Turn on MFA Before Crooks Do It for You
krebsonsecurity.com
krebsonsecurity.com
I've been in tech for 25+ years. I'm very familiar with security, and I have the internal endurance to sit patiently and work through IT-related issues.
However, at this point, there are just too many broken ways and I'm at the point of giving up. I use LastPass and if that somehow gets hacked or phished, I lose absolutely everything. I'm waiting for the next virus or phishing attempt to steal my LastPass password.
I use multi-factor authentication on some accounts, but if they use SMS like many sites do, I can get my phone number stolen from me and then I lose access.
I use Gmail and Google Authenticator, but if I somehow do something to piss off Google, I can lose my gmail account and access to Google Authenticator and then I'm really fucked. I've lost some gmail accounts because they will ask me for security questions when I log in with the correct password, and I don't remember them so my account gets locked, so they're gone forever.
What we need is a single way to do login, MFA and security across every single site. We can't have every company incorporating their own methods. We need standardized customer support, where Tier 1 customer support can't give you access to things like credit card numbers, last 4 digits of SSN, or change passwords. Changing passwords needs to be a higher level, better trained customer support.
There needs to be an ISO standard that is well thought out and implemented by all the vendors, or at least all the big vendors. If there's a standard way of doing security but also a standard way of doing customer support and what data is exposed to various levels of customer support, then social hackers can't take partial info from sites A and B, and use that to social engineer site C.
This has to be simplified because it's absolutely unwieldy even for a veteran like me. There are too many ways I can get hacked and we are all just sitting ducks. The only thing protecting us is that we aren't high-value targets.
What happened to me is that I went to reset my password one day, and they required I confirm my backup email which I no longer had access to.
Even though I had access to read messages sent to the gmail account itself, and I had access to the phone number connected to my gmail account, without my backup email as well, I could not get anywhere. The recovery procedure that asks you questions didn't get me anywhere either, because I couldn't possibly answer things like exactly when I started using gmail due to using it for too long. And I even had an archive of a few years of my email, that ought to have enabled me to answer the other questions, but it didn't work and there is no feedback nor escalation procedure.
I may well still be logged in due to a certain buggy/obsolete device I have; I think it's probably been five years, but I don't believe I will ever be able to log in or reset my password again.
It didn't have a great deal of impact on my life in the sense that I was able to simply switch to a new email account, but I feel a certain sense of loss at not being able to use the one and only address that was my full name. More significantly, it indelibly engraved in my mind, the kafkaesque, diabolical nature of Google, the ingrained lack of customer service, the way in which, while they may mostly be geniuses, when they screw up, they won't admit it and there's no appeal.
The thing that I object to on an emotional and logical level, is that adding a backup authentication method removed the ability to use the primary authentication methods. If I just never added the backup email I'd be fine! I can't accept that makes sense, that it adds security. Something the user does to make them safer should not make them less safe.
Around the same time my old phone broke and i had to change the password.
I must have mistyped the password while changing it in both fields and since then have never managed to re-access the account. I have old passwords, backup email, previous contacts, phone, ... But i cant restore the password because i hadnt yet set up authenticator on my new phone.
My fault? Probably. But that there's no way out, no option beyond the horrible restore wizard - that's Google's irresponsibility. How many millions must have lost access to their gmail accounts by now?
If someone hacks your phone they have access to all your email, whether you have 2fa set up or not. If someone hacks your computer in this case then they also get access to all your email.
The thing that 2fa is good at is preventing hackers from logging in if they guess or find out your password. If your device is compromised then everything you do on it is vulnerable, no matter how many factors you have.
It prevents from someone, somewhere, having your password but not your 2nd factor.
It's incorrect to take these measures as giving perfect security. They're efforts to greatly increase the cost for attackers. It's a pretty good improvement to increase effort from "having a password" to "having remote access to your computer."
AndOTP has some support for SteamGuard (though not everything), which I can't use since I refuse any proprietary app on my phone.
I wish websites supported PAKE, Fido U2F, Webauthn, TOTP and Client certs across the board, but that's probably a pipe dream :)
Maybe try again. :)
One thing to note is that I was unable to access an old account for so long that it no longer has any old email in it.
I don't think my earliest emails are available at all, I may well have deleted them, but even if they were, the device that remained logged in is over a decade old, uses POP or IMAP or something and barely functions. Not the gmail web interface, that's out of reach.
I wonder if signing up for Google One, which apparently comes with support, would possibly get access to a real person who could resolve the issue?
Also, anyone who still can should print out Google backup codes and store them somewhere safe. Google Authenticator is not enough, because phones break eventually. A Yubikey is not enough, because they can break too.
The 2fa set up process for many websites (and iirc Google too) do not make this a priority. They should clearly emphasize the importance of saving the backup codes, and make you check a box that says you printed them. The 2fa should not be enabled until that is done.
- The inconsistent, chaotic patchwork of ID systems is more resilient than a monoculture, and definitely more resilient than a centralized solution.
- The gaps provide necessary cover for people who need to hide.
- Doubt usually plays in the little guy's favor. The bank eats the loss when it can't prove the debt is yours. Copyright lawsuit fails when it could have been anyone at that IP address.
- The difficulty of strong ID verification is what keeps it from being used gratuitously. A PKI or SSO provider that's too good will soon be required for every little thing.
- Customer identity is something a business should own, not rent.
This can be done in a decentralized manner where people host their identity. For example, for email you can buy a domain name and set the DNS MX record to point to whichever email server you want to receive email at. For identity you could have a DNS record with a public key, and then use your private key to generate random signed identities for every website. Obviously that's a bit out of reach of normal people, but it can be implimented without too much complexity. And inevitably it'll get pretty centralized for 90% of people, just like 90% of people use a @gmail.com email address, but the option will still be there for those who need it.
- SSN is great and works well for everything.
It turns out that you can completely centralize ID and authentication, provided you have a government which is mercilessly willing to violate your privacy...
It's a very US-Centric view of the world.
otpauth://totp/Domain%3Ayour%40email.com?secret=HXDMVJECJJWSRB3H&issuer=Domain
That "secret" field is the only thing that TOTP actually cares about, and any app that supports TOTP will happily ingest the secret and provide 2FA codes.
I grab all my QR codes or secrets, but I store them in 1Password so they're strongly encrypted in my backups.
(Just so I'm not misunderstanding something.)
Qubes OS maybe a good idea here -- isolated VMs. (One VM for the pwd manager)
Additionally it has support for Steam and Blizzard TOTP secrets. Though they aren't straightforward to use, its nice having them on one app.
This also helps if you want to use YubiKey TOTP support. Grab the keys, and then set them up on multiple sticks. If you lose a stick, you need to rotate, but if you say accidently snap one in half (yes, I've don't this).
Fido2 is better, but for sites that don't support it, I use this to make TOTP sites almost as secure.
How do you download and decode?
Any Linux software tips?
And how do you verify and double check you did it right? (Saved the exact correct code)
Verifying that I did it right: I manually enter the secret into a tool that can produce TOTP codes and verify that Google Authenticator and my backup are producing the same one-time passwords.
Agreed. The worst part, in my opinion, is the penchant of sites/providers to demand a phone number any phone number as an identity mechanism.
Which is to say, there is no way to tie this number I have just entered to my personal identity in any way, or to verify that it has any relationship with me ... but as long as I successfully enter any mobile number I pass with flying colors.
In the beginning it was just a password. Then it was a username + password. Then an email address was tacked on to support "forgot my password". Then phone number was added to support SMS-based 2FA (or, hopefully, out of band contact).
The problem is that only government IDs have a high enough assurance to reduce fraud, and our {companies, employees, consumers} seem to avoid wanting the government to be involved in internet-based identity/authentication. Having a chip used to sign encrypted messages in our government ID cards would both assure authentication and reduce all of the frictions added after the fact.
The sad part is that USA government institutions are woefully underprepared to support internet scale of adoption and the legacy services (like DMV and county/state government offices) aren't exactly known for their swift customer service (which would be required if you lose access to your government ID).
That type of "assurance" is really quite irrelevant to most authentication. Google doesn't need to know the name on your driver's license or your street address, only that you're the owner of this gmail account.
> Having a chip used to sign encrypted messages in our government ID cards would both assure authentication and reduce all of the frictions added after the fact.
Or you could have the same chip in a YubiKey and get the same result without the centralization or the privacy violation of having everything tied to the same identity without your consent.
> The sad part is that USA government institutions are woefully underprepared to support internet scale of adoption and the legacy services (like DMV and county/state government offices) aren't exactly known for their swift customer service (which would be required if you lose access to your government ID).
This is just more reason why it makes no sense to have the government involved.
It's not actually that hard to get a state-issued ID in someone else's name, especially for criminals who are willing to do things like pay off government employees, but even just for someone willing to forge documents.
The government can't use good cryptographic solutions to authenticate you in order to give you the card with the good cryptographic solutions because it's chicken and egg. But without that the security will always be weak.
Starting with a card which isn't associated with any "identity" to begin with and making the service you're using it to authenticate against your "identity" doesn't have that problem, because it isn't necessary to prove "identity" when you're opening the account to begin with (the account is then empty and contains nothing to compromise) and thereafter you can use the authentication method(s) configured when you opened your account.
But then the government wouldn't be doing anything but selling blank cards you could use to create identities with various services, and any private business could do that as well.
To hijack accounts at bulk, you also need to procure phone numbers in similar quantities. The cost of a phone number is low, but so is the value of the average hijacked account.
If you go post something on craigslist and show your phone number as a contact method, I guarantee you that you will soon get spammed by google 2FA notifications. Around me they seem to be primarily set to a Vietnamese language.
I live in the same city as the AT&T headquarters.
AT&T and Google could also have systems to help prevent these scams, for instance I could specify the languages I speak and if SMS messages arrive in a different language, they could allow me an SMS command to flag a sender as the trigger-er of the phishing attempt.
However, AT&T could also make a phone app for billing that loads menus in less than 30 seconds to a minute, and considering they've done neither I suppose I'll take the billing app first since it gets more use than craigslist does. After all, we only pay them 60 dollars a month for a phone and another 60-100 dollars a month for DSL for quite literally decades, so I wouldn't want to strain them by requesting too much in the way of a basic level of service.
It’s just not well-known enough on enough sites and services yet, but it exists and WebAuthN makes it easy.
Outside of the browser, it has OpenSSH support but not git or pgp/gpg support. GPG (and by extension git) don’t support very many security technologies... Windows Hello and CryptoKit are solutions but rarely implemented yet. Perhaps this will change over the next decade as hardware-based security authentication supplements or replaces soft- or password-based authentication....
Touch ID on phone apps can show how it’s done...
The best article I’ve found to explain USB security keys has so far been https://paulstamatiou.com/getting-started-with-security-keys... but it’s ... very long.
Just to point out how a billion dollar company also has issues here.
The whole API design incorporates this thinking. The API call to tell a browser "Hey I want to enrol a Security Key" navigator.credentials.create() takes an array as a parameter with IDs for keys you don't want to enrol because they enrolled already.
The call for "Hey, prove you still have that second factor" navigator.credentials.get() needs among many things an array again, this time for IDs for keys that you'd accept, and one reason that's needed is that other keys needn't bother doing anything as they can't help.
That probably came across like speculation based on AWS's reputation, but it's also my actual experience after going on a U2F spree. Out of maybe 7 or 8 accounts, AWS was the only one that didn't support a backup key. Point is: I don't think it spells doom for U2F. Wasn't it just a few days ago that AWS was allowing password resets that couldn't be used for login because of validation? I don't remember the service, just that I saw it on HN.
It hit a huge maturity milestone last year when the last major browser/OS combination got support for USB keys by default. Now the user story is "insert key, boop button." It's intuitive enough for my parents to understand, it's easy enough to habitually use, and the security is a big step up.
It's worse than you're even alluding to. I recently purchased a Yubikey with the intention of securing as many accounts as I could with FIDO2 and U2F. Literally the only service I could secure fully with the key was Google.
Google was the ONLY service that supports FIDO2 on both the desktop and mobile (using the Yubikey 5Ci with the lightning connector). Everything else was a hodgepodge mess of two factor options:
Twitter: FIDO2 on desktop only, needs TOTP fallback for mobile. Recovery keys for backup. Facebook: FIDO2 on desktop only, need TOTP fallback for mobile. Recovery keys for backup. LastPass: TOTP or YubiOTP only, email to recover. ProtonMail: TOTP only, recovery keys as backup. US Bank 1: TOTP via their app only, email and SMS as backup. Recovery by customer service US Bank 2: Email only, recovery by customer service. DE Bank: PhotoTAN only, recovery by customer service & postal mail. US Investment Firm 1: Symantec VIP only, email as backup US Investment Firm 2: Email only Reddit: TOTP only, recovery codes as backup. Amazon: TOTP only, SMS as backup Duo: FIDO2 on desktop and mobile, but lack of support for embedded browsers means I need to have HTOP or push as a fallback for some applications on both platforms.
For the services that have recovery keys, I have them in an envelope I keep in my gun safe as well as a PGP-encrypted text file on my computer. I didn't store the TOTP secrets separately, although I probably will next time I re-enroll everything because my Yubikey physically fell apart a month after using it (a common thing with the first batch of 5Cis from what I gather) and I had to move everything back over to TOTP codes.
It's not just the standard for 2FA, it's everything from the bottom up. The 2FA tool, how backups work, how recovery works. It's a complete hodge-podge mess and and, like you mentioned, if it's this big of a pain in the ass for an experienced tech guy, how am I supposed to, in good conscience, recommend this stuff to my non-techie friends?
You don't need the TOTP fallback for Facebook on mobile browser (though annoyingly they'll still always send you the code via SMS, if you haven't disabled). I suppose it's possible that their app has issues with FIDO2, and maybe that's why you had to fallback to TOTP.
But yeah, 4 services (including Google), out of all the ones that I use... The track record for supporting FIDO2 is underwhelming. It's especially annoying that you cannot set up backup FIDO2 keys in AWS, which means that I won't rely on it.
Unless it was changed, GA is one of the few apps that doesn't sync with Google nor require a Google account to use.
I'm much happier doing this than risking having a phone number hijack due to a $cellCarrier employee maliciously or negligently transferring my phone number to a malicious user, but it's not easy for me to remember to do all of these security steps, let alone someone who doesn't work in the cybersecurity industry. There's no way in hell my parents could do this.
The previous answer made me think a bit more seriously about those reset codes that are lying around (maybe?) my computer.
I’m a digital native and digital lives are still so hard even for me; no wonder regular people just nope out of it.
And with regards to your fear from Google: Short from full-on identify theft I have a controversial solution: E-Mail is something one should pay for.
E-Mail is essential ; the one thing you can use to pretty much sign up for everything, the one thing to use to reset passwords ; the one form of communication which is open, readily accessible to almost everyone, crosses borders, doesn't ask for fees, doesn't need a specific app, et cetera
I once lost my complete password database (if you sense irony here, it was a long time ago, and I was being stupid), including my E-Mail password, no 2FA set up, nothing. I was completely locked out, but: since I paid for the service: I could open a ticket, I could get a human(!) within a short time frame who actively assisted and I could proof my identify via easy means.
I was greeted with empathy, we could work with whatever I knew about the account and related information. There was no ridiculous meaningless questionnaire, no support ticket answered by some volunteer moderators. I was dealing with someone from staff who knew what they were doing, and we worked it out quickly.
Not saying it would have been impossible to restore access to a Gmail Account, but at the very least it would have been incredibly more painful, I am sure of that much.
Google Authenticator is not tied to your account. Unless you lose your phone at the same time (or have remote wipe enabled and someone who gets your Google account wipes it), your Gmail account is not tied to access to Authenticator.
You should also backup authenticator codes on paper in a safe place.
> What we need is a single way to do login, MFA and security across every single site.
This. U2F could be it, but even the vendors that implement it often implement it poorly (e.g. not allowing multiple tokens).
The way to do that is to use a client-side certificate in combination with a username/password for authentication.
When I create an account on a website, these are the steps I should have to follow:
1. Choose a username and password
2. Upload a CSR
3. Get the client-side certificate
4. Add it to my local certificate store
When I log in, I should have to follow these steps
1. My client automatically chooses the correct client certificate to send based on the server certificate
2. If I need a passphrase to decrypt my private key, I enter it at a prompt
3. The server verifies the certificate the client sent against whatever CA they use
4. I enter my username/password
5. My credentials are verified and I'm logged in.
I shouldn't have to provide my phone number or email address as a second factor because those factors aren't under my control. The private key associated with the client certificate is under my control.
This is the main problem any such solution has to solve (IMO) to be better than the hodgepodge of 2FA methods that we currently have. Humans are fallible and will likely not maintain proper backups and such.
If you don't do that and lose the certificate and private key, then you lose access to the account. You should not be able to log into the account without both the client certificate and the username/password.
The procedure I described earlier would be for accounts like HN or reddit. If this was an account with a government agency, bank, or credit card company, then the part where you generate a CSR and get a certificate would be done at an office where they verify your identity (drivers license, passport, etc). In the latter case, if you lose your certificate, then you need to go back and repeat the procedure to get a new one.
> Humans are fallible and will likely not maintain proper backups and such.
While that's true, we really ought to sacrifice some convenience for better security. If a user fails to maintain proper backups or register multiple devices for an account, then the inconvenience of losing their account and going to the arduous process of creating a new one is on them. They shouldn't put the lack of security burden on us by having companies engage in security theater like MFA (i.e., SMS or email based second factor) because they want convenience over actual security.
That said, those users could opt out of MFA and just rely on their username/password for authentication. Those of us who want MFA could use the client-side TLS certificate in combination with the username/password and keep our account secure.
The biggest barrier to 2fa is the fear of loss of a factor.
I can reset a password with an email account, i can't reset a 2fa with an email account. As long as that will be the case adoption can not go forward.
I would rather have the ability to use real security with the MFA scheme I described above (and in my other post [1]) rather than the security theater we have with email/SMS MFA. If some people aren't able to deal with that and lose access to their account, then the burden is on them. On the other hand, by using email/SMS based MFA and account recovery, the burden is on all of us for the lack of security for everyone. If someone wanted to get into the important accounts, they don't necessarily need to target the user's bank. They could target their cell phone provider or email provider and get access not only to their bank account, but any account using those as factors for authentication.
With a client side TLS certificate, they would actually have to get physical access to the device and brute-force the private key passphrase in addition to the username and password for the account.
You + firefox remembered passwords = more secure then a user on 2fa.
This aint about you bud.
On the contrary, people like me do need it. The status-quo right now is that companies are forcing us to use security theater measures to further secure our accounts. But since those measures are actually weaker than the original password, it actually reduces the actual security around our accounts.
And I never use the remember password feature in my browser because I don't want to inadvertently give someone access to my account if they manage to access my machine.
Of course that would eliminate anonymity, which would be horrible, but maybe ok for Gmail where people use their real names anyway.
But in the event of loss of ID card or identity theft, there is a trusted instance (the government) that can block old ones and issue new ones. This could be used as a reliable way to rotate a 2FA key, because some unique number attached to a citizen won’t change.
I mean how many times have you been left alone in a doctors office with a computer just sitting there with connections/inputs exposed. I am 0% shocked at the large scale retail data theft that gained steam a few years ago.
Oddly for me it seemed like as time went by I had a better chance of recovering old gmail accounts with spurious remembered information, like the algorithm thinks the longer nobody's in it the more likely you're the owner trying to get in. This was ~10 years ago though.
Microsoft is starting to push passwordless features for Windows and online accounts.
YubiKeys and OTP apps are pretty common (hopefully there will be more standardization and less fracturing of those features).
OAUTH2 is mature and Google/Facebook/GitHub/etc all work decently as providers.
Although I wish a single government entity would replace those OAUTH providers. I can't get banned by my state like I can get banned by Google for ToS violations, so I'm wary of creating a federated auth account unless I'm certain I can't lose access to the root account without necessarily losing access to the subservient accounts. The obvious downside is that dissidents and criminals are easily identified, but that's an offline problem as well as an online.
Clonable, backupable, encrypted on disk and in cloud sync.
I have it on my phone, laptop, and desktop.
You should never trust any of these companies with your actual bank account. All of them have garbage customer service with hoops upon hoops to get real help if your account is somehow compromised.
Use a credit card, prepaid card (in the US Amex gift cards you get at grocery stores will work just fine) or buy codes from Amazon and redeem them.
Personally, the only companies that have direct access to my bank account are those that either won't accept credit cards, or make it excessively difficult to do so. Chief among them would be the service that processes my rent payments, and PG&E.
Even with that, I'd still prefer a credit card. If there's fraud on my CC, I haven't lost anything. If there's fraud on my debit card, there will be a period of time where that money will be gone before the bank investigates and decides to give it back to me. Even if they are 100% reliable at giving it back to me, the money is still inaccessible for some non-zero period of time.
At banks that make it easy to have multiple checking accounts tied to one online account, create accounts just for these debits. Don't keep funds in them until close to the transfer date. "The Paypal Maneuver".
Every other bill gets paid by credit card or gets pushed to the biller through online banking that I approve. No one gets to pull money from my primary bank account.
If someone attempts to max the card out it won't directly affect your bank account balance (which you may need access to in the meantime) immediately.
That's why Don Knuth stopped sending checks.
Someone made a fraudulent charge with it (probably the visa side unless my pin was compromised).
My bank refused to refund the money unless I could prove the thief used the visa network to make the charge.
Of course, that information was in their records, which they refused to share with me.
The same bank frequently froze the card for “fraudulent” charges that I made. Eventually, I closed the account.
It works on Google Cloud Compute I used it last year. Then there is an option to completely block any transaction of my actual card for any online purchases. When I go on a trip I generate a few virtual numbers and write them down in case I need to make an online purchase from abroad.
I have 2FA turned on for Github. Since they refuse to recover accounts that have 2FA enabled if you lose your second factor, I have many alternative ways configured: TOTP, U2F, recovery codes, recovery phone number.
I have the recovery codes stored in a secure location, and several U2F tokens enrolled (one of them is also off-site at a different location).
But I didn't back up my TOTP seed. I still have the old phone with Google Authenticator, but it's too old to accept the version that lets me export my keys.
Getting a new TOTP seed requires me to re-setup 2FA, which will invalidate the recovery codes and possibly unenroll my security keys (it says "This will invalidate your current two-factor devices and recovery codes.")
It's also apparently impossible to set up Github 2FA with "only" a set of security keys + recovery methods - you have to first set up an authenticator app or SMS 2FA as a primary method.
So now my options are:
- Leave the dead TOTP on the account, and don't have a working TOTP setup
- Re-setup from scratch, invalidating the recovery codes and possibly U2F tokens, requiring me to visit two distinct off-site locations to re-setup everything, one of which is currently locked down and inaccessible due to Coronavirus.
And Github is one of the better sites when it comes to 2FA!
A potential alternative could be finding an ancient APK that didn't have the 'prevent backup' bit set, downgrading via adb install, and pulling an adb backup. Still, massive PITA.
adb root && adb pull /data/data/com.google.android.apps.authenticator2/databases/databasesI have none of these problems with local important services because I can use my goverment-issued ID for those things.
Two-factor authentication is largely an annoying band-aid over an easily-solvable problem. It either relies on devices and protocols like smartphones and SMS (which are fundamentally insecure to begin with) or requires expensive proprietary solutions like Duo.
I do like hardware (U2F) keys a lot though.
It's like an anti-password manager. Doesn't depend on any specific device.
Essentially it's a sane implementation of what others have already discussed below, in the other child comments -- using the name of the site to derive a secure, non-reusable password.
- Sites that have different password requirements (some require special characters, some don't allow them, for example). - Changing my password on a site.
I took a peek at masterpassword.app, but couldn't see that it solved these. Does it?
- A choice between a few different password types (numerical, short, long, complex, phrase) for picky sites. It relies on you to remember which password type you used for which site.
- A counter you can increment arbitrarily to generate new passwords for a given site. Again, relies on you to remember that you're on password #3 for site X, password #5 for site Y, ...
I haven't reached a point where I've had to make heavy use of these features (yet) but if you use lots of picky sites, or change passwords very often, certain limitations will become apparent.
If it's any consolation, passwords generated by Master Password tend to have a unique phonetic cadence -- that is to say, once you're familiar with the first or second syllable of your password for a given site, you'll know pretty much instantly if you're looking at the right one, despite not being able to reproduce the entire string from memory.
This might make it easier to increment the counter several times in quick succession while being able to conclusively discard passwords that don't "sound right".
YMMV of course. If this sounds like something you'd hate to do, Master Password may not be a viable solution.
The Java-based desktop app somewhat solves these issues by (optionally) caching encrypted data about your passwords (site names, password types, and counters) on disk. However this could possibly end up defeating the point of "doesn't rely on any specific device", if the user grows to become reliant on the cached data.
With that you never reuse passwords. Someone with other passwords of yours is likely just trying these automatically, people who would target you usually don't have your passwords from a breach elsewhere and can't figure out your password rule.
It is not easy though and I find myself having to reset my passwords occasionally...
I'm not sure what the point of this when there are password managers available. Sure, it prevents simple credential stuffing attacks, but you're still open to sophisticated attackers deducing your passwords based on a leak. For instance, if your bank password is "correct horse battery staple chase", an sophisticated attacker might try "correct horse battery staple paypal" for your paypal account. Attackers already bruteforce common variations of passwords (eg. password -> (Password, password1, etc.), so this isn't too far fetched. Password managers with randomly generated passwords have none of these issues, and you still only need to remember one password.
A password manager is probably very good, but it's a single point of failure and a huge target for the black hats; it's a program on a computer or on a smartphone that (potentially) sends data back and forth as it pleases.
So maybe the idea is to use a password manager for single-use entropy and then add some mnemonic manually before submitting the password. Then it's down to keyloggers and other sophisticated attack vectors?
Wouldn’t work for driveby hackers, but anyone specifically interested in targeting you could get a long way with this technique.
What's the threat model here? If it's downloading a malicious password manager, that can be mitigated by using an open source/audited one (eg. keepass or bitwarden). If it's your browser/computer being compromised, that really isn't fixed with manually entered passwords either. If there's malware on your machine, you can assume that all your keystrokes and form submissions are logged. The only advantage is that rather than getting all your passwords, the attacker only have whatever passwords you've entered prior to detection.
correct horse apple stable eat (c.h.a.s.e) is, I suspect, closer to the spirit of the original suggestion. Just tacking the name of the company onto the end instead of weaving it in is, as you say, pretty weak.
The nice thing about password breaches is that they're all from the same source, so you can come up with a few variations and they'll be valid for all the passwords in the breach.
The answer is that services like LastPass and OnePassword have recovery codes that you're supposed to download and save somewhere (possibly even on paper). These codes can get you into your account if you are somehow locked out of your account.
That said, 2nd factor that's not U2F are not worth it at this point with lots of issues, so indeed U2F is about the only no-compromise (security wise) 2nd factor. All other 2nd factor have serious security or availability downsides.
SIM-swap fraud is super common here, so turning on 2FA actually reduces the security of my account.
A soon to be released patch offers world of Warcraft players an in game upgrade (additional bag slots) for players with MFA setup. I would have thought this would be supported by a community.
Instead, the feedback I'm seeing everywhere us "it's just a scam to make you setup the authenticator, don't fall for it". I cannot fathom why people think this, when it's a free offering and protects you more than them.
It just shows how differing some community views are from the security community.
You can reset a lost password with an email and an automated process. You can not do this with 2fa on just about any 2fa enabled site I've seen.
2fa is a net gain in how likely you are to get locked out of your account, This is why nobody wants to use it.
Bag slots do seem like a more concrete reward for using authenticators.
I'm actually toying with what sort of trivial reward would be appropriate for using WebAuthn to sign into an archaic PHP-based web site we built last century, I wrote a PHP WebAuthn implementation for it and it'd be fun to give people some silly reward for turning it on.
Say I have MFA enabled to send me an SMS when I log into my email.
I am abroad, and my phone gets stolen. I need to log in to my email on some other device and re-access my boarding passes, maybe communicate about my upcoming radio silence. But I can't access my account without the code sent to my phone...
That's my worry with this thing.
I've also done it where I sent them a YubiKey with my secrets, then set it up so I can access a computer remotely (via ssh, rdp, etc...). I have to call them to insert the key into the machine, so if the machine gets compromised, there's not much risk, as it's only plugged in if I call them to do so (and tell them to unplug it X minutes later).
Of course, that requires maintenance and checks it would work in a real life situation, that network configurations haven't changed, the parents are present and compos mentis, etc.
Since access only requires 1) internet access, 2) a common, publicly-available decryption program, and 3) stuff in my brain, I can gain access to it under pretty much any situation where I'd need access to it.
A potential downside is that if I ever had to access and decrypt the file on hardware I don't trust, I'd have to revoke and re-issue all my backup codes, and come up with a new long passphrase to protect the new file, which is a huge pain to do.
This is of course not perfect security, but I think it's fine for my purposes and threat model.
This is obviously not perfect security for that reason and a few others, but it's good enough for me.
What's annoying is that a lot of these attempts would stop if spotify simple started forcing MFA. Even if through their mobile app.
1) To get free premium account
2) Same email/password re-used on other sites
NYT: Who’s Hacking Your Spotify?
https://www.nytimes.com/2019/12/05/style/spotify-hacked-what...
They were lined in front of tent and told to leave external layer of clothes and shoes in the tent. Otherwise it would be to easy to escape in the darkness. Walked down the slope, some resisting had been beaten (Kolmogorova, Slobodin) and under the tree some were undressed and tortured with fire (Krivonischenko).
This TV show is a mess of but there are some interesting witnesses who came forward.
https://youtu.be/uBzHvq3fWh8?t=1295
https://youtu.be/dN7LSVjpPGs?t=882
https://youtu.be/UM2csYGEU5k?t=2160
The most mysterious persona are Krivonischenko nad Zolotaryov .
Also on the subject of the rib fractures, they've been described as consistent with a bomb or car accident, a snow mobile like a B7 seems like a possibility. Maybe Krivonischenko was suspected of leaking information and Zolotaryov was there to keep an eye on him, and the rest got caught up in the mess. And when things got out of hand, Zolotaryov sided with the group.
Krivonischenko was no ordinary guy. His father was in rank General Major and in charge of constructing Soviet nuclear plants. Krivonischenko himself worked on liquidating Mayak (Kyshtym disaster - https://en.wikipedia.org/wiki/Kyshtym_disaster) then he suddenly quit his job and ignored letter denying him release. From what he saw at Mayak and from informal talks with his father he could have had troves of valuable information.
https://dyatlovpass.com/konstantin-krivonischenko?rbid=18461
Suprisingly there is another member of the group - Kolevatov - that from analysis of his biography looks like career officer involved with nuclear industry. At 19-year-old Kolevatov graduated from the Mining and Metallurgical College in Sverdlovsk and was sent to Moscow to work at 9th Directorate of the NKVD of the USSR laboratory "B", focused on creating protection against ionizing radiation. And then sent back to Sverdlovsk (which does not make sense as voluntary career move but makes sense as some sort of assignment).
https://dyatlovpass.com/rakitin-on-kolevatov
And Zolotaryov - there are witnesses of him beeing seen at different places at the same time. We know that he had zek brother (kept in Gulag for beeing traitor after WW2). He was leading tourist expeditions often close to the borders of USSR (in 1950s it was difficult to achive permits for such expeditions - there were people trying to escape and in some still active ant-Soviet partisans).
He claimed that after Dyatlov expedition he will achive fame. He was simple PE instructor but working in secret city.
On the TV show the daughter of Zolotaryov life partner and a person who have taken bath with him on previous expedtion does not remember Zolotaryov tattoos. No one else does and Zolotaryov was handsome man and well remembered. It was also at times hard to imagine for a normal member of Soviet society to have tattoos. Especially for PE instructor who has been leading PE classes with students in short sleeve shirt.
https://dyatlovpass.com/resources/340/gallery/Semyon-Zolotar...
Zolotaryov young son disappeared without a trace. He was apparently given into foster care but boy's mother (Zolotaryov's life partner) had been actively looking for him for long years in vain. So it looks like the paper trail of the boy vanished or have been erased.
https://dyatlovpass.com/semyon-zolotaryov?lid=1&flp=1#sasha
So we might assume that Zolotaryov had been given new life, taking boy with him and the body found have been his brother's.
https://dyatlovpass.com/zolotaryov-exhumation-3?rbid=18461
Tumanov - pathologist on the TV show - claims that Krivonischenko's burns are a sign of prolonged exposure to fire - not an accident casue even semi-conscious person will react to contact with fire. So either Krivonischenko climbed the tree and fire was used to force him to get down or it was plain torture to extract some information.
Slobodin (amateur boxer), Kolmogorova and Dyatlov all had died of hypothermia but also all have signs of blunt force trauma. So hypothermia might have been result of being left unconscious in the cold after receiving serious blows (back of skull for Slobodin, batton on a hip and bleeding nose of for Kolmogorova and Dyatlov had frozen with his both hands in protective gesture). Especially in case of Slobodin the snow evidently melted under his warm body and frozen later.
All three of them especially Kolmogorova have been really well dresed so hypothermia is unlikely explanation (they were all tough tourists, familiar with camping in the snow without all the equipment that we have now (polartec, gore-tex, down parkas and down sleeping bags, mats etc.) - all of them perishing from hypothermia within few hours is absurd).
The ravine four might have been just finished off with broken necks. Their bodies had autopsy after long time in snow.
There are less credible sources saying that Dyatlov group had been followed by another group of people. On the Rusdian TV show there is a guy who tells that his father was hunting in the area, saw the fire, came closer and have seen people being beaten. He did not came forward cause hunting without permit was criminal offense.
---
Now this is all armchair theorizing, grasping at straws and nothing more and it probably belongs in https://dyatlovpass.com/ forum rather then here. ;-)
But let's hope that as Russia's attorney opened the investigation we may learn what has happened some day.
And yes, store your recovery codes in your safe. Or print them, I guess, but it isn't that big a deal.
My problem is with most banks that make me use some MFA that I can't reasonably recover with codes, or those that can be recovered so easily that MFA is a joke.
Of course it also is a reminder to be careful about what money you tie to online accounts at all:
>Nevertheless, the thieves began abusing their access to purchase games on Xbox and third-party sites. “During this period, we started realizing that his bank account was being drawn down through purchases of games from Xbox and [Electronic Arts],” Dayman the elder recalled.
I would never, ever tie a checking/savings account to basically anywhere online. When the money is pulled out of those it's a huge pain to get back if it's possible at all. Credit cards, even ultra basic low cap starter types for people with no credit history yet, are another layer of protection and intermediation. Virtual card numbers with unique cards per account may sometimes be useful. Even better is to take the convenience hit and leave no stored financial payment at all. Just reenter each time, or get $10/25/50 gift cards and use those to fund a game account as needed for new purchases.
>“I pulled the recovery codes for his Xbox account out of the safe, but because the hacker came in and turned on multi-factor, those codes were useless to us.”
I think this is bad design by Microsoft. Why should turning on MFA, or adding a new MFA factor, obviate one-time use recovery codes which are to some extent a weak form of MFA themselves and explicitly should serve as a final emergency recovery thing people have in a physical safe? A decent recovery code system itself is typically a requirement for good MFA, as a final resort in case the factors are all lost/damaged. They could also be used as another way to try to meet the issue of verifying the person who created/owns the account is indeed the one turning on MFA.
I have no idea if Microsoft works this way, but I believe that many places generate new recovery codes when you enabled 2FA. If Microsoft is such a place, then the thieves would have been given the new recovery codes when they turned on 2FA, and any prior codes would be invalidated.
Or it may be even simpler. I don't have an XBox account, but I do have a Microsoft account. Not sure if they are the same or not. Anyway, once you are logged in you can simply go to the security settings and ask for a recovery code. It gives you one, and notes that any prior codes are now invalid.
Recovery codes are really generally just for dealing with forgotten or inaccessible credentials. An example would be someone who forgot their password and they also no longer have access to the email address that would be used for password recovery. Another example would be someone who enabled 2FA and has lost their 2FA device.
Also once, I got locked out because they used incorrect data to generate one of those questions. Once I got in, I then had to dispute that data.
Let's say I was a bad guy and I looked at my target's social media. I see he was in the military, and I see USAA (a bank that caters to the military) is an answer choice, I'll try that one. Or if I know approximately where my victim lives, I'll look at an online map and see what banks are close by. Chances are the victim would get a loan at a bank they are already a member of, and would be a member of a nearby bank so they could deposit/withdraw easily.
I suppose it may work better for people who have lived in a variety of places and had a number of different accounts or loans.
Most of the questions can be easily figured out. See this article: https://blog.alloy.co/answering-my-own-authentication-questi...
Anecdote: I was once asked what type of car I got a loan for. First of all, just because the dealer pulled my credit doesn't mean I bought it (I never took out a loan for the vehicle). Second, just go on Google Street View to see what car is in my driveway, or check social media because people like to post pictures of their cars. So again, more incorrect data they used to verify me, and if it was correct, it wouldn't be secure!
I only use MFA when it is forced on me, yet to encounter a situation where it prevented anyone but me from accessing a service.
The old account has been silent for years, to the point that if I'd forgotten whether I'd even deleted it or not. So imagine my surprise when in the span of a minute, I get several forwarded emails from Google stating that the account was recovered, a new device has signed in, password was changed, secret question changed, and recovery email changed.
Now, as far as I'm concerned, the account is dead and hasn't been linked to anything I've signed into for years. But that doesn't mean it was never linked to anything important and who knows what's still sitting in the archive or who's still in the contact list. So as soon as I saw the messages I jumped to figure out what happened.
But it turns out that all these security alerts from Google are just to "let you know about important changes to your Google Account and services" and if there's a problem just tell you to click a button to login and "Check activity"...which is difficult to do when all your security information has been changed before you have time to respond.
There are options to try old passwords and linked email addresses, but after several attempts all I got was "Unfortunately Google couldn't verify that <the account> belongs to you." and a link to "Recover your account"[1] that just tells you to try the recover options that have already been prompted for, and if all else fails "consider creating a replacement Google Account."
There is no contact information, no option to let anyone know you have a problem. The emails alerts are sent from the uncaring "no-reply" address while Googles "Contact Us" only gives a physical mailing address and directs you to the same help articles.
Now, again, the account is--has been--dead as far as I'm concerned. But considering the forwarding rule was still in place Google probably thinks differently. So now the account, and everything in it, belongs to someone else.
The moral of the story is not only do you need to practice good security now, you need to have done it your whole life, and go back to do it better when new security practices are adopted--before crooks do it for you.