40 points
*

Didn’t Okta just straight up get all their customer data hoovered up by hacker squad

permalink
report
reply
19 points

My employer uses Okta for SSO lul

permalink
report
parent
reply
8 points

Hoo boy

permalink
report
parent
reply

yes

permalink
report
parent
reply
1 point
Deleted by creator
permalink
report
parent
reply
37 points
*

Every ‘passwordless’ solution to passwords always ends up being the informational equivalent of ‘passwords, but the method is changed’. Biometrics are just a once-in-a-lifetime password that’s entered differently, password managers are just all your passwords, but behind one big password.

Even 2FA is just “password you know” and “password your device knows”.

Not saying these solutions don’t have value, but to say passwords are outdated is a bit silly.

permalink
report
reply
3 points
*

USB/NFC hardware keys are pretty good though, they are just the current form of smartcard hardware keys that have been around since the late 1990s for high security environments. If you worked for certain federal agencies or private sector companies, you might have used them. They are old technology at this point that has more recently been introduced into the consumer space as platforms and companies face backlash for constantly having security breaches.

permalink
report
parent
reply
2 points
*

I have used them (coincidentally, with Okta), and they are pretty neat! I actually choose to use them instead of a smartphone app where I can, because it’s much faster to use. I’d recommend them to companies as a good measure.

They are still effectively 2FA where it’s just a lot harder to work out the proprietary system with which the password is encoded. So it is a sort of a ‘security by obscurity’, but the likelihood of someone going through all the work to disassemble your key and work it out with you noticing / before the key gets invalidated is pretty low, so unless you’re protecting something super-duper high value (and assuming the manufacturer hasn’t screwed up too badly), they’ll do a good job.

permalink
report
parent
reply

Guy who thinks passwords are outdated, setting a new password for his bank app: Hmm, how about Christmas123!, just like all my other logins so I don’t have to worry about forgetting it!

permalink
report
reply
11 points

A fundamental problem with passwords is that you either have a “secure” selection of large, distinct, constantly rotating codes that you have to keep track of on paper/in an app (insecure!) or a single memorable code that - once it is cracked - exposes all affiliated systems (insecure!)

There’s a serious argument to the effect that a physical id tied to a digitally managed rotating set of large arcane codes is at least as secure as the paper/app-based list of hard codes. The big problem with this technology is that it requires a more complex hardware interface with more attendant IT support. So you’re talking about $$$ that people don’t want to spend for additional technical security.

Two-factor authentication is cheaper and easier than biometrics. So we’ve settled on that instead.

permalink
report
parent
reply
10 points

just like how every one of my work passwords that i never set but just came with the IT gear i use is “season two digit number”

permalink
report
parent
reply

I simply use the fingerprint scanner with my balls. They’d never think to check there.

permalink
report
reply
13 points
CW: pretty gross even by my standards

I use my butthole and make sure to get a new hemorrhoid every 120 days to reduce my vulnerability to butthole database leaks

permalink
report
parent
reply

If they do think to check there, I’d see that as a net win.

permalink
report
parent
reply

fingerprints, face scanning… my OnePlus just keeps asking for pics of my asshole before I can unlock it. Is this just a China thing?

permalink
report
reply

It’s like a thumbprint, but more secure because you don’t typically rub it on every surface.

permalink
report
parent
reply

you don’t typically rub it on every surface

I don’t think you’re using your asshole right

permalink
report
parent
reply
16 points
*

As a fellow OnePlus haver, I have LineageOS (which is privacy-focused) installed and am not asked for pics of my asshole

permalink
report
parent
reply

I also use lineageos but still send them pictures of my asshole since I don’t want them to feel left out

permalink
report
parent
reply
Deleted by creator
permalink
report
parent
reply
11 points

Please drink the Diet Mountain Dew Verification Can.

permalink
report
parent
reply

the_dunk_tank

!the_dunk_tank@hexbear.net

Create post

It’s the dunk tank.

This is where you come to post big-brained hot takes by chuds, libs, or even fellow leftists, and tear them to itty-bitty pieces with precision dunkstrikes.

Rule 1: All posts must include links to the subject matter, and no identifying information should be redacted.

Rule 2: If your source is a reactionary website, please use archive.is instead of linking directly.

Rule 3: No sectarianism.

Rule 4: TERF/SWERFs Not Welcome

Rule 5: No ableism of any kind (that includes stuff like libt*rd)

Rule 6: Do not post fellow hexbears.

Rule 7: Do not individually target other instances’ admins or moderators.

Rule 8: The subject of a post cannot be low hanging fruit, that is comments/posts made by a private person that have low amount of upvotes/likes/views. Comments/Posts made on other instances that are accessible from hexbear are an exception to this. Posts that do not meet this requirement can be posted to !shitreactionariessay@lemmygrad.ml

Rule 9: if you post ironic rage bait im going to make a personal visit to your house to make sure you never make this mistake again

Community stats

  • 1

    Monthly active users

  • 20K

    Posts

  • 432K

    Comments