<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Two locks are better than one lock, right?🔒 And the same should apply for your online account credentials!]]></title><description><![CDATA[<p>Two locks are better than one lock, right?<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f512.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--lock" style="height:23px;width:auto;vertical-align:middle" title="🔒" alt="🔒" /> And the same should apply for your online account credentials! That's why 2FA, like U2F, stops &gt;99% of automated account attacks.</p><p>Find out more on why you should use U2F <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f449.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--point_right" style="height:23px;width:auto;vertical-align:middle" title="👉" alt="👉" /></p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://tuta.com/blog/why-u2f-is-important" title="What is U2F used for and what are the benefits? | Tuta">
<img src="https://tuta.com/assets/2fa-two-factor-authentication.DTXgkgMz_Z2gv7Py.png" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://tuta.com/blog/why-u2f-is-important">
What is U2F used for and what are the benefits? | Tuta
</a>
</h5>
<p class="card-text line-clamp-3">A U2F security key is important to secure your authentication process. These U2F security keys protect your account from malicious take-over, including pishing attacks. This guide helps you to understand what a U2F security key is and why we at Tuta recommend using one. This helps you to never lose access to your online identity!</p>
</div>
<a href="https://tuta.com/blog/why-u2f-is-important" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://tuta.com/favicon/logo-favicon-192.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />





<p class="d-inline-block text-truncate mb-0">Tuta <span class="text-secondary">(tuta.com)</span></p>
</a>
</div><p></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://files.mastodon.social/media_attachments/files/116/306/393/257/926/504/original/a7f0d48604e51172.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/2df7ae1c-40a7-4f2c-837c-dc48b01951f0/two-locks-are-better-than-one-lock-right-and-the-same-should-apply-for-your-online-account-credentials</link><generator>RSS for Node</generator><lastBuildDate>Wed, 08 Apr 2026 16:40:37 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/2df7ae1c-40a7-4f2c-837c-dc48b01951f0.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 28 Mar 2026 12:07:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Two locks are better than one lock, right?🔒 And the same should apply for your online account credentials! on Sat, 28 Mar 2026 21:05:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/blueluma%40mastodon.social">@<span>blueluma</span></a></span> <span><a href="/user/tutanota%40mastodon.social">@<span>Tutanota</span></a></span> Not true actually, you can download Authnkey from fdroid that provides the "UI" needed for hardware passkeys to work without google play services. <a href="https://github.com/mimi89999/Authnkey" rel="nofollow noopener"><span>https://</span><span>github.com/mimi89999/Authnkey</span><span></span></a><br />Hopefully this helps!</p>]]></description><link>https://board.circlewithadot.net/post/https://social.linux.pizza/users/Cosipa/statuses/116308831573478716</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.linux.pizza/users/Cosipa/statuses/116308831573478716</guid><dc:creator><![CDATA[cosipa@social.linux.pizza]]></dc:creator><pubDate>Sat, 28 Mar 2026 21:05:27 GMT</pubDate></item><item><title><![CDATA[Reply to Two locks are better than one lock, right?🔒 And the same should apply for your online account credentials! on Sat, 28 Mar 2026 19:52:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/tutanota%40mastodon.social" rel="nofollow noreferrer noopener">@<span>Tutanota</span></a></span> I’d rather have a good long password.</p>]]></description><link>https://board.circlewithadot.net/post/https://gts.skobk.in/users/tennoseremel/statuses/01KMV03720A2M1YGQMDK467MKA</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://gts.skobk.in/users/tennoseremel/statuses/01KMV03720A2M1YGQMDK467MKA</guid><dc:creator><![CDATA[tennoseremel@gts.skobk.in]]></dc:creator><pubDate>Sat, 28 Mar 2026 19:52:48 GMT</pubDate></item><item><title><![CDATA[Reply to Two locks are better than one lock, right?🔒 And the same should apply for your online account credentials! on Sat, 28 Mar 2026 16:28:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/tutanota%40mastodon.social">@<span>Tutanota</span></a></span> in France, for banks you have to have a password only with digits and I never saw a proper 2FA with an external app. They are still in the previous century</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/dadinek/statuses/116307743111767453</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/dadinek/statuses/116307743111767453</guid><dc:creator><![CDATA[dadinek@fosstodon.org]]></dc:creator><pubDate>Sat, 28 Mar 2026 16:28:38 GMT</pubDate></item><item><title><![CDATA[Reply to Two locks are better than one lock, right?🔒 And the same should apply for your online account credentials! on Sat, 28 Mar 2026 15:28:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/tutanota%40mastodon.social">@<span>Tutanota</span></a></span> <br />JFC, this should have been the first sentence in that blog.<br />DEFINE ACRONYMS AT THE FIRST USE.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.hachyderm.io/media_attachments/files/116/307/502/925/609/826/original/6d6925e4f4e62223.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/RealGene/statuses/116307508444076271</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/RealGene/statuses/116307508444076271</guid><dc:creator><![CDATA[realgene@hachyderm.io]]></dc:creator><pubDate>Sat, 28 Mar 2026 15:28:57 GMT</pubDate></item><item><title><![CDATA[Reply to Two locks are better than one lock, right?🔒 And the same should apply for your online account credentials! on Sat, 28 Mar 2026 14:01:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/tutanota%40mastodon.social">@<span>Tutanota</span></a></span> Android does not supports security keys by default, you need google play services for this <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f62e.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--open_mouth" style="height:23px;width:auto;vertical-align:middle" title="😮" alt="😮" />‍<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f4a8.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--dash" style="height:23px;width:auto;vertical-align:middle" title="💨" alt="💨" /></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/blueluma/statuses/116307164247525457</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/blueluma/statuses/116307164247525457</guid><dc:creator><![CDATA[blueluma@mastodon.social]]></dc:creator><pubDate>Sat, 28 Mar 2026 14:01:25 GMT</pubDate></item><item><title><![CDATA[Reply to Two locks are better than one lock, right?🔒 And the same should apply for your online account credentials! on Sat, 28 Mar 2026 13:30:53 GMT]]></title><description><![CDATA[<p><span><a href="/user/tutanota%40mastodon.social">@<span>Tutanota</span></a></span> : rubbish.</p><p>Two WEAK locks may be LESS pointless than one WEAK lock, but they're still pointless. Go read <a href="https://www.csoonline.com/article/4147134" rel="nofollow noopener"><span>https://www.</span><span>csoonline.com/article/4147134</span><span></span></a>.</p><p>U2F has been superseded by FIDO2 (hardware keys in WebAuthn mode) and Passkeys (example in Dutch: <a href="https://todon.nl/@ErikvanStraten/116285192238090438" rel="nofollow noopener"><span>https://</span><span>todon.nl/@ErikvanStraten/11628</span><span>5192238090438</span></a>).</p><p>Both WebAuthn methods have advantages and disadvantages.</p><p>If you don't like them, use a trustworthy passwordmanager and:</p><p>• Let it create a unique, random, as long as possible, pw per account</p><p>• Make backups of the pw mngr database</p><p>• Device compromise means "game over"</p><p>• Use Autofill (easy in Android and iOS/iPadOS)</p><p>• If Autofill does not automatically retrieve your credentials, it probably is a fake (phishing) website. Do read <a href="https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/" rel="nofollow noopener"><span>https://www.</span><span>troyhunt.com/a-sneaky-phish-ju</span><span>st-grabbed-my-mailchimp-mailing-list/</span></a></p><p>Please stop misinforming people.<br /> </p><p><a href="https://todon.nl/tags/WeakMFAsucks" rel="tag">#<span>WeakMFAsucks</span></a> <a href="https://todon.nl/tags/Weak2FAsucks" rel="tag">#<span>Weak2FAsucks</span></a> <a href="https://todon.nl/tags/FIDO2" rel="tag">#<span>FIDO2</span></a> <a href="https://todon.nl/tags/WebAuthn" rel="tag">#<span>WebAuthn</span></a> <a href="https://todon.nl/tags/Passkeys" rel="tag">#<span>Passkeys</span></a> <a href="https://todon.nl/tags/AutoFill" rel="tag">#<span>AutoFill</span></a> <a href="https://todon.nl/tags/KeePassium" rel="tag">#<span>KeePassium</span></a> <a href="https://todon.nl/tags/KeePassDX" rel="tag">#<span>KeePassDX</span></a></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://todon.nl/system/media_attachments/files/116/307/032/098/505/089/original/93c7f937898362ca.jpg" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://todon.nl/users/ErikvanStraten/statuses/116307044160577835</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://todon.nl/users/ErikvanStraten/statuses/116307044160577835</guid><dc:creator><![CDATA[erikvanstraten@todon.nl]]></dc:creator><pubDate>Sat, 28 Mar 2026 13:30:53 GMT</pubDate></item><item><title><![CDATA[Reply to Two locks are better than one lock, right?🔒 And the same should apply for your online account credentials! on Sat, 28 Mar 2026 13:01:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/tutanota%40mastodon.social">@<span>Tutanota</span></a></span> its a shame a lot of websites still want to use SMS for their 2FA. I have an account with a big bank that won't allow me to use my preferred 2FA method, while another account I have with a small town bank will let me 2FA with whatever more secure method I want. Get with it people.</p>]]></description><link>https://board.circlewithadot.net/post/https://closednetwork.social/users/guyincognito/statuses/116306926760832301</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://closednetwork.social/users/guyincognito/statuses/116306926760832301</guid><dc:creator><![CDATA[guyincognito@closednetwork.social]]></dc:creator><pubDate>Sat, 28 Mar 2026 13:01:01 GMT</pubDate></item></channel></rss>