Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 
freitasm

BDFL - Memuneh
80654 posts

Uber Geek
+1 received by user: 41050

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3218706 15-Apr-2024 15:33
Send private message

Yes, it is.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 




Gordy7
gordy7
2001 posts

Uber Geek
+1 received by user: 505

ID Verified
Lifetime subscriber

  #3218707 15-Apr-2024 15:42
Send private message

freitasm:

 

Gordy7:

 

How do I setup 2FA Yubikey on GZ?

 

 

You can't. We offer TOTP-based 2FA (Authenticator).

 

 

Thanks. I like a challenge. I have Yubikeys for other apps.

 

I thought I would see if I could use my Yubikey in Windows to do a 2FA login to GZ.

 

I don't know if the Yubikey GZ login procedure listed below is similar to other 2FA login procedures.

 

I launched Yubico Authenticator and created a Geekzone account/profile.

 

Entered the Geekzone 2FA authentication 16 character key and saved with a password.

 

Now when want to log into Geekzone:

 

     

  1. enter my user name and password.
  2. launch Yubico Authenticator.
  3. select the Geekzone account/profile option.
  4. press my Yubikey which generates a 6 digit code.
  5. enter the 6 digit code into the Geekzone 2FA window.
  6. press the GZ login button and I am in.

 

 





Gordy

 

My first ever AM radio network connection was with a 1MHz AM crystal(OA91) radio receiver.


freitasm

BDFL - Memuneh
80654 posts

Uber Geek
+1 received by user: 41050

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3218722 15-Apr-2024 16:18
Send private message

Oh, yes. You can use the Yubikey Authenticator. You can't use the other Yubikey features like FIDO U2F.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 




Wheelbarrow01
1784 posts

Uber Geek
+1 received by user: 2638

Trusted
Chorus

  #3218724 15-Apr-2024 16:22
Send private message

Batman:

 

freitasm:

I may not understand what you wrote. Do you mean to imply you think other password managers were compromised? Because that is not what I wrote.

 

i meant that not long ago people were recommending LastPass as the best password manager, and now I am hearing don't use LastPass.

 

what is the current best password manager? why are we no longer recommending LastPass?

 

thanks

 

(no i don't think password managers are compromised, i was just hoping you use one password manager and never need to change but it seems you have to change password managers from time to time for reasons I don't yet understand)

 

 

What annoyed me most about Lastpass was that about a month after I signed up and moved everything across to them, they implemented their policy to make free users choose either mobile access or desktop access. That p1ssed me off no end but I ended up making do with the limited mobile access. This means I had to look up passwords on my mobile and manually type them into my desktop when required, but I ended up getting google/chrome to remember them anyway so it wasn't so bad.

 

My general inertia at not wanting to go through the process of changing password managers again is what made me stay with them for three years, but news of their security issues made it a pretty easy decision to take action last night, and Bitwarden is working perfectly across all devices today. Should have done it sooner!!

 

 

 

[EDIT corrected spelling]


jlittle
200 posts

Master Geek
+1 received by user: 76

ID Verified
Subscriber

  #3218734 15-Apr-2024 17:01
Send private message

Batman: Thanks guys will check out bitwarden...Just a question, is Microsoft authenticator ok to use? I have no issues using it, just wondering if it's safe

All the TOTP authenticator apps use the same standard, RFC 6238, so don't use Microsoft authenticator, use Bitwarden! Though that does require the premium subscription, at 10 USD a year; I've found it value for money, with the wide range of clients.

I'm not familiar with MS Authenticator, but my work had got me to use the Google one. If I didn't have the phone it was installed on, I was locked out. After leaving my phone 250 km away one day, I switched to Authy, but its owner turned shady (I can't remember the details, perhaps they were bought out by someone with a questionable record) I switched to Bitwarden. In good time, authy had a data breach not long after.




Regards, John Little


jjnz1
1371 posts

Uber Geek
+1 received by user: 195

Lifetime subscriber

  #3218752 15-Apr-2024 19:09
Send private message

Geekzone planning to implement passkeys anytime soon? 

 

Although in saying that, I try to use Bitwarden (actually Vaultwarden selfhosted) with passkeys between my iphone and mac and they only work 50% of the time. I feel like passkeys is a beta/early adopter feature that most big companies support, although slightly differently. 


HP

 
 
 
 

Shop now for HP laptops and other devices (affiliate link).
skewt
752 posts

Ultimate Geek
+1 received by user: 215


  #3218755 15-Apr-2024 19:24
Send private message

Chills:

I thought LastPass was already gone along with Dashlane but I must just not be caught up. My personal recommendations are BitWarden and 1Password! 



What happened with Dashlane?

Lightbulb
119 posts

Master Geek
+1 received by user: 10

ID Verified
Lifetime subscriber

  #3219060 16-Apr-2024 11:55
Send private message

I use lastpass.

 

About two years ago, I peppered my important passwords ie lastpass only holds the first part of my password and I then manually add on the last 6 digits/ characters - which are the same 6 for all my peppered passwords.  Unimportant pws aren't peppered.

 

I also use a 21 character master password , with 1001000 iterations and restrict logins from NZ only.

 

I was aware of the security breaches, but after just reading this thread am unsure how safe I am.

 

Am I safe from past security breaches - and do you still think I should go through the pain of changing password managers

 

ps - I am still going through the intense pain of changing all of my logins that use an xtra.co.nz email!!  so not keen to add to my workload.


1 | 2 
View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.