#authentification #2FA with #twilio #authy in #nixos did not work... so I just used the Gnome authenticator which is great. The same QR code can be used to set up authentication in multiple authentication apps all of which produce the same #OTP #onetimepassword
My #twilio #authy #authenticator #authentification providing #otp #onetimepassword for #twostepverification #2sv does not work on #nixos . Can you recommend any alternatives that work for e.g. Amazon , Bitwarden, google and so on? Thanks.

👋 OTP (One-Time Password) with WhatsApp
Allow users to log into your app via OTP with WhatsApp, as a 𝐦𝐨𝐫𝐞 𝐛𝐮𝐝𝐠𝐞𝐭-𝐟𝐫𝐢𝐞𝐧𝐝𝐥𝐲 alternative to SMS and secure authentication method, to increase conversion rate and grow sales with more engagement.

https://www.authgear.com/features/whatsapp-otp

#whatsapp #onetimepassword #authentication

WhatsApp OTP - Authgear

Send OTP via WhatsApp, a more cost-effective and efficient authentication method, to provide frictionless and secure signup and login process for your users.

Oursky

It’s a bit annoying that #Apple has decided to bundle the options for #Passkeys with their options for filling #Passwords in #iOS17 when #VerificationCodes (or #OneTimePassword codes) are separate. It’s possible there are technical reasons for this, but it means that I’m in a bit of a bind.

I can either switch over to Apple’s password manager (which I don’t like) or wait to adopt passkeys until #1Password has mobile support for them. Or am I missing something?

https://2fas.com/ ist eine #TOTP App, die mit einer Browser Extention gekoppelt wird und somit die #OneTimePassword eingabe erleichtern.
Auch ein kompromiss zwischen Vereinfachnung und ein weiteres Angriffsvektor.
Ob es evtl durch Domainprüfung beim Phishing Problem von TOTP hilft?
2FA Authenticator App (2FAS)

2FAS (2FA Authenticator App). Protect your accounts and online services.

2FAS.com
How long would it take to brute-force an OTP?

I was wondering if there is a formula to calculate how long it would take to "guess" a "X-Digit" OTP, presuming you limited the number of times you can try for each code and the

Information Security Stack Exchange
Does this implementation of 2FA expose valid credentials?

I have come across scenarios where a website would send OTP once a user has supplied valid username/password. A confirmation dialog e.g. An OTP has been sent to your registered mobile number would be

Information Security Stack Exchange