[ARIN-consult] Consultation on Requiring Two-Factor Authentication (2FA) for ARIN Online Accounts

Scott Leibrand scottleibrand at gmail.com
Thu May 26 11:48:43 EDT 2022


For me, that situation would require pulling out and powering on a backup phone that hasn’t gotten any app updates recently, putting it into airplane mode to protect against any C&C in case the back door has been in place longer than my phone has been off, and then start the tedious process of manually exporting all my important credentials. Once that is complete, I would need to go log into everything important, change my password, re-enroll 2FA, and store the new credentials in another uncompromised password manager. 

Scott

> On May 26, 2022, at 2:55 AM, Gert Doering <gert at space.net> wrote:
> 
> Hi,
> 
>> On Wed, May 25, 2022 at 07:35:21PM -0400, Peter Beckman wrote:
>>   In the 11 years I've used 1Password, I have always had access to my
>>   authentication through multiple secure encrypted means. Even when I lose
>>   my mobile phone or it is not nearby.
> 
> So, if 1Password becomes corrupted (due to supply chain attacks), and
> you wake up one morning with the message "you can not trust this anymore,
> because we know the source code was backdoored", what do you do then?
> 
> Your solution very much sounds like "I have this great tool which never
> failed for me", but eventually, it will.  Then what?
> 
> Gert Doering
>        -- NetMaster
> -- 
> have you enabled IPv6 on something today...?
> 
> SpaceNet AG                      Vorstand: Sebastian v. Bomhard, Michael Emmer
> Joseph-Dollinger-Bogen 14        Aufsichtsratsvors.: A. Grundner-Culemann
> D-80807 Muenchen                 HRB: 136055 (AG Muenchen)
> Tel: +49 (0)89/32356-444         USt-IdNr.: DE813185279
> _______________________________________________
> ARIN-Consult
> You are receiving this message because you are subscribed to the ARIN Consult Mailing
> List (ARIN-consult at arin.net).
> Unsubscribe or manage your mailing list subscription at:
> https://lists.arin.net/mailman/listinfo/arin-consult Please contact the ARIN Member Services
> Help Desk at info at arin.net if you experience any issues.


More information about the ARIN-consult mailing list