56
CRA now allows 2FA apps
(infosec.pub)
What's going on Canada?
🍁 Meta
🗺️ Provinces / Territories
🏙️ Cities / Local Communities
🏒 Sports
Hockey
Football (NFL)
unknown
Football (CFL)
unknown
Baseball
unknown
Basketball
unknown
Soccer
unknown
💻 Universities
💵 Finance / Shopping
🗣️ Politics
🍁 Social and Culture
Reminder that the rules for lemmy.ca also apply here. See the sidebar on the homepage:
Yes but you’re free to use an email provider which also supports security keys, which gmail and proton mail* do. I understand that the CRA needs to accommodate the average person who doesn’t care about security, but I think everyone in this thread appreciates when they also cater to people who care deeply about security and are willing to use strong unique passwords in a password manager and security keys or at least TOTP.
*
it seems like they require keeping TOTP enabled because their mobile apps don’t support security keys. Meh.To clarify on this: even the people who use gibberish as their password and don’t store it and rely on password resets via email are actually somewhat safe if their email is also highly safe. Maybe their password strategy for CRA implies they don’t take their email password security seriously either… but still, my point is just that “at least as secure as your email” can be an incredibly high bar if you do it right