Skip to content

Comment on Impact to DigitalOcean customers resulting from Mailchimp security incident

Comments

I do wish DigitalOcean would support WebAuthn/FIDO2. Meaning I could use my Yubikey and other hardware tokens I have.

Instead they only supported TOTP (Google Authenticator is one implementation) second factor which is vulnerable to phishing attacks. But still better than SMS or nothing at all.

On a similar note, Azure only supports U2F with yubikey on select Windows / macOS environments, but Firefox ESR on Debian is not supported at all. Every other service I use supports U2F just fine on Linux, but Microsoft wants Linux users to live slightly more insecure.

https://bugzilla.mozilla.org/show_bug.cgi?id=1530370

Afaict, the bug is that Firefox doesn’t support FIDO2. AzureAD also doesn’t support U2F, which is unsurprising.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.