Cross-posted from: https://sh.itjust.works/post/19987854
We have previously highlighted the importance of not losing your account number, encouraging it to be written down in a password manager or similar safe location.
For the sake of convenience account numbers have been visible when users logged into our website. This had led to there being potential concerns where a malicious observer could:
- Use up all of a user’s connections
- Delete a user’s devices
From the 3rd June 2024 you will no longer be able to see your account number after logging into our website.
- “Hiding account numbers”. Mullvad. 2024-05-27. Mullvad Blog (https://mullvad.net/en/blog/2024/5/27/hiding-account-numbers).
- Archive
A FIDO2 hardware key should do the trick. Not all MFA are based on communications.
Why can’t you use FIDO2 hardware keys on a router? I have a PC running openBSD as a Router and I can use hardware keys.
So you are running a full-fledged OS on a standalone computer that functions as a router. An actual router has a very limited operating system with no such functionality, plus it’s always online by design, so you’d basically have to have a key that is permanently plugged in; or depending on the setup you’d have to re-authenticate ever so often. Not exactly great considering most routers are hidden somewhere in an inaccessible corner.