⤷ Title: How I Designed Multifactor Authentication In An Enterprise Application
════════════════════════
𐀪 Author: Amresh Singh
════════════════════════
ⴵ Time: Sat, 25 Jan 2025 17:06:40 GMT
════════════════════════
⌗ Tags: #application_security #authentication #system_design_interview #mfa #totp
════════════════════════
𐀪 Author: Amresh Singh
════════════════════════
ⴵ Time: Sat, 25 Jan 2025 17:06:40 GMT
════════════════════════
⌗ Tags: #application_security #authentication #system_design_interview #mfa #totp
Medium
How I Designed Multifactor Authentication In An Enterprise Application
In this article I share my experience of designing and implementing MFA feature in an enterprise application.
👏1
⤷ Title: HOTP 與 TOTP:一次性密碼的原理與差異
════════════════════════
𐀪 Author: Atlancube 涵容科技
════════════════════════
ⴵ Time: Sun, 02 Feb 2025 13:50:09 GMT
════════════════════════
⌗ Tags: #hotp #otp_verification #technology #totp #cybersecurity
════════════════════════
𐀪 Author: Atlancube 涵容科技
════════════════════════
ⴵ Time: Sun, 02 Feb 2025 13:50:09 GMT
════════════════════════
⌗ Tags: #hotp #otp_verification #technology #totp #cybersecurity
Medium
HOTP 與 TOTP:一次性密碼的原理與差異
隨著網路服務的普及與駭客攻擊的增長,使用者帳號的安全性變得至關重要。除了傳統的帳號密碼登入方式,一次性密碼(OTP, One-Time Password) 也是目前廣泛應用的身份驗證技術,能有效防範密碼竊取與重放攻擊。
⤷ Title: Microsoft Authenticator for iOS: Cloud Backups Arrive, Ditching Personal Accounts
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:08:03 +0000
════════════════════════
⌗ Tags: #Microsoft #Apple ID #backup #enterprise #icloud #ios #MFA #Microsoft Authenticator #security #TOTP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:08:03 +0000
════════════════════════
⌗ Tags: #Microsoft #Apple ID #backup #enterprise #icloud #ios #MFA #Microsoft Authenticator #security #TOTP
Penetration Testing Tools
Microsoft Authenticator for iOS: Cloud Backups Arrive, Ditching Personal Accounts
Microsoft Authenticator for iOS gets a new backup system in September, using iCloud instead of personal accounts to streamline TOTP code management.
⤷ Title: iOS Update: Proton Authenticator Bug Leaked TOTP Secrets in Plaintext Logs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 07:12:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #ios #MFA #Plaintext Logs #Proton Authenticator #Secrets #TOTP #update #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 07:12:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #ios #MFA #Plaintext Logs #Proton Authenticator #Secrets #TOTP #update #Vulnerability
Daily CyberSecurity
iOS Update: Proton Authenticator Bug Leaked TOTP Secrets in Plaintext Logs
Proton has patched a critical flaw in its iOS Authenticator app (v1.1.1) that logged TOTP secrets in plaintext. Users are urged to update immediately to secure their accounts.
⤷ Title: TOTP in the Clear: Proton Authenticator’s Privacy Misstep on iOS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:40:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #ios #MFA #Plaintext Logs #Proton Authenticator #Secrets #TOTP #Update #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:40:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #ios #MFA #Plaintext Logs #Proton Authenticator #Secrets #TOTP #Update #vulnerability
Penetration Testing Tools
TOTP in the Clear: Proton Authenticator’s Privacy Misstep on iOS
Proton Authenticator for iOS exposed TOTP secrets in plaintext logs, risking 2FA account leaks. A swift patch fixed it—but trust may take longer.
⤷ Title: Google Password Manager Arrives as a Standalone App on Android
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 22 Aug 2025 04:07:28 +0000
════════════════════════
⌗ Tags: #Android #Android security #Chrome sync #Google Password Manager #Google Play #Passkeys #password management #TOTP
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 22 Aug 2025 04:07:28 +0000
════════════════════════
⌗ Tags: #Android #Android security #Chrome sync #Google Password Manager #Google Play #Passkeys #password management #TOTP
Daily CyberSecurity
Google Password Manager Arrives as a Standalone App on Android
⤷ Title: TOTP Demystified: How Time-based One-Time Passwords Secure Your Logins
════════════════════════
𐀪 Author: Aditya Ramaswamy
════════════════════════
ⴵ Time: Sun, 28 Sep 2025 11:18:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #authentication #2fa #totp #mfa
════════════════════════
𐀪 Author: Aditya Ramaswamy
════════════════════════
ⴵ Time: Sun, 28 Sep 2025 11:18:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #authentication #2fa #totp #mfa
Medium
TOTP Demystified: How Time-based One-Time Passwords Secure Your Logins
A deep dive into Time-Based One-Time Passwords (TOTP)
⤷ Title: Critical Cal.com Flaw (CVE-2025-66489, CVSS 9.9) Allows Authentication Bypass by Submitting Fake TOTP Codes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:22:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #Account Hijacking #Authentication Bypass #Cal.com #Critical Vulnerability #CVE_2025_66489 #TOTP
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:22:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #Account Hijacking #Authentication Bypass #Cal.com #Critical Vulnerability #CVE_2025_66489 #TOTP
Daily CyberSecurity
Critical Cal.com Flaw (CVE-2025-66489, CVSS 9.9) Allows Authentication Bypass by Submitting Fake TOTP Codes
A Critical (CVSS 9.9) Auth Bypass flaw (CVE-2025-66489) in Cal.com allows attackers to bypass password checks and hijack accounts by supplying any value in the TOTP field. Update to v5.9.8.
⤷ Title: “CL Suite” Deception: Malicious Chrome Extension Steals 2FA Secrets and Meta Business Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 00:07:00 +0000
════════════════════════
⌗ Tags: #Malware #2FA Theft #Account Takeover #CL Suite #Cyber Security #Facebook Business #Instagram Business #Malicious Chrome Extension #Meta Business Suite #Socket Threat Research #TOTP Seeds
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 00:07:00 +0000
════════════════════════
⌗ Tags: #Malware #2FA Theft #Account Takeover #CL Suite #Cyber Security #Facebook Business #Instagram Business #Malicious Chrome Extension #Meta Business Suite #Socket Threat Research #TOTP Seeds
Daily CyberSecurity
"CL Suite" Deception: Malicious Chrome Extension Steals 2FA Secrets and Meta Business Data
"CL Suite" Chrome extension steals Meta Business 2FA seeds & data. Attackers bypass security even after uninstall. Reset 2FA immediately.
⤷ Title: SonicWall Issues Critical Patch for SMA 1000 Series to Stop SQL Injection and MFA Bypasses
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:44:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_4112 #CVE_2026_4114 #CVE_2026_4116 #cybersecurity #infosec #MFA Bypass #privilege escalation #SMA 1000 #SonicWall #sql injection #TOTP #Unicode Encoding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:44:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_4112 #CVE_2026_4114 #CVE_2026_4116 #cybersecurity #infosec #MFA Bypass #privilege escalation #SMA 1000 #SonicWall #sql injection #TOTP #Unicode Encoding
Daily CyberSecurity
SonicWall Issues Critical Patch for SMA 1000 Series to Stop SQL Injection and MFA Bypasses
SonicWall patches critical SMA 1000 flaws, including a 7.2 SQL injection for privilege escalation and Unicode-based MFA bypasses. Secure your VPN—update now!
⤷ Title: Juice Shop Write-up: Two Factor Authentication Challenge
════════════════════════
𐀪 Author: ~ Jeff ~
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 13:07:21 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #totp #owasp_juice_shop #broken_authentication #sql_injection
════════════════════════
𐀪 Author: ~ Jeff ~
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 13:07:21 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #totp #owasp_juice_shop #broken_authentication #sql_injection
Medium
Juice Shop Write-up: Two Factor Authentication Challenge
The goal of this challenge is to bypass the 2FA mechanism by retrieving a user’s TOTP secret from the database and using it to generate…