• realitaetsverlust@piefed.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    11 days ago

    And I kinda don’t want to know if complex passwords and low retries before an account gets locked out are enough.

    I’ve created a custom cert that I verify within my nginx proxy using ssl_client_certificate and ssl_verify_client on. I got that cert on every device I use in the browser storage, additionally on a USB stick on my keychain in case I’m on a foreign or new machine. That is so much easier that bothering with passwords and the likes, and it’s infinitely more secure.