Welcome to Incremental Social! Learn more about this project here!
Check out lemmyverse to find more communities to join from here!

NuXCOM_90Percent , (edited )

There is.

2FA. No, not the fucking "we'll send you an SMS" bullshit that is increasingly used to just highlight an active phone number for spam purposes. Proper TOTP with the code backed up to a proper service (bare minimum, Bitwarden)

Someone can steal your password and even your email account (unless you TOTP that too...). They still can't get into your account unless you are an idiot who gets tricked into providing the 2FA key.

In a perfect world? Have your TOTP credentials in one encrypted database/Bitwarden account and your passwords in another. In reality? Just use a trusted service. I used to be a big fan of Keepass but protecting that with a yubikey (or similar) is a huge mess.


The recent push for passkeys (?) is a nice-ish middle ground. People don't need to understand how to paste a TOTP code into Bitwarden but they still need to approve a login. That said, I hate it since so much of it is dependent on a single device that can generally be opened by just applying REDACTED to the screen and doing REDACTED to narrow down the lock code significantly.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • mildlyinfuriating@lemmy.world
  • incremental_games
  • meta
  • All magazines