Email or username:

Password:

Forgot your password?
Jerry Bell :verified_paw: :donor: :verified_dragon: :rebelverified:​

This message for everyone on the fediverse:

First, please ensure you go into your account settings and enable two/multi factor authentication. No, I mean do it right now. I’ll wait till you’re done.

Ok, thank you.

Now, if you are the admin of a mastodon instance, please go upgrade to 4.0.2 ASAP.

Background: portswigger.net/research/steal

39 comments
Maya :v_gay: :v_trans:

@jerry @david we up to date on tech.lgbt yet?

Seems there was the ability for credential stealing.

a pup of coffee :v_agender: :bowie: ☕

@AtomicMaya @jerry Thank you for sharing. I scheduled the update for tomorrow, but based on this info I'm going to run the upgrade now after a backup

Aaron de Montmorency

@jerry beat me to it. I mean, if someone in the infosec community didn't immediately set up MFA, that's a paddlin'.

Reverse Module :kafeneio:

@jerry Can someone tell me where 2FA resides cause I can't seem to fin it in the Settings.

yoshir

@ReverseModule
click on the gear, then on account, then on confirmation

aetios ▶️ kwsp
@jerry No 2FA on akkoma I believe, which is too bad. Interesting vulnerability though. Good thing I've long stopped using chrome autofill for my passwords. I believe more of these vulnerabilities will be found in the future. They are part of the growing pains of a hobby-size platform growing up.
Simon :donor:

@jerry I give up, I can't find the settings for it :-(

Jerry Bell :verified_paw: :donor: :verified_dragon: :rebelverified:​

@staustellsimon you have to do it through the web interface- most mobile apps don’t expose that setting

Simon :donor:

@jerry yeah, I am, gone to account, nothing about 2fa that I can see

Simon Zerafa :donor: :verified:

@jerry @staustellsimon

Probably best to set 2FA/SA up via web on a PC. You'll need your phone free for the setup anyway 😉🤷‍♂️

ChickenPwny

@jerry i knew the img had something bad with it xD

🕵CatSalad🐈🥗〰️⁠ℹ️Ꝋℂ

@jerry
I always setup 2FA on every site/account I can by default, but yikes. Signal boosting this #vulnerabilty for awareness

KayleeSerenada

@jerry excellent work, thank you for publishing this!!

Carlos Melero

@jerry seems MFA is mitigating the issue of having a password manager autofilling credentials. *Disable autofill*

Charles Gillogly

@carlosmelero @jerry Thankfully that is always my default setup. It's always a little less convenient, but I've never trusted autofill because of stuff like this.

May 🌲
@jerry oh thats good, im not retarded enough to use browser autofill
Simon :donor:

@JessTheUnstill that works for me, and clearly shows 2FA under Account, but not when I browse to Account, odd

Simon :donor:

@JessTheUnstill hmmmm now it is, and now I just dont know if I was being completely stupid or not

Jess👾

@staustellsimon Yeah I spent a while looking for MFA myself. It wasn't obvious at first.

I think it's because Account isn't expanded by default. So you click on infosec.exchange/auth/edit and there's nothing on that page for MFA.

It's not until you go BACK to the menu that you see the MFA sub menu.

Simon :donor:

@JessTheUnstill I think that must be it! I should be better than this really 😜​

:antifa:‌ω‌:antifa:

@jerry Tho that only works if your browser stores your credentials

@lanika@mastodon.design

@jerry I don't see the option in #Tusky, I will go to the browser but it would be a good idea to get the apps to enforce it too.

lp0 on fire :unverified:

Enabling #2FA was one of the things which I did soon after creating my account (while looking to see what configuration options were present). Just as well that I did.

Go Up