Skip Navigation
Why every TOTP app default uses SHA-1 hash encryption?

I use Aegis as my 2fa. Today on new token creation I observed that there's hash function set to SHA-1, later checked all my tokens and the result is same type of encryption used for all. So I have edited all my tokens to SHA-256 as a result my totp doesn't authenticate. Do I have to rescan my tokens for updating to SHA-256 or it doesn't work like that?

Security: SHA-1 < SHA-256 < SHA-512

Speed: SHA-1 > SHA-256 > SHA-512

My doubts are: Why can't we use SHA-256? Is it because TOTP requires less time so faster one(SHA-1) is chosen? Can we use SHA-256 for TOTPs?

11
Something's off lately with Proton VPN free tier.

Websites and apps are not loading, sometimes buffering on connecting with majority of servers like Netherlands, Japan etc.. available on free tier.

I am also getting this message/popup while running proton VPN for long time i.e. "Device limit exceeded, join plus..." though i am using single device. lol

I know I know nothing comes for free and you need to compromise lot of stuff when it comes for free.

But I just want to address there are more issue with free tier proton vpn after the recent update (keeping timeout for changing servers, not able select server of you choice among the 5 free tier servers like previously).

I am thankful for you people increasing freebies like extended drive space from 1gb to 5gb and added two other countries i.e. Romania and Poland for Proton VPN free tier but at the same time changed the other features like mentioned above. This make me feel that old one is far better compare to now.

Afterall, these are maybe the tactics used by the company on persisting to buy their plus tier.

1
Locked Removed
"ProtonMail is subject to surveillance due to its location in Switzerland." Thoughts on the video.
  • Take a chill pill. There is nothing called privacy if you are using internet. If not the big bro companies, we are only left with companies like proton which is widely popular in privacy community. I recommend to use different service providers rather completely relying on one company. Example: Mail - Proton, VPN - Mullvad, Drive - FIlen with cryptomator etc.

  • Locked Removed
    "ProtonMail is subject to surveillance due to its location in Switzerland." Thoughts on the video.
  • I do have concerns about Proton since I am using their products and services.

    Their payment methods doesn't include options like Monero or atleast through other cryptocurrencies. They have this anonymous data collection, ofc we can disable it. And it has this ip log info for "checking unknown entities". Can they completely disable or remove this feature from their code? So they can proclaim they are "unable to log" instead they "do not log" - I think you know the french activist incident. Btw I am not here to blame them.

  • Thoughts on Kagi?
  • It's great using their Fastgpt which gives accurate results from various forums and websites, where other gpt based search engines lack. And got to try their Summarizer.

    I recommend to use it as Secondary source (with tempmails) and Primary remains SearX for sure.

  • InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)PR
    PrivacyWayFinder @lemmy.world
    Posts 3
    Comments 10