AT2k Design BBS Message Area
Casually read the BBS message area using an easy to use interface. Messages are categorized exactly like they are on the BBS. You may post new messages or reply to existing messages!

You are not logged in. Login here for full access privileges.

Previous Message | Next Message | Back to Computer Support/Help/Discussion...  <--  <--- Return to Home Page
   Networked Database  Computer Support/Help/Discussion...   [411 / 1585] RSS
 From   To   Subject   Date/Time 
Message   Arelor    Kurt Weiske   Re: Yubikey   June 9, 2021
 5:23 PM *  

  Re: Re: Yubikey
  By: Kurt Weiske to Sean Dennis on Wed Jun 09 2021 08:22 am

 > -=> Sean Dennis wrote to All <=-
 > 
 >  SD> I have thought about using a Yubikey for limiting root access to my BBS
 >  SD> server.  Are any of you using a Yubikey or something similar?  I know
 >  SD> that Slackware supports the use of a Yubikey via third-party software.
 > 
 > While hardware 2FA is pretty nifty, I'd think that SSH keys would be
 > sufficient.
 > 
 > 
 > ... Am I any closer to finding what I'm looking for?

It depends on the application, but pretty much this.

When you enable 2nd Factor Authentication in a _small_ firm, user support
tickets SKYROCKET because everybody and their grandmother eventually manages to
lose, corrupt or have their 2nd Factor Auth device stolen.

There was a cryptocoin exchange that started charging a fee for solving 2FA
issues because they were badly overloaded.

2FA is also causing me lots of headaches in e-commerce because many users can't
figure it out and get credit card payments authorized.

In my opinion, small users are better served with a single user-password pair
and some anti-bruteforce technique, such as temporarily disabling users with an
excess of failed logins. This has other issues (it makes your services DoSable
if you are not careful) but it seems to be less of a problem in the wild than
the 2FA apocalypse.

--
gopher://gopher.richardfalken.com/1/richardfalken
--- SBBSecho 3.14-Linux
 * Origin: Palantir * palantirbbs.ddns.net * Pensacola, FL * (618:250/24)
  Show ANSI Codes | Hide BBCodes | Show Color Codes | Hide Encoding | Hide HTML Tags | Show Routing
Previous Message | Next Message | Back to Computer Support/Help/Discussion...  <--  <--- Return to Home Page

VADV-PHP
Execution Time: 0.0164 seconds

If you experience any problems with this website or need help, contact the webmaster.
VADV-PHP Copyright © 2002-2024 Steve Winn, Aspect Technologies. All Rights Reserved.
Virtual Advanced Copyright © 1995-1997 Roland De Graaf.
v2.1.220106