link accounts with real world identities and have sold this information to advertisers

    • 2 weeks ago
      Anonymous

      >what is TOTP

      • 2 weeks ago
        Anonymous

        what you don't understand is not every site offers TOTP or webauthn

  8. 2 weeks ago
    Anonymous

    i dont get it.. is it asking u to use SMS 2FA? cuz u dont have to sign up to anything to use TOTP lol

  9. 2 weeks ago
    Anonymous

    >its an additional layer of security*
    *that gives us access to your phone and all your data to sell to third parties.

    enjoy the extra securityTM so nobody hacks into your fucking videogame/forums account.
    good god fuck modern "security". not everything needs to be inconveniently secure. but i know the financial reason behind it

    • 2 weeks ago
      Anonymous

      u r retarded

  10. 2 weeks ago
    Anonymous

    I just stole a bunch of those 2FA physical keys from my job and now I can make infinite accounts easily.

    If you can afford a phone plan, you can afford a yubikey. You should be using them anyway.

    • 2 weeks ago
      Anonymous

      hoqw do they work?

      • 2 weeks ago
        Anonymous

        >key stores secret
        >plug in key
        >sys time + number sent to key
        >computes hash on the key
        >sends HOTP back
        it's a smart card but with a USB port, some of them require you to touch it or enter a pin/biometric as well depending on the standard

        >totp device
        >has battery
        >keeps time
        >computes TOTP "burned" in with NFC
        same shit but it's air-gapped and has a screen, cheap AF for work ones and can last for like 8 years on the included RTC battery. again some can hold multiple or be plugged in to transfer secrets via a computer.

        then there's hybrid devices like hardware wallets that can have a camera, do both HOTP/FIDO2 and TOTP with a screen, type shit out for you as a password manager, and store arbitrary shit used for crypto. an old phone storing your keypass db can do this just as well.

  11. 2 weeks ago
    Anonymous

    >Phone 2FA
    >Not just using something like Aegis
    NGMI

  12. 2 weeks ago
    Anonymous

    you shouldnt post your 2fa code like that anon

  13. 2 weeks ago
    Anonymous

    switch to codeberg since they force 2fa

    • 2 weeks ago
      Anonymous

      I completely forgot about Codeberg. What are the reasons people use Codeberg over Github or Gitlab?

      • 2 weeks ago
        Anonymous

        ~~*codeberg*~~

  14. 2 weeks ago
    Anonymous

    https://codeberg.org
    works for me

  15. 2 weeks ago
    Anonymous

    What should I use instead of GitHub? I'm not self hosting

  16. 2 weeks ago
    Anonymous

    i will just ask my friend if i can use his phone. i have no idea what phone all of my 2fa accounts are using

  17. 2 weeks ago
    Anonymous

    if it wasnt for 2fa i would have been hacked and lost all my money and had my identity stolen like 6 times over by now. passwords are so easy to get leaked and cracked nowadays that they are basically useless, they are just the first line of defense.

    • 2 weeks ago
      Anonymous

      Your post is full of indoctrinating bullshit.

      • 2 weeks ago
        Anonymous

        im just saying its saved me many times. if its 'indoctrinating' then fine.

        • 2 weeks ago
          Anonymous

          Maybe you should not make your password to be 123456.

          • 2 weeks ago
            Anonymous

            going with full-autismo 56 character password won't help you with inevitable password leaks. but to be fair, TOTP probably won't help you neither. I guess when passwords leak, so do authenticator keys (unless they are handled by third party).

          • 2 weeks ago
            Anonymous

            my passwords are very secure, uses every type of character avaliable, random bullshit that no one could ever guess.
            that is totally fucking irrelevant however because of how easy to is to crack passwords and how prevalent data leaks are now. fuck, some exploits with cookies/tokens whatever mean you dont even fucking need the password.
            the fact of the matter is a password is NOT enough and hasnt been since around 2018.
            if you wanna risk having basically your entire life fucked because of some nonsensical principle against 2fa, thats on you. indeed i will quite happily laugh alongside those benefiting from your ineptitude,

  18. 2 weeks ago
    Anonymous

    Every single time I open an app these days I get this vibe. Why are they like this?

  19. 2 weeks ago
    Anonymous

    Literally George Orwell's Animal Farm

  20. 2 weeks ago
    Anonymous

    ITT: Retards not knowing about Aegis

    • 2 weeks ago
      Anonymous

      doesn't work for steam. as soon as you try to trade anything you have to convert back to using the app and waiting 14 days. otherwise thats the only service ive even found that allows totp to be setup. most use sms and don't give you token access

      • 2 weeks ago
        Anonymous

        Steam is annoying in that it forces it to be either email, sms or their own app iirc. But I have loads of sites using my 2FA app (Aegis). To mention a few:
        >Amazon
        >Microsoft
        >Epic Games
        >Reddit
        >Firefox
        >Github
        >Proton
        >AutoDesk
        >Nextcloud
        >Facebook
        >Paypal
        >LinkedIn
        >Discord
        >Google

        • 2 weeks ago
          Anonymous

          >Steam is annoying in that it forces it to be either email, sms or their own app iirc.
          and it doesn't even fucking work!!!
          source: got my account stolen by a russian which then replaced email/phone number and everything else and I didn't even receive an email warning or anything

          • 2 weeks ago
            Anonymous

            holy shit this
            I recently moved my account to a new phone and you can just fucking say "I lost my old one" as a button like it means jack shit.

            • 2 weeks ago
              Anonymous

              well, that explains how that happened then, because why send a security notification to your old number just in case if you forgot it anyway, am i right?
              Luckily I pirate 99,9% of my games and I only lost a couple of cs:go skins + 3€ (which support couldn't give me back because somehow it was my fault for not securing my account properly)
              and i'll keep pirating, not that I was planning to ever stop, but this just gave me a reminder to never """"purchase"""" shit on steam ever again

  21. 2 weeks ago
    Anonymous

    > proven method
    aaaaaaaaaahahahaha. nah, this is false.

    • 2 weeks ago
      Anonymous

      It's proven that it offers better protection than just password for sure

      • 2 weeks ago
        Anonymous

        > what is sim hijacking?
        > what is signalling system #7?
        absolutely 100% not going to make it
        https://en.wikipedia.org/wiki/Signalling_System_No._7?useskin=vector#Protocol_security_vulnerabilities

        2fa is a joke.

        • 2 weeks ago
          Anonymous

          >better protection
          >better
          Do you understand what that means?

        • 2 weeks ago
          Anonymous

          You're yet another joke in this thread that doesn't understand TOTP

          Fucking moron

  22. 2 weeks ago
    Anonymous

    >Guys, you should now secure your accounts to prevent them from getting stolen by skids.
    >THIS IS LITERALLY LE HECKIN 1984!!!! FUCKING OPRESSIUN, EAT ZE BUGS!!REEEEEEEEEEEEEEEEEEEEEEEEE!!!!
    Why is LULZ full of Dunning-Kruger NEETs like that?

    • 2 weeks ago
      Anonymous

      >why userbase that consists of uneducated losers suffers with Dunning-Kruger the most
      who knows?

  23. 2 weeks ago
    Anonymous

    2fa is a scam, you will be forced to upload your biometrics to the botnet to authenticate soon.

    • 2 weeks ago
      Anonymous

      Bet

  24. 2 weeks ago
    Anonymous

    I wanted to create an account in Gitlab the other day and it said I had to give them my phone number or credit card number.

  25. 2 weeks ago
    Anonymous

    github hasn't bothered me about 2FA for some reason yet. I'm assuming someone fucked up somewhere but I won't complain.

    • 2 weeks ago
      Anonymous

      You don't have to use 2FA unless you have public repos published.

      • 2 weeks ago
        Anonymous

        That's the weird part. I do have public repos published

        • 2 weeks ago
          Anonymous

          Learn to read, then just get what the guy above you posted and call it a day, 2FA is purely beneficial unless it uses a phone number

          • 2 weeks ago
            Anonymous

            >Learn to read
            try applying this advice to yourself first and reread the reply chain carefully

  26. 2 weeks ago
    Anonymous

    I'm gonna put the 2fa key into keepass next to my passwords

    There's NOTHING you can do about it

    • 2 weeks ago
      Anonymous

      It's not gonna be as secure but that's about it. Very handy though

  27. 2 weeks ago
    Anonymous

    I lost like 4 accounts that started using 2fa without getting my consent, I had a different phone number back then so when I tried to login it just fucking send the code to a non existing phone number, pieces of shit

  28. 2 weeks ago
    Anonymous

    mooltipass anon
    ya store all those secret keys on some device you can care enough about to lug around at work

  29. 2 weeks ago
    Anonymous

    For me, it's https://www.f-droid.org/packages/com.beemdevelopment.aegis/

  30. 2 weeks ago
    Anonymous

    Being tech incompetent has nothing to do with 1984. You don't even need a phone to use 2FA, not that you retards would realize this when you likely think Google Auth is the only way to do it.

Your email address will not be published. Required fields are marked *