Krypton: phone-based U2F Authenticator
krypt.co
krypt.co
You weren't kidding. :(
"Free as in beer, not as in speech."
You're welcome to pick your own license / source availability terms for your own work.
[0] https://en.wikipedia.org/wiki/Source-available_software [1] https://www.oracle.com/technetwork/java/scsl-1-1-149938.txt
Looking at all-rights-reserved code on a public repository on GitHub is like going to a strip club - you may look, but you can't touch.
>Feel free to compile Krypton from source and run it on your phone and workstation. [0]
I've not tried it, but they also suggest you can compile your own binaries from that source to get around the untrusted binary problem.
You could... Except that, if I'm not mistaken, "All Rights Reserved" doesn't allow you to compile and use the code in any way, including diffing.
IINAL, is that an incorrect reading?
We are granted a license to use it on GitHub by the GitHub ToS.
https://help.github.com/articles/github-terms-of-service/#5-...
They give permission to compile on the website. Otherwise you would be correct.
you can say the same about all the other open source projects that don't have reproduceable builds.
I understand that's a lot of "ifs", but even if it was fully open source, it's hard to use it in anyway that's scale-able, since hardly anyone wants to compile it themselves, and hardly anyone can get it on to their phone by themselves in some ecosystems
It sure would be nice to have some process to ensure my phone was running what I thought it was, even if it required publisher opt-in (and even if it requires I trust the phone OS).
This is interesting, because at work pretty much all of our logins (including for third-party services) go through SAML, where our IdPs use Duo for two-step. That gives us similar functionality to this, without needing to use a browser plugin. You do need to use an app, though, to avoid insecure SMS or voice.
(Duo does support U2F, but it's not as obvious, because end users have to initiate the setup, and Duo instances that existed before U2F became available have it turned off—instance-wide—by default.)
One thing you could do, assuming work uses Duo and U2F support is on: You could have a singly Krypton install for both personal and work (particularly if you have one mobile device). Then, enroll Krypton as your U2F device in Duo.
I'm kindof surprised that either Duo or LastPass haven't bought out krypt.co yet…
Would be the perfect move for LastPass - around the beginning of this year Lastpass started a beta program for LastPass connect [0], however, was suddenly put on hold [1][2], and I think krypt's technology would be the perfect candidate to pull together the app.
I also trust LogMeIn much more than I trust Krypt to not push out malicious binaries, so there's a plus for that.
1: https://judge.sh/VBRJP4n.png
2: https://www.androidauthority.com/lastpass-connect-861342/
What if I lose my phone?
Many websites require a backup two-factor authentication methods such as SMS and TOTP (authenticator 6 digit-code apps) even if you are using a U2F security key such as Krypton. For certain sites that allow U2F only (such as Google Advanced Protection), we recommend having a backup phone with separate Krypton U2F key setup or a physical hardware key that you store securely in somewhere.
We are actively building a robust account recovery service with partners to solve this problem and make U2F/WebAuthn a viable "single-factor" login system. We hope this will remove the need for these backup methods that make your account vulnerable to phishing attacks. We also see this as a major barrier to wide adoption of U2F/WebAuth/2FA so we are eager to solve this problem.
I understand their argument about security vs. usability for laypeople as it's an age old one, but I think that applies better to situations where there's a marked tradeoff in principle.
Tapping just once or reaching for one's phone doesn't detract from usability. Quite the contrary, it's a common sense approach (and teaches common sense security posture) to give one's explicit agreement for authentication, U2F or otherwise.
Otherwise, the intended user base that zero-touch seems to target may end up being the same folks that question why it didn't work out of the box to protect their logins when their laptop gets physically compromised; since they assumed they didn't have to "understand or care about the differences between two-factor, U2F, or web authentication" in the first place, to quote the FAQ.
This is brilliant. I love it!
Now please fix the licensing, make the core open-source, be a bit more transparent, and get audited. It would really inspire a lot more confidence in a tool whose target audience is currently the security paranoid crowd.
Edit: I didn't realize that they publish the source code, but with a non-FLOSS license.
That's completely unfair. U2F was from the start designed to be rendered in this kind of form factor. "All" Krypton (and Duo, BTW) did was implement this obvious form factor.
U2F itself, was the hard problem.
And anyway, push 2FA has been around for approx. as long as U2F. It may not be obvious now, but U2F will ultimately die in favor of push. IMHO. (they each have strengths and weaknesses but overall push is better.)
As far as UX goes it's identical to the user.
That's why Krypton is better. It works everywhere U2F (an open spec) is supported, while the proprietary company solution is supported where the company has partnered
U2F has traditionally been distributed in the form of physical tokens. It's an open standard compared to Duo's.
(The rest is just copied off another comment I made down this thread)
But there in lies the difference. With Krypton, the company doesn't own your keys, you do. It's like Fiat vs Bitcoin.. only there's literally no difference in experience.
That's why Krypton is better. It works everywhere U2F (an open spec) is supported, while the proprietary company solution is supported where the company has partnered
You pair your phone and browser and then they can talk. Any time you want to log in through that browser it can talk to your phone and auth you automatically. For someone to exploit this, they'd need access to the computer with your browser.
So if your laptop gets stolen, yes this is a bad idea, but I think most people think that they can just revoke the browser's keys if if the laptop gets stolen and they are way more likely to have their phone stolen anyway.
1. Wait for user to sign in. 2. Intercept their sign in. 3. User: "Oh, it didn't work. I'll just try again." 4. User tries again and it works. Attacker is also logged in now.
Alternatively, at that point you could just inject JS into whatever website needed 2FA and do everything without the user noticing anything.
I typically authorize the host for three hours, meaning for the next three hours I don't have to Touch ID in again.
https://www.howtogeek.com/336775/how-to-enable-and-use-windo...
It's listed in their docs.
That's a slight bummer because now there's another service dependency in your authentication flow. It's probably pretty rare that SQS will go down, but still is a bummer.
This is horrible. Now the security of it is tied to the security of the stuff they have running in Amazon. Which they probably don't publish source code for? Even if they do, you have no way to know that is what is actually running.
Not the mention reliability and availability concerns.
ah well, I had such high hopes.
So as long as the source code for both parts (browser-side and phone-side) is there, and you can audit that the code viewable is the code installed, this is pretty solid.
Of course the reliability and availability issue is still there.
On iOS it works for Google logins, see the blog post here: https://krypt.co/blog/posts/use-google-advanced-protection-w....
I'm not saying Krypton is bad, just that you're installing an extension that (I imagine) interacts with a server to send a push to your phone. It's a very different security model than keys, that require no extension and don't interact with any 3rd party.
Update: I'm seeing that my comment is read as negative, and I don't want to give this impression. I think Krypton is great, I use 2FA over push notifications all the times myself. I was just trying to reply to the "has it been audited?" question.
Edit: changed chrome extension -> extension according to comment below.
From the FAQ:
"The Krypton browser extension currently only works on Google Chrome and Firefox.
Safari, and Edge are coming soon."
Also, it supports U2F. From the FAQ:
"Krypton supports any site that supports U2F security keys."
U2F is one of the two protocols supported by the FIDO standard (the other one is UAF). This doesn't say anything about whether this uses FIDO (v1) or FIDO2 though.
I think this is pretty cool from a user friendly PoV. Google Android has something similar. The Facebook app doesn't AFAIK (I quit Facebook so cannot verify), but Battle.net does and so does Microsoft Authenticator. The disadvantage is that you need all these separate apps. I'd rather use just one.
And phones makers are starting to adopt "hardware security modules" (just Pixel 2 so far, not sure about the new Samsung ones) and Android 9 is giving app developers access to them via API.
So I guess in theory one could turn the phone into an actual "U2F security key," for all intents and purposes?
I would hope so. Anything less is not secure. (This is one of the basic "problems" with hardware authentication.)
However, the software model allows for pre-arranged cloud sync between multiple devices. Given how Krypton handles PGP/SSH this support isn't there, but there's no technical obstacle.
You just need a device that you tell it some master key, or that can export it for you. eg a true ($$$$$) HSM can do this, exporting keys that can [only] be imported to another device configured for the same security "world".
I charge $500/hr for security consulting, 1 week minimums, and am fully booked for months out. I have 20 years in security experience. I'd say I "get it".
I specialize in security UX.
Don't mistake my absolute position on what is secure vs what is usable and what will be used. In general I am a critic of U2F.
All the problems you have stated are real, and you are correct, however the way to overcome them is NOT to have the device keep/use the secret "insecurely". Watch Apple's blackhat talk from last year for some insight into the problem and a usability-friendly yet still secure approach.
It's a hard problem, not one that is going to be solved here on HN discussion.
Security is literally spending resources to protect something. Time is a resource. Space in your brain is a resource.
If I want to secure a city, I spend labor and materials to build a wall. If I want to secure my documents, I spend money on a safe. If I want to secure my emails, I spend brain space and time dealing with passwords.
You can argue that the resource <--> security tradeoff is too expensive and that being insecure is a better choice, but just because something is harder doesn't mean it's less secure. People make that choice every day. When someone reuses a password, they are choosing to not use brain space and instead be less secure.
Plenty of HSMs can export secrets. It's straightforward to have them make a regular export, encrypted such that only the backup HSM can read them.
Edit: You simultaneously made a comment saying almost exactly the same thing, so now I really don't understand why you would say anything less than "redo from scratch" is insecure. Is there an unstated assumption of "if you have no other device"? Because that was not clear at all.
(although I can't access the <teams> section of the app on an iPhone 5SE)
1. sharing a secret (which is bad, and possibly already compromised by the time it reaches your device (phone))
2. permanent attention to the domain. Remember similarities between the cyrillic a and latin a? (phishing, etc.)
even without that, it is what U2F was always destined to become.
it's especially better than u2fzero. ;)
genuinely curious: why? (disclaimer: I'm working on Solo, the successor of u2fzero)
Again, I'm not trying to downplay Krypton, I like the phone solution a lot, I think it's much more usable than security keys. I use push notifications all the times e.g. via DUO. But I still think we need physical security keys against online attacks, for example as a mechanism to secure your phone itself.
Hopefully other sites support iOS based callbacks soon.
By reading the website it seems they are doing the same thing as Duo.
Is "zero touch" secure? How is it a second factor if it approves automatically? Yes, zero touch is safe. The security behind Krypton is established when you pair Krypton with your browser (via the extension) by scanning the QR code. This ensures that only your specific browser will be able to talk to Krypton. Krypton and your browser establish a secure cryptographic channel using keys that only your phone and computer have. There is NO trusted third-party.
Two-factor is simply a way to defend against compromised passwords. If someone knows your password and attempts to login then they'll be hit with a second-factor challenge. Since this attacker is remote and doesn't have access to your browser they won't be able to talk to Krypton.