Why this matters
Most account compromises we handle start with a stolen password — through phishing, reuse across sites, or a data breach elsewhere. Multi-factor authentication (MFA) adds a second check (an app prompt, security key, or one-time code) so a stolen password alone is not enough to sign in.
Recommended actions
- Turn on MFA for your GARNET email and any service that offers it. Prefer an authenticator app or a hardware security key over SMS codes where possible.
- Register a backup method (a second device or recovery codes) so you are not locked out if you lose your phone.
- Use a unique password per service — a password manager makes this practical.
Need help?
If you are unsure how to enable MFA on a specific service, or you manage a system for the community and want to require MFA, contact the team. This advisory is informational — there is no active threat tied to it, but acting on it meaningfully reduces your risk.
This advisory is published with a detached PGP signature against the CSIRT key. Confirm it is genuine and unmodified before acting:
Downloads: source .md · signature .md.asc · public key. Check the fingerprint (684C7B7DA77E4F1B68AED3ECE84B541C6184CC6F) on the PGP page — if gpg reports a “Good signature” from that key, this advisory is authentic.
Think a system in the community is affected or compromised?Report an incident