The bleak picture of two-factor authentication adoption in the wild
elie.net
elie.net
Where as I feel I'm still waiting for my bank (actual money) to catch up. they took the easy way out by sms-ing me a second factor authentication key. Even though phone number theft is a known attack vector.
YubiKeys can store and access OTP secrets. I put the secret in both Google Authenticator and my YubiKeys as backup.
They refused a refund as well.
Horrifically bad company customer service, UX, UI. Save yourself the trouble and skip them, call 1Password.
On the one hand a password could be popped from the target site or phishing, and you’d still need the 2nd factor from 1password to get in.
But on the other hand, if you leave your phone lying around unlocked with a poor master password, both get popped together.
Thankfully Google Authenticator is just TOTP, so you can use whatever client you want.
Open source and supports backups.
andOTP is just what I was looking for since it's FOSS and had backup! This would have been a lifesaver when I lost my phone but glad to have run into it now.
TOTP sounds much better. Also doesn't requires "trusted magic hardware"
It did the work and even today I use it every now and then, instead of pulling out the mobile.
This probably undermines the idea - but phones get lost/destroyed/wiped regularly.
i worked at a major semiconductor company in the late 1990's and to use their VPN from home you needed an authenticator fob. eventually this was replaced with a password, but hardware fobs (& parellel port dongles) have been around since at least the 80's. astonishing this has taken so long.
although i still have trouble understanding how to best protect myself against MYSELF. I'm just now getting my head around multiple yubikeys and subkeys in case i get locked out.
It would be great if everyone adopted TOTP, I'm up to a dozen sites in Authy and it's fantastic. Still waiting for my actual banks to support it though.
They've now moved on to certificates on your phone.
You go to the bank, prove your identity, they sms you a certificate. When you choose electronic authentication on the website you get a popup on your phone to accept. You put in a password and it validates the cert on your phone and sends the response to the website.
All without having to install anything.
For instance I perfectly agree to have an extra, branded, physical token, to log in to my bank, I totally refuse to use a mobile app on my phone to do the same.
My phone is a connected device, monitoring me constantly outside my control, controlled by the most powerful data mining companies in the planet. I simply can't trust my phone. I can trust enough my physical offline devices and if it will be cracked sometime I'm completely not responsible for it, my bank is. While with my phone it's really easy to say "it's because of this or that, not our faults" where this or that can be anything from unupdated fw (by the vendor, of course), unsafe apps installed, ...
In the Netherlands the ING bank was testing the waters this year by holding back on announcing a non-smartphone alternative to their ageing authentication methods (either SMS or a list of pre-generated codes received by mail). All of their communication was bent on nudging customers to use their banking smartphone app, and only at the end of this year did they announce a separate hardware solution for customers who don't want to, or cannot, use a smartphone for their banking.
Every other bank in the Netherlands already had such hardware devices (TOTP usually, although newer generations use more complex methods) for a decade.
U2F and its successors are the way forward if we want to maintain some semblance of digital freedom, not tying your whole identity to a smartphone.
while i agree with you, i seem to lack the imagination to come up with realistic examples that i can present as arguments.
i am afraid anything i think of would get a response like "yeah, sure, but noone uses their phone like that" or they'll simply accuse me of being paranoid.
Forcing me to use a smartphone app means I can't use a normal desktop or laptop computer, or even a non-Android, non-IOS smartphone. It means that institutions that provide a semi-public utility (e.g., banks) force people to support and agree with the terms of use supplied by a (foreign) megacorporation to function as a citizen in the digital realm. That is inherently undemocratic and a threat to our freedoms.
Expecting the vast majority of citizens to have access to a computing device with a modern web browser is somewhat reasonable (as long as those who can't are supported by other means). You can at least choose what software you run, and there are free software options available. With smartphone apps (well-built web applications excluded) that freedom does not exist.
For instance I hate in the same way countries that ask users to install proprietary crappy software's to pay taxes instead simple pdfs/standard WebUI.
We can't trust smartphones/connected devices in general, that's why IMO is better, for safe auth only, use offline stuff.
Can you point to any instances where that's actually happened? Yes, sure, it's theoretically possible for someone to break into my fully patched phone and steal my 2FA secrets. But it's also theoretically possible for a mobster to break into my house, hold a gun to my head, and force me to log in to all of my banks accounts so that he or she can drain the money from them.
There is no such thing as perfect security, and I would much rather have people using a 2FA app on their phone than just username/password. Is it perfect? No, of course not. But insisting that the existence of phone vulnerabilities makes 2FA apps on phone unacceptable, and that the only form of acceptable security is for people to juggle dozens of authenticator tokens is making the perfect the enemy of the good. It's because of "advice" like this that people ignore armchair security experts.
A dangerous thing remain dangerous even before accidents happen.
that may be fine for some things, but surely not my bank account
I use NixOS so my OS will replicate autonomously, I have dotfiles managed via org-mode+stow (and trying homeManager), rsync and unison at hand. I'm pretty confident that I can survive many kind of crush quickly with enough safety.
My phone however is an entirely different story: I can't backup it properly, I have to relay to obscure, proprietary and totally unreliable mechanism that prove to being able to restore only parts of my phone "operating environment" and in an unpredictable manner.
What you can do with all your soft-token if your phone suddenly die?
Another example in the past banks have had bankbook on paper, essentially ledgers that banks and their consumers have in hand, so both parties can prove a transaction. Now it's all on bank's servers, I can prove nothing as a consumers, I can only hope my bank do it's job well. Same if you buy shares, in the past you obtain a paper document that prove the transaction, now it's all on someone else server. You can take screenshots, perhaps have some sort of pdf receipts but they have essentially no legal value, anyone can forge them. Credit card are the same, internally they operate like paper bankbook, recording a certain number of transactions, however you have no control on that.
That's the BIG point: it doesn't matter how skilled and provident you are, the systems it more and more designed in a way that you are TOTALLY powerless, no matter how many things you know and how attentive you are.
the phone i carry always around. the risk if loss or theft is always lingering.
my wife just dropped her phone. it crashed. took 5 minutes to boot, i guess a filesystem check after the crash. it could have died completely too. my previous phone stopped working because of a botched update. we had a phone stolen...
there are just to many uncertainties to trust a single portable device.
In 2018 I'm using an app to take screenshots of QR codes to generate one time codes. It's a sad state of the art, we need to do better.
A different question, though, is whether a password keeper web service could leak passwords like any other service.
2FA is meant to protect primarily against phishing. It happens to protect against some other attacks as well, but phishing is the primary motivation.
That's why physical U2F devices are considered the gold standard of authentication today - it's possible to phish a TOTP code, but it's very difficult to phish a U2F signature, and impossible to do so through a scalable, automated attack.
If your master password is someone exposed, then nothing really protects you.
If they could do one, they can do the other. Just a matter of efforts I guess
Vanguard recently required that all accounts be "secured" via SMS, and I was dismayed to learn that Nest (of all companies) didn't even support Google Authenticator -- the only option with Nest was to use SMS as well.
It just seems like a losing battle at this point.
The hidden assumption is that the use is able to distinguish the fake from the correct site.
For any authentication system to work in the face of adversaries trying to confuse a user, the system needs to be robust against that.
https://eccentric-authentication.nl/blog/2014/11/30/spot-the...
https://eccentric-authentication.nl/blog/2016/11/18/on-the-i...
I have my primary phone with Authy and all the accounts.
I also have a secondary (old) phone in my drawer, which also has Authy installed. Both of them automatically sync the 2FA accounts in my Authy account, which is linked to my email and phone number. In the event that my primary phone is not available, I can switch to my secondary phone quickly.
Is that a good practice? I also plan to get physical keys and do the same when they become more popular.
That said, linking SMS often allows for SMS to be used to reset passwords. As sim swapping and phone cloning become more common attacks, the level of protection you gain from having SMS available drops. These attacks essentially let someone else receive your texts or calls. I have at least one friend who has been attacked this way.
I'd argue that it's exporting the failures of human psychology, not software security.
Sure, there are some pretty egregiously bad technologies underlying a lot of industry standard encrypted-communication/authentication/identity-management systems (including HTTPS). No argument that the tools and practices on the technical side could be way better.
But even if technical security was executed 100% perfectly, if the inputs to those systems remain usernames and passwords, people will be incredibly vulnerable. It's just too easy to [re]use weak usernames/passwords, too easy to write them down, and too easy to forget them (requiring "forgot password" attack vectors).
I agree with you that MFA is much more inconvenient than traditional U/P authentication. But I don't think it's inconvenient because of a failure in software security; it's inconvenient because it's extra work, and it has to be extra work because, well, people suck at diligence and security.
All that's really needed is for browser vendors to improve their UI for generating certificate signing requests and importing certificates.
Some of those companies offer SMS or email based 2FA as an option.
In any case, every single one of those services allows me to connect using TLS where my browser verifies the server's identity via the CA bundle I have installed on my machine. I simply don't see why companies don't make the investment to support client-side TLS authentication or start supporting U2F.
> And there's no way to steal your key without physically getting the dongle.
I would contend that it's probably easier to steal the dongle as opposed to my machine at home.
I have only seen client-side certificates used twice. Once at now infamous StartSSL and second at a bank but for vendor access, not regular customers.
Its huge downside is that it's a second factor which doesn't protect against a compromised device.
That's true, but I think that if people used an encrypted private key (protected by a passphrase), then that would be less of an issue.
No matter, I’ll use the phone authenticator for day-to-day, and the HW key as a backup. Not optimal, but until they support U2F it’ll have to do. Nope, you get to pick one key. So the HW key goes in the safe, and I use SMS for day-to-day. Or IOW, might as well have saved the plastic and postage for that HW key.
EDIT: someone else suggested directing email codes to an account that is protected by a HW key. Firing up GMail on my phone I less convenient than reading the SMS code off my watch, but I’ll probably do that.
Interesting write up here: https://wunderwuzzi23.github.io/blog/passthecookie.html
I have seen this being used by red teams, not sure about real malware.
How to fix it? Create two accounts -_-.
LastPass and bitcoin.de also don't support multiple devices.
We can handle good passwords. But our customers deserve for our database, admin tools, etc to require the more comprehensive authentication.
I'm not going to make our customers use 2FA, but we do require it internally now. We can handle it.
The "I know what I'm doing" doesn't hold up very well, statistically.
while you can protect yourself against fishing, and there 2FA is indeed less useful, you can't control how diligent the bank is in verifying your identity.
You do you; but personally, I would rather memorize timeless things like facts and theorems - or at least ephemeral-yet-important things like deadlines, decisions, names+faces, etc. - than memorize a ton of meaningless blobs of entropy.