this post was submitted on 03 Jul 2024
118 points (100.0% liked)

Cybersecurity

5594 readers
152 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] schizo@forum.uncomfortable.business 28 points 3 months ago (1 children)

What confuses me is even a half-competent audit and pentest would absolutely have found an api endpoint that's going to absolutely leak customer data, so the assumption I have to make is that, yet again, a "security" company can't be fucked to do the bare minimum to ensure their security shit is you know, secure.

[–] LordKitsuna@lemmy.world 8 points 3 months ago (1 children)

Posting this against your comment for visibility, I would recommend anyone that was using authy switch to bitwarden's dedicated 2F authentication app. The company maintains several security compliance certificates and fairly regularly gets audited which they post publicly at https://bitwarden.com/help/is-bitwarden-audited/

Oh neat. I use their password manager but totally somehow missed them releasing a separate 2fa app.