This solution seems ripe for exploitation by putting your passwords (if you store your passwords on your computer) and 2FA on the same machine.
This solution seems ripe for exploitation by putting your passwords (if you store your passwords on your computer) and 2FA on the same machine.
Come to think of it, I'm not sure that's a problem with the cookie and not with TOTP.
Of course, keeping the token on the same machine that you're using for logging in is reducing the security, but then, the token is stored in the Keychain and once you're at the point where malware is so deeply hooked into the system that it has access to the system Keychain, then it can also inject itself into your browser and get a 2FA token whenever you log in.
If you use Authy on your phone, they have long had a chrome extension that allows you to get your codes on your computer, already for years and that works with all your existing codes rather than this which is limited to just GitHub currently it sounds.
But hopefully someone else can comment on the security improvements of Soft U2F or if its more just building a standard rather than people having to rely on Authy or such.
The main difference is that U2F is phishing-resistant because it binds keys to the origin. TOTP, on the other hand, can still be phished.
(I believe Authy attempted to solve some of this with their browser extension for sites that use their first-party integration, rather than just for users using Authy as a generic TOTP app. I would generally avoid their first-party integration because of their reliance on SMS.)
At that point, your laptop is basically your 2nd factor - which this software is pretty similar to.
It kinda can, it just needs to trigger a dialog the user thinks looks legit. Or easier, just stay resident until the next time the user pushes the button.
Don't get me wrong, U2F has benefits, but it's not invulnerable to malware designed for it. You want real system level protections to back it up and most users aren't running on operating systems that can really cash the check you're trying to write with that threat model.
I think that may be Project Fi specific. To my knowledge, Hangouts doesn't do SMS anymore except for Project Fi customers, and even prior to them forcibly removing SMS handling from Hangouts on my Samsung and telling me to find something else after an update, it never synced SMS messages it to other Hangouts instances.
Not saying it was a good idea for security, but that probably made it easier to justify internally.
And the real danger of cell phones and SMS is account recovery processes that SMS a recovery code to your cell. That's way more concerning than 2fa via SMS IMO.