mastodon.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
The original server operated by the Mastodon gGmbH non-profit

Administered by:

Server stats:

329K
active users

#authn

0 posts0 participants0 posts today

Default passwords (in this case voicemail PIN) strike again! There are many #AuthN systems around that support sending OTPs by a phone call as an alternative/fallback to SMS (and is an accessibility requirement). Unfortunately, they can't account for this attack vector.
(Oh, and use Signal, not Telegram)
#Identity #Security
gbhackers.com/hackers-hijack-t

GBHackers Security | #1 Globally Trusted Cyber Security News Platform · Hackers Hijack Telegram Accounts via Default Voicemail PasswordsThe Israeli Internet Association has issued a public warning about a surge in cyberattacks targeting Telegram accounts in Israel.

Dans son guide "Recommandations relatives à l'authentification multifacteur et aux mots de passe", l'ANSSI nous explique que l'authentification forte doit mettre en oeuvre un protocole cryptographique et résister aux attaques par rejeu, et aux attaques de l'homme du milieu.... Puis s'en va nous donner des exemples d'authentification forte...

Dans cette liste, on y retrouve TOTP...

Les TOTP sont parfaitement vulnérables aux attaques par rejeu, une fois interceptés par un site de hameçonnage. Ils sont également parfaitement attaquables par MITM...

En outre, on retrouve dans la liste FIDO2.

FIDO2 est attaquable par MITM si l'on ne met pas en oeuvre la mesure dite de "channel binding" ou "token binding". À ma connaissance, cette fonctionnalité n'est prise en charge par aucun navigateur. Même Chrome l'a retiré.

groups.google.com/a/chromium.o

Ils sont beaux, les guides #ANSSI depuis quelques années... ​🥱

Edit : Cette communauté est formidable <3 Merci à toutes et tous celleux qui se sont proposé.es !

Besoin d'aide pour une relecture

J'ai rédigé ces derniers temps un cours "Identité et méthodes d'authentification" pour une grande école parisienne. Niveau Bac+5.

Ce cours sera ultérieurement publié en licence libre (probablement CC-0 ou CC-BY).

Je dois donner ce cours mercredi. Est-ce qu'un gentil ou une gentille fédinaute compétent.e ou pas sur le sujet spécifique aurait le temps de relire ce que j'ai produit ce week-end et me faire un retour ? Ca fait environ 20 pages de texte brut police 12, alinéa simple.

I'm looking for an open source #IAM provider with good recommendations... I'm considering Auth0 (out of laziness), but definitely not interested in AD or Google direct - does anyone know a good open-source tool to use for authentication? Hosting my own is fine, but rolling my own is re-inventing the wheel a bit too much.

Federation supported or not, either fine.

Some listed here: medevel.com/5-iam-enterprise/ such as #KeyCloak and #OpenIAM

MEDevel.com · Best 5 Open Source Identity Management Solutions (IAM) For Enterprise for 2023Identity management is a crucial aspect of modern-day digital operations. It involves the management of user identities, access controls, and authentication in a secure and efficient manner. With the rise of cloud computing, the need for effective identity management solutions has become more apparent. This has led to the development
#Auth#Authr#Authn

#Passkeys question, I have Yubikeys set as the second factor on numerous accounts. What if I want to use passkey for those accounts stored on a Yubikey, will using passkey mean I need an OTP code or have to use a different Yubikey? Or will passkeys eliminate the second factor as it has seemed to do with my Google account, I just signed in using a passkey and wasn't asked for my second factor. I should have really done far more reading on this matter.
#Fido2 #authN

As we recap our fantastic #EverythingOpen talks, next up is William Brown @firstyear from @SUSE who walks us through #passkeys for #web #authn, showing us their ambiguities, how they work, what their limitations are, and what we need to be thinking about when we implement them.

Another fabulous talk from William.

youtube.com/watch?v=V-7zMIgGO1

Here’s my first video chat with ChatGPT about authentication, authorization, and building Android and iOS apps that use Auth0/Okta for login. Does ChatGPT gets the answers right? Yes for some, categorically NO for others.

ChatGPT did me a solid, though — it wrote the YouTube description of the video for me. Thanks, ChatGPT! 🤖

#ChatGPT #AI #security #cyber #cybersecurity #OAuth #OIDC #authN #authentication #authorization #login

youtube.com/watch?v=rfkgdorO-8