Twitter reveals surprisingly low two-factor auth (2FA) adoption rate
bleepingcomputer.com
bleepingcomputer.com
SMS is a terrible 2FA anyways
If you remove it after adding it to get through verification, your account is likely suspended a day or two later
Somehow my account is "blocked" for "security reasons", yet Twitter is still fine sending me spam from it.
Besides, all SMS 2FA does is open you up to getting social engineering SIM hacked when you weren't before.
I just had the hole my Yubikey attaches to my keyring break. If I wasn't lucky it might have fallen off my keyring and disappeared. (No more Github for you!)
As it was I managed to stuff it into one of the pockets of my gym bag.
I keep the backup yubikeys in safe places and periodically when they are available I search in keepassxc for entries tagged with A but not B, for example, and add the missing yubikey to that service.
The following search in keepassxc will show entries with the attribute "yubikeyA" but lacking "yubikeyD":
attr:yubikeyB !attr:yubikeyDThat's a really good point. I keep a key with a friend in another city. When I visit them I use a query like the one above to determine any services that need to be registered with the normally unavailable key.
> So it makes this setup a bit harder than it could be.
I wish there was a way to enroll keys without them being present.
https://arstechnica.com/staff/2018/01/introducing-ars-pro-th...
so I'd guess 2018. I guess I could have reinforced the hole and I probably still could.
The build quality is still awful and given all the varieties of badUSB out there I'm not enthusiastic about a USB connector that lacks a grounding shell. (That said, at our public library all of the Dell machines have AC current floating on the USB shells that give a gentle little shock... That might not be so gentle if you were standing in a puddle)