Two Factor Auth List of Websites
twofactorauth.org
twofactorauth.org
Edit, examples:
No 2 factor authentication
Displaying the answers to your security questions in multiple choice form (with a none of the above option, but usually including your answer).
Requiring your password to be entered with mouse clicks at an on-screen keyboard. Not kidding.
Those ridiculous "anti-phishing" pics.
TradeKing is the definition of security theatre.
Do not use TradeKing.
Kill it before it lays eggs.
> Requiring your password to be entered with mouse clicks at an on-screen keyboard. Not kidding.
[x] Bad security
[x] Bad usability
(Edit: apparently unicode checkmarks are filtered out on input now)
This is like the personification of a lose-lose interpretation of AviD's rule of usable security.I started working on a vendor-agnostic 2FA implementation for PHP projects.
https://github.com/paragonie/multi_factor
It's far from complete, but hopefully it makes it easier for others to add 2FA to their projects.
If anyone's interested in the open source CMS I mentioned: https://github.com/paragonie/airship
There have been technologies to try to bridge the identity islands -- social login (which previously created trust issues through OAuth abuse - many resolved, but trust is hard to win back), Mozilla persona and others. But, at the end, the hostility of end user identity is still a problem that needs to be solved in such a way that end users have good authentication choices (no more bad security questions, for example) with good security attributes (low replay, discoverability and guessability, for example) with good usability. Ideally, an end user should be able to choose an identity provider, trust them, and then use that identity provider across multiple services. I know that some companies are working on this, but it still tends to be in islands, rather than an industry group, for example, dedicated to making it work. At this point, a de facto standard may be the best thing.
I've been in meetings with IAM architects at large banks who scoff at social login because they don't want to trust social login security, yet their own end user security is marginal. Some honest conversations need to happen in this space to help move things forward.
Better identity infrastructure for end users will help service providers.
Whoop. Looks like the tiling system is relying on JavaScript instead of <a> tags for links:
``` <div id="communication" class="category column" style="display: block;"> <h5 class="ui icon header"> <i class="circular chat icon"></i> <small>Communication</small> </h5> </div> ```
The contributors are pretty responsive, so I'd recommend noting the issue: https://github.com/2factorauth/twofactorauth/issues
An anchor would be good here if the clicking the icons also triggered a URL change, but as it stands a button would be semantically most appropriate
[1]: (http://blogs.ancestry.com/techroots/buttons-vs-anchors/)
Also, proper HTTPS and HTTPS-only support. There are still way too many sites that offer HTTP as a valid option.
Citibank does support it, but only on their "Gold" accounts.
Some backstory on that decision: the site originally had columns for each 2fa company/product you could use; e.g., Google Authenticator, Authy, etc. Listing all the options was not scalable as the number of options grew, so twofactorauth.org went with a more abstract classification based on the second factor interaction. A few examples where that matters: * If you refuse to use an easily misplaced fob then you might avoid sites that only offer hardware 2fa. * Not everyone can receive SMS, but maybe they can download an app (software) or reuse their hardware token. * Some people prefer a voice call, so they might choose a bank that allows for 2fa-over-voice.
Hope this helps.
Just do it.
Also, I'm not aware of Google Authenticator being updated. Which makes me concerned that it's not a priority for Google and might be end-of-lifed.
If you use a different client, you can probably find one that will let you back up codes (I'm sure Authy supports TOTP). Also note that all you need for that backup is a "seed", which is a hash. IIRC Google Authenticator uses SQLite to store its data, I bet it's not hard to get the seeds out and back them up manually.
Things with backup or sync are risky, they add additional ways your authenticator can be compromised. There's an alternative that's similarly useful, but far more secure. When you add a 2FA code, print the QR code presented by the website and store it somewhere very secure in real world space. You can later scan it with any TOTP app, and it'll add the identical authenticator to another device.
1. Banks and finance sites do not implement 2FA enough.
2. All crypto sites have 2FA.
3. No airline website has 2FA.
I have more hope for U2F as second factors go. That is at least easy to work with once you have bought the token. I find it a joy to use.
I'm not sure I agree with that.
Generating a code:
<?php
use ParagonIE\MuiltiFactor\Vendor\GoogleAuth;
use ParagonIE\MultiFactor\OTP\TOTP;
$seed = random_bytes(20);
/** Then persist $seed into the database for a user **/
$gauth = new GoogleAuth($seed, new TOTP());
header("Content-Type: image/png");
$gauth->makeQRCode();
Validating a code: <?php
use ParagonIE\MuiltiFactor\Vendor\GoogleAuth;
use ParagonIE\MultiFactor\OTP\TOTP;
if (\password_verify($_POST['password'], $storedHash)) {
$seed = /** Get seed from database for this user **/;
$gauth = new GoogleAuth($seed, new TOTP());
if ($gauth->validateCode($_POST['2facode'])) {
// Login successful
}
}
Then you can just use the 2FA app of your choice (Authy, Google Authenticator, etc.), scan the QR code, and you're good to go.The fact is people hate typing stuff from their phone into their computer. Specially if you phone is not always within reaching distance. If you have to do it with tons of different logins you will be annoyed. As long as you have 1-2 accounts its fine, but if we really want to role it out everywhere, we need something better.
Neither of these things is a barrier.
I recently forgot my phone at university and realized that I was potentially locked out of many websites.
stupid but works
s/can't/won't
Not saying you don't have a valid complaint, but let's not forget what can't means.