• 0 Posts
  • 50 Comments
Joined 1 year ago
cake
Cake day: June 14th, 2023

help-circle


  • Could a hypothetical attacker not just get you to visit a webpage, or an image embedded in another, or even a speculatively loaded URL by your browser. Then from the v6 address of the connection, directly attack that address hoping for a misconfiguration of your router (which is probable, as most of them are in the dumbest ways)

    Vs v4, where the attacker just sees either your routers IP address (and then has to hope the router has a vulnerability or a port forward) or increasingly gets the IP address of the CGNAT block which might have another 1000 routers behind it.

    Unless you’re aggressively rotating through your v6 address space, you’ve now given advertisers and data brokers a pretty accurate unique identifier of you. A much more prevalent “attack” vector.



  • Ok. Did a quick read. And I think I mixed my words a little.

    Yes, Active Directory supports TOTP fine.

    But my understanding is rollouts can disable TOTP, and instead force the use of the proprietary scheme requiring the MS Authenticator app (which also supports TOTP) that uses push notifications to the device.

    As is the case with my employer. They didn’t enable TOTP, and I am unable to use the provided MFA QR code with 1Password.