Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×

Comment Re:Security is bad enough as it is then... (Score 1) 37

You've got these ridiculous apps ...

I don't use it but will note that you can use Zelle from within your bank's online portal, so you don't have to use a banking app. And you must have either an actual bank account, or a pre-paid credit card, from a bank within the Zelle network to use this. Your other comments are spot-on...

Comment Hmm ... (Score 2) 37

1. Poor identity verification methods, which have allowed bad actors to quickly create accounts and target Zelle users.

You must have an actual bank account, or a pre-paid credit card, from a bank within the Zelle network (in either case), so this item seems a little fishy.

Search: bank account required for zelle

Comment Re:And the alternative? (Score 1) 84

Authenticator apps need to have a clear backup approach and not one that turns out to have circular dependencies should you lose your phone.

I switched from Authy to 2FAS on my Pixel 5a, for several reasons, including that the latter can export your token info as JSON in either a clear-text or encrypted file for offline backup. I don't have a second Android (or iOS) device, but could stand up a virtual device in, say, Android Studio on Linux, but don't have to go that far. I also just started experimenting with KeePassXC and it supports TOTP tokens and you can copy/paste the Manual Keys for your tokens from the 2FAS JSON file ... I imagine other password managers support similar features, but KeePassXC is free and runs on Android, Windows, Linux and (I'm guessing) iOS ... and can all use the same database file.

Comment Re:Passkeys are better for everyone (Score 1) 203

I had Authy and they now no longer support there desktop version, ...

That annoyed me too, enough that I switched to 2FAS on my Pixel 5a. Of course, that didn't solve that issue, but I like that the tokens can be exported from 2FAS as JSON, in either a clear-text or encrypted file and stored offline. I don't have another physical device to run 2FAS, but it will run in virtual device, like in Android Studio, though I don't have to go that far. KeePassXC supports TOTP tokens and you can copy/paste the manual keys from the 2FAS JSON export; it runs pretty much everywhere...

Comment Re: Just Microsoft (Score 1) 203

Passkeys will be around until someone figures out a fatal and unrecoverable weakness with them.

From TFA... not necessarily fatal or unrecoverable, but probably super annoying or problematic:

Passkeys are not foolproof though. A compromised device might expose private keys, and a successful social engineering attack could dupe a user into creating a passkey for a malicious service.

There are also potential problems if the user loses access to a device that stores passkeys – another means of authenticating to a passkey-linked service would be required, which might involve passwords or a more involved recovery process.

Also, passkey portability between credential providers (across platforms or password manager applications) is still a work in progress.

While it notes, "a compromised device might expose private keys" it fails to be clear that it might expose *all* your private keys. I'm not a fan of having all my eggs in one basket. Also, using bio-metrics to access your passkey means no, or less, legal protections from searches -- so use a long PIN, or password - oh, wait ...

Comment Re:Beaurocrats with too much time on their hands (Score 1) 258

Agreed. And more importantly, belting things in keeps them from flying around if you get into an accident. The last thing you want is that 20lb suitcase becoming, effectively, a 200lb projectile ... Personally, I don't like having stuff in the cabin and put them in the trunk.

Comment Re:Security for me, but not for thee (Score 1) 38

Why only senior government officials and politicians? Wouldn't *everybody* benefit from secure communications?

And how senior? Trump wouldn't stop using his iPhone, in favor of the secure one Presidents usually use, during his first administration -- before this guidance. What makes anyone think he'd change this time around? And if his communications aren't secure, ...

Comment Re:about time (Score 1) 131

You must've missed the words "bipartisan measure" in the summary...

That'll be great until the rich people running these companies have dinner at Mar-a-lago, with the guy who will be in charged of enforcing laws and also has an iron grip on the (R) party, who will also be in charge of everything next year ...

Slashdot Top Deals

Hackers are just a migratory lifeform with a tropism for computers.

Working...