nanog mailing list archives

Re: FYI - 2FA to be come mandatory for ARIN Online? (was: Fwd: [arin-announce] Consultation on Requiring Two-Factor Authentication (2FA) for ARIN Online Accounts


From: Peter Beckman <beckman () angryox com>
Date: Fri, 27 May 2022 23:53:29 -0400

On Wed, 25 May 2022, Crist Clark wrote:

FIDO2

 I'm in full support of ARIN implementing FIDO2 IN ADDITION TO TOTP 2FA.

 For the uninitiated -- FIDO2 requires you to have one of the following in
 order for you to log into your ARIN account:

    - A security key (like Yubikey): USB, NFC, Bluetooth
    - A mobile device capable of biometric confirmation (FaceID, TouchID,
      etc)

 FIDO2 does NOT support older browsers, text-based browsers, and generally
 non-mainstream modern devices.

 Not to be confused with FIDO U2F, which is basically what TOTP 2FA is,
 just implemented differently.

Beckman
---------------------------------------------------------------------------
Peter Beckman                                                  Internet Guy
beckman () angryox com                                https://www.angryox.com/
---------------------------------------------------------------------------


Current thread: