Software U2F Authenticator for macOS
github.com
github.com
In a similar vein, here's a TOTP client (unfortunately no U2F/WebAuthn) that can bind the secrets to the hardware (on TouchID Macs): https://github.com/sqreen/twofa (disclaimer: I'm the author)
OTOH, the anti-phishing/shoulder surfing benefits of U2F are substantial and eliminate the ability to perform very common attacks. This is a great piece of software.
It seems like a hardware key helps when using a machine temporarily, and it gets compromised after you use it.
Hacker will just wait until after auth and steal your cookies.
https://github.com/github/SoftU2F/pull/29
Not sure why they don’t explain that in their readme.
https://blog.mozilla.org/security/2019/03/19/passwordless-we...
I prefer to do the device trusting with Firefox's login manager, and then the second factor is a hardware PGP key where supported, or TOTP on another device if not. Whereas with this the device is trusted with the 'second', so you probably want to store the 'first factor' passwords separately (i.e. have to enter them) for anything important.
Services such as websites assume and grant trust levels based on if you have 2FA enabled (such as requiring 2FA for certain operations). Instead, if you don't use hardware 2FA, they shouldn't grant the same level of trust as when you do.
The example of malware is mentioned in the README. The secondary reason I use 2FA is stolen device. I keep my hardware token separate from my device when I don't use my device.
Also, the README does not mention FIDO2 at all. IIRC that had further protections against malware, but I'm not sure. The README is out of date regardless.
https://github.com/github/SoftU2F/pull/29
I would prefer a fingerprints change equates to loss of hardware key. I quit sessions, and would like the stronger mitigation of various password bypasses and priv escalations.
> Some people may decide the attack scenario above is worth the usability tradeoff of hardware key storage. But, for many, the security of software-based U2F is sufficient and helps to mitigate against many common attacks such as password dumps, brute force attacks, and phishing related exploits.
Inexpensive ways to do it will help adoption and people who care more will stick with hardware keys.
But instead of "faking" U2F keys just go with something like authy or phone verification. I still believe it defeats the hardware purpose of u2f given that it's software (even if it's a backup)
Any backup for a u2f that isn't another physical u2f is compromising in some way, it's just a matter of which way.
In reality though I agree with you and use one time code backup for u2f, and just trust that I will be careful if I ever need to use them. (But maybe I'll be panicking already and get phished? Who knows...)
It works in mobile Chrome just fine with built in NFC, but it doesn't work in Windows and Linux last I tried, because there's no support for U2F NFC in desktop browsers yet.
Surely there's a way to meet in the middle somewhere, so instead of doing it in software it would use a smart card via card reader.
Though it suffers from the caveat that secrets are just stored as a file in $HOME. I'd love to support more secure methods but haven't seen enough interest in the project to justify the dev time that would be required.
I'm just emulating a USB device and using OpenSSL to do the signing, is there a better approach I should be looking at? (perhaps PKCS #11)
$ gpg -d encrypted-secret.txt | goathgen
https://github.com/w8rbt/goathgenThe keys come from a dedicated password manager that only stores TOTP secrets and the password manager wipes the clipboard.
All this happens on a physically separate machine.
> We take the security of this project seriously. Report any security vulnerabilities to the GitHub Bug Bounty Program.
I'm guessing that means it's actively maintained.
I'm guessing it isn't.
> Soft U2F is a software U2F authenticator for OS X. It emulates a hardware U2F HID device and performs cryptographic operations using the OS X Keychain. This tool works with Google Chrome and Opera's built-in U2F implementations as well as with the U2F extensions for OS X Safari and Firefox.
That U2F extension link for Firefox is dead because Firefox has it native for a few versions now. about:config -> u2f shows it (I'm on Nightly so not sure its same in current stable).
The bot makes trivial changes to your git repo every two weeks so that web people will feel at home.