1. There is an encrypted blob which contains distinct authentication tokens/passwords/whatever for every website/service I have an account at. This blob can be moved around, synced and updated however I like, with zero concern about who has a copy of it.
2. I decrypt this blob locally on device, using a combination of multiple factors such as what I know (a passphrase) and what I have (e.g. a copy of a static but un-guessable and un-rememberable account key, which is copied to all my devices, potentially stored at rest inside a secure enclave).
3. The decrypted blob then authenticates me on services using data which is entirely random and arbitrary.
I could only imagine how much more perfect this arrangement could be with total industry uniformity. Imagine if a common, uniform password manager API was integrated into computers from the earliest days, and all browsers integrating this system service from the very beginning of the Web. Every website could have been built be built around this workflow, not to mention every binary application on desktops and smartphones.
The solution is a competent hardware security layer and a reasonably strong passcode, such as offered on recent models of iPhone. This is sufficient for normal people to thwart opportunistic attacks.
Of course if your adversary is a Government or a corporation that has root permission on your device, you would obviously take a different security posture.
This is because the security of "2FA" isn't really from the fact that there are two factors, but that one of the factors is kinda just ok, and the other factor is ideal. A password on top of a proper 2FA method doesn't actually add any security to the typical login flow.
> So we’re back to one factor that’s ultimately secured by a device password/passcode anyway.
Unsure of exactly what you mean here - in what way is something like a yubikey secured via a password? Also, even if that were the case, changing the scope of passwords is important in and of itself.
> Plus if/when you’re not able to access the device, it’s much more painful to deal with.
Agreed, this is the big problem to solve - essentially this is just a subset of the "recovery" problem. It's one place where passwords may still fit in, though in a different role.
Ultimately, verifying identity at scale is just extremely difficult, and there will never be a perfect solution to recovery, but I think that we can mitigate that quite well with things like:
a) Phones as 2FA devices/ recovery devices
b) Multiple devices (ie: if we can reduce the cost of hardware tokens by an order of magnitude it becomes viable to buy 2+ for many more people)
c) Slower recovery methods that involve leveraging multiple identity methods - things like validating a government issued ID, mailing address, etc.
It isn't, which makes me confused about how it is supposed to be more secure. If I lose my keys with a physical security key attached, not only do I now have to worry about somebody breaking into my house, but all of my online/digital properties as well (assuming passwords become a thing of the past). If they have my phone which has Touch/Face ID enabled, that poses a much more significant challenge to an attacker (and can maybe be mitigated if I can remote wipe the device in time).
> but all of my online/digital properties as well (assuming passwords become a thing of the past)
For sure, and that's definitely not a threat to take lightly - another thing to consider would be when the attacker is someone who inherently has physical access to you (say an abusive partner, parent, etc).
You're totally right that a password can, at least to some extent, help in these situations. Like I said, I still see a use case for the password, it's just that the scope would change - like how password managers only require you to remember one single password, and that password is essentially only used in one place. This really reduces the risk of phishing.
> If they have my phone which has Touch/Face ID enabled, that poses a much more significant challenge to an attacker (and can maybe be mitigated if I can remote wipe the device in time).
Yeah, agreed - I think biometrics can definitely be a key part of how we get to a password-less world. There's other stuff too, like if the attacker has your key, but they're logging in from a new device, maybe it asks for some other verification like a biometric, or even a password / pin - but now the password again is taking a very different, much more limited role.
All I'm really saying is that the current way things work is pretty bad. Passwords get forgotten, guessed, stolen, reused, phished, etc. Using a device solves those problems really well, and while it does have its caveats, I think the caveats are largely addressable.
[0] https://developers.yubico.com/yubikey-piv-manager/PIN_and_Ma...
I can use biometrics/sms for the less important stuff.
As much of a Science Fiction fan I am with "iris logins" and similar, I am also a retro-futurist who appreciates things like punch-number security for secured doors.
I mislike this current 2FA path of security for several reasons, the least of which is what if the email never comes or I don't have a cell phone (let alone a smartphone)? I'm screwed.
Passwords, passcodes, number pads ... seems to be quite more Human than all of this "prove yourself in the name of security theatre" these days.
It's unchangeable and externally facing. The only truly secure enclave is the things in my head, and they have the benefit of being changeable if compromised, and I can make a positive distinction of value if under duress.
[Snark warning!]
"We were compromised. Rotate your passwords, chop off your finger and change your face."
[End snark]
Biometric measurements are fuzzy, by their nature. This in turn means that for every stored biometric identifier, there is a whole range of inputs / input signals that will match. On top of that, the measurement devices are on untrusted systems.
If you can compromise the device and extract the signal sent from the sensor, you should have a near universal replay payload. Right now that is still an espionage realm threat, but as these methods become more universal, mass attacks against large populations become more and more appealing.
Archives of valid (username, password) tuples are already sold on underground markets. It's not much of a stretch to predict that (username, biometric sensor dump) archives will eventually become a commodity too.
If the manufacturers had a sense of security, they would make the sensor into a hard-wired device that takes an auxiliary value as input and combines the input with a fuzzy extractor to provide a unique key per auxiliary value in such a way that neither the value nor the biometric can be extracted from the key.
But I'm not holding my breath!
[1] https://support.google.com/accounts/answer/7026266 [2] https://www.forbes.com/sites/zakdoffman/2020/06/17/google-co...
They all do the same basic thing: userid and password let them know who you claim to be, which they validate using one of the second factors listed above.
Can you provide some more information on how using Google's security prompt provides "where you are and what you are doing"?
Sure it's broken if that password is "password123". And remembering 20+ characters (minimum to be good) isn't practical.
But all that is solved problem with password managers. Generate very long truly random & unique passwords which are never reused and that is actually very strong.