Dan Goodin

@dangoodin@infosec.exchange
14.5K Followers
1.1K Following
4.6K Posts
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Site:https://arstechnica.com/author/dan-goodin/
It would appear that if a Microsoft account holder wants to go passwordless, they MUST install Microsoft Authenticator. Authy, Google Authenticator and similar apps won't work. Can anyone confirm?

Microsoft writes:

"For example, if you have a password and “one time code” set up on your account, we’ll prompt you to sign in with your one time code instead of your password. After you’re signed in, you’ll be prompted to enroll a passkey."

I don't understand this. Why would Microsoft remove the password requirement and rely solely on a 1-time code? And what happens if the user decides not to use a passkey?

Windows RDP lets you log in using revoked passwords. Microsoft is OK with that.

Researchers say the behavior amounts to a persistent backdoor.

Ars Technica
If me wanting to view any of your shit requires zuckerburg begging me to log in or create an account, I will just as soon fuck off.
April was the first full month since I installed my 4.1 kW solar system and accompanying batteries. And just like that, I went from drawing 200-250 kWh per month from the grid to 3 kWh. For the month, I produced 583 kWh, 284 kWh of which I exported 284 kWh to the grid.

Mike Waltz Accidentally Reveals Obscure App the Government Is Using to Archive Signal Messages

https://www.404media.co/mike-waltz-accidentally-reveals-obscure-app-the-government-is-using-to-archive-signal-messages/

Mike Waltz Accidentally Reveals Obscure App the Government Is Using to Archive Signal Messages

A photograph of Trump administration official Mike Waltz's phone shows him using an unofficial version of Signal designed to archive messages during a cabinet meeting.

404 Media

Trump officials, they're just like us!*

*put off verifying their Signal PIN

Reuters got a photo of Mike Waltz checking Signal in a cabinet meeting and hoo boy, that entire government is running on it

Edited to add: it's not even Signal, it is an app called TM SGNL which "captures" all the Signal messages and archives them... in plaintext... over unencrypted channels...

https://www.reutersconnect.com/item/us-national-security-advisor-mike-waltz-attends-a-cabinet-meeting-held-by-president-trump-at-the-white-house-in-washington/

https://www.404media.co/mike-waltz-accidentally-reveals-obscure-app-the-government-is-using-to-archive-signal-messages/

For World Password Day today 🔑✨

Here again is my tutorial on
how to install the excellent local-only password manager KeePassXC (with a YubiKey)!

This is what I use to store all my passwords! 🔑🔑🔑🔑🔑  

My only disappointment is not starting to use it earlier. Keep your passwords safe! For free! And offline!

https://infosec.exchange/@Em0nM4stodon/114184594797507039

#WorldPasswordDay #Security #Privacy #KeePass #KeePassXC

Em :official_verified: (@Em0nM4stodon@infosec.exchange)

Attached: 1 image New Privacy Guides article 🔐✨ by me: If you want to keep your password manager local-only, KeePassXC is a great solution! It's free, Open-source, Easy to install and use, Doesn't require an account, Works on Linux, macOS, and Windows, And the team is here! 👉 @keepassxc@fosstodon.org Here's how to set it up with a YubiKey: https://www.privacyguides.org/articles/2025/03/18/installing-keepassxc-and-yubikey/ #PrivacyGuides #KeePassXC #Privacy #Security #PasswordManager #Passwords #FOSS

Infosec Exchange

I'm looking forward to being at #CYBERUK25 next week. Lots of interesting looking sessions and I'm sure it will be great to catch up with a lot of people too. Who will I see there? 🙂

I should also note that I have availability for writing news, features and analysis from the show. I already have several ideas and proposals about what to potentially write about, so if you're looking for editorial from one of the premier cybersecurity events in the calendar, please do get in touch! ✍

(Especially because I'm discovering that going as free agent means the costs of travel and accommodation are all coming out my own pocket! It's why I'm so late to sign up, but I couldn't feel FOMO twice in two weeks. So an opportunity to make that money back would be most welcome. 😅 )

https://dannypalmer.co.uk/

Danny Palmer

Award-winning cybersecurity writer and editor with over a decade of experience covering cybersecurity threats and trends.

Danny Palmer
@GossiTheDog @mttaggart
Thanks.
Yes, you can still RDP in with the old password after the account has been switched to passwordless. No Microsoft Authenticator required.