Protectimus TOTP tokens with time synchronization are going on sale tomorrow
releasewire.com
releasewire.com
> But users often don't have access to the authentication server, so Protectimus figured out a way of correcting the token's clock instead. The time will be resynchronized when a secret key is flashed to the to the token.
Not sure I follow... the sync happens because when the user sends an attempted TOTP code to the server, the server calculates a few codes just before/after the current time, and if they match, the server updates its cache of the token's clock drift. Nothing is stored on the client. Why would this not be an option? (It requires the same access as required to send it a code in the first place, no more.)
It seems like a serious negative to have a hardware token with significant complexity on board; at that point you're better off using a smartphone which gets software updates, because you have a platform that's rich enough to have vulnerabilities and an attack surface. (And you can do things like put a password on the smartphone.) Hardware tokens with no inputs, like RSA keyfobs, make more sense.
"The server" here is owned by the site where you're logging into, not by Protectimus, so you can't make it do those things. They found a way to fix the clock issue from the end they can affect.
Plus you need some input anyway, since the TOTP protocol requires a shared secret, and for some reason it became a standard that the server is the one providing it on setup.
TOTP is still vulnerable to phishing attacks and MitM, while U2F machine-verifies the application ID, thus making phishing impossible (unless the phishing site tricks the user into using a non-U2F backup method for 2FA.) The downside is limited adoption, such as no support from Safari, and no support on most websites today. But I expect U2F to have a bright future ahead.
You can test it right now with any recent Android smartphone with TPM chip:
Apple will eventually join the club too once they stop dragging their feet.
Of course with the TPM you effectively have a hardware token permantently physically linked to your smartphone, so it changes the security analysis a bit.
For users this means that WebAuthn for accessing websites on a TPM-capable smartphone is really just a matter of unlocking the device when prompted. Quite user friendly.
Edit: looks like solo has a USB-C + NFC option that seems to be missing from Yubikey's selection.
Edit 2: Same with Feitian which also only has USB-A for the NFC product...
Apple's business tools still only support SMS authentication.
Try: https://en.wikipedia.org/wiki/Time-based_One-time_Password_a...