edric
link
fedilink
68M

Everything else can either be replaced, or is on my own infrastructure.

I’m curious, do you have accounts on other social media? Also, do you have any accounts on sites like shopping, government sites, etc.? And if you do, do you intentionally not use MFA (if it’s available) because you believe it should be those services making sure you are secure instead of you taking steps to make it harder to compromise your accounts?

Have you looked at it from this angle?: MFA is one of the steps that service providers are doing to be responsible with securing your account.

Security is a never ending game of cat and mouse, and the malicious actors are always a step ahead. There’s no such thing as being 100% secure, so both sides have to take steps to secure a transaction. If you believe security is 100% the burden of the provider, then we shouldn’t be using passwords and password managers in the first place, because the burden of having to maintain, secure, and memorize passwords shouldn’t be on the consumer. That’s great in theory, but not possible in practice, at least in the present.

It’s kinda weird that you like to have your own agency on things (i.e. own infrastructure) yet the minute you need to use a third party service, you let go and put everything on the service, KNOWING they are not doing a good job with it.

aard
link
fedilink
-88M

And if you do, do you intentionally not use MFA (if it’s available) because you believe it should be those services making sure you are secure instead of you taking steps to make it harder to compromise your accounts?

Yep. We can discuss me using a second factor once they start designing their services better.

Payment on such sites is set to require approval via my bank (hardware token), I don’t care about the purchase history - so if somebody manages to breach the account and order something it’s entirely their problem, not mine. I’m aware they might close my account when confronted with that attitude, but I’m also fine with that.

so both sides have to take steps to secure a transaction

My passwords are stored locally encrypted, with the encryption key stored in a hardware token. The browser doesn’t have access to that. That’s already more than a lot of sites are doing for their security…

yet the minute you need to use a third party service, you let go and put everything on the service, KNOWING they are not doing a good job with it.

That’s exactly why I treat any 3rd party service as throwaway.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 2.44K Posts
  • 57.6K Comments
  • Modlog