BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Password managers
- Subject: [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- Date: Wed, 6 May 2020 13:02:50 -0400
- In-reply-to: <CANiupv5AJPwvc4-z9Wp3PeK-Py51nRF2p87nHqs9xZERwQiCyg@mail.gmail.com>
- References: <9c4a5c7e-55aa-8ae1-da3b-4512cb2ae85c@gmail.com> <5eb1f81d.1c69fb81.80c8b.07ca@mx.google.com> <CANiupv686GBC5EZVsiEf831-b4i0E3NjZ3fnsDToM02z1zjUNg@mail.gmail.com> <5eb223cd.1c69fb81.6fa04.3ab5@mx.google.com> <0cbc8403-48a5-14bd-524c-a4eded6b64fa@borg.org> <e2be00f8-8de6-4645-e71b-a5d14f78ede7@borg.org> <5eb2d4b7.1c69fb81.c9540.9f0b@mx.google.com> <CANiupv5AJPwvc4-z9Wp3PeK-Py51nRF2p87nHqs9xZERwQiCyg@mail.gmail.com>
On Wed, 6 May 2020 12:03:41 -0400 Doug <sweetser at alum.mit.edu> wrote: > Am I wrong to presume everyone here uses 2-factor authentication? Probably. To be nit-picky, common 2FA is actually 2SV (two-step verification). 2FA collquially is something you know plus something you have like an ATM PIN and the matching card. Authenticator applications are 2SV which are two forms of something you know: your password and a code which can be revesed by someone who knows the device identification information and the initial handshake timings. Given the difficulty of obtaining the information backing the code generation most 2SV authenticator applications are good enough for general use, but they are not 2FA. Less nit-picky, plenty of sites out there don't support 2FA or 2SV. Therefore not all of us use these all the time. > Yubikey is that, plus it has software that does try to figure out if > the servers being contacted are the right ones, and not ones that > just look right to a casual observer. Mine aren't and don't. There are a variety of different Yubikeys with different capabilities. Likewise Nitrokey. -- Rich Pieri
- References:
- [Discuss] Password managers
- From: j.natowitz at gmail.com (Jerry Natowitz)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: sweetser at alum.mit.edu (Doug)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: sweetser at alum.mit.edu (Doug)
- [Discuss] Password managers
- Prev by Date: [Discuss] Password managers
- Next by Date: [Discuss] Password managers
- Previous by thread: [Discuss] Password managers
- Next by thread: [Discuss] Password managers
- Index(es):