New two-factor authenticator: Commodore 64
oldvcr.blogspot.com
oldvcr.blogspot.com
This is unrelated to "Van Eck Phreaking"
The RF encoder + cable acted as a transmitter.
We were granted a guided tour one night of a facility at the top of a skyscraper in San Diego. It was shrouded in mystery and government TLA programs. My boss was explaining parts of it to me.
He said this is a TEMPEST secure facility. I'd never heard the term but when he described the principle to me it made a lot of sense. My father is a radio buff and raised me to learn all about electromagnetic stuff. The facility had conditioned power lines and shielded walls and partitions that could block EMR effectively to keep computing information safe from prying eyes.
There were other fascinating Top Secret features of the facility that were explained to me that night. Of course the facility was not in operation and unmanned at the time of our unclassified tour. I was gobsmacked at the depth of real bona fide security measures and countermeasures, even in those primitive times.
Everyone has a webauthn capable device, if not multiple, right now.
The only reason phishing is still a thing is because people keep implementing and defending phishable 2FA methods.
(Personally, I'll be waiting until 1Password gets WebAuthn support before moving to it from TOTP.)
1Password is a centralized and proprietary database system that leaks all secrets to system memory every time you use one. Why would you want that to manage webauthn secrets for you? You just tap your webauthn device when prompted. No third party control required.
https://rationalwiki.org/wiki/Not_as_bad_as
TOTP is phishable and the secrets to unlimited codes live in plaintext on both the client and the server. Endpoint malware, phishing, and database dumps are some of the biggest threats online and TOTP offers no strong defense to any of these. In some ways TOTP is even worse than SMS as it is possible to manipulate timestamps to get a code valid in the future. SMS and TOTP both are garbage in terms of both security and UX. Their use should be discontinued ASAP.
Webauthn solves for these problems, and everyone has devices that support it already. It is negligent at this point for web service providers to not mandate webauthn and discontinue both SMS and TOTP.
Webauthn has a number of severe usability downsides that will conspire to hamper its adoption outside of use cases where people are literally forced to use it.
1. The keys cannot be backed up. Nobody is going to accept being locked out of their online accounts if they lose a physical key.
2. Nobody wants to mess with a physical key when logging in anyways. At least TOTP can live in my password manager.
3. The options for not having physical keys are platform specific, tie you to a platform providers account for backup, and turn an operating system reset or a new smart phone or badly applied ban or account lockout from an annoyance to a possibly catastrophic loss of functionality.
None of these are problems in the enterprise because they have simple workarounds. For the rest of us? Yuck. I will gladly keep my platform independent, easy to back up, widely ubiquitous standard with the trade-off of looking at the URL bar when logging in and not clicking links in emails.
To your points:
1. Multiple devices such as Ledger support FIDO key backups in the form of transcribing simple english words to paper. Most services support multiple webauthn devices registered at once though which is simpler for most people. You can also as a last resort offer a user with a one-time-use 2FA reset code just like TOTP sites do if you wish. Lots of options.
2. Your laptop and phone already have built in webauthn authenticators if you have a device made in the last several years.
3. See #1 for backup options
The default paths for TOTP recommended to most like Google Authenticator do not have a backup solution either. Users will have to research alternative TOTP solutions that support backups just like Webauthn, so that situation is no worse.
Webauthn is as good or better in UX and better in every way in security. People had to learn to use TOTP, which is complicated. People capable of using TOTP are technical enough to register two webauthn devices like a phone and a yubikey, or a phone and a laptop, or failing all else a phone and a paper backup.
As this article shows, a 6502-level CPU is definitely powerful enough to do this and other crypto primitives; smartcards, which can perform RSA operations, are roughly of the same power.
FIDO in contrast has better security and retains control, with the main loss being simplicity, I understand how it works pretty well, but most people aren't going to really put the time in or have the inclination.
FIDO is designed to be used for things like WebAuthn, which can't be phished, and doesn't use secrets so the Relying Party doesn't know anything which can be compromised.
You can build one yourself, buy Solo Keys, or indeed buy a Yubico product.
Does Solo Keys enable that?
Generate whatever you need on your PC and then load it into as many keys you feel like.
But even if you don't want to use the popular passkey implementations, you can still easily register multiple authenticators which mitigates the risk of losing one. On a new site, I'll register my hardware FIDO key, my phone as a passkey, and my laptop authenticator (either touch-id on MacOS or tpm-fido on linux machines).
Soon there will be other passkey implementations that will also support syncing and backups (1password for example is working on this).
Don't settle for a phishable authentication method.
We'll see how it plays out but I'm not optimistic this is going to end well.
Why? Its all open standards. There are already a number of independent implementations in the works.
The 'leaking' of the secret is, to me, a feature. That means I can safely store it as a backup (printed in a safe, even) and restore it to any device I want in seconds. I don't care about a leak by the service, because that is game over for my data there anyway: if they can't protect 2F secrets, nothing is safe.
Really, mutual TLS would be perfect, but nobody is going to support that. I seem to remember even Windows tried something like that a decade ago and even their weight couldn't break us away from passwords for Internet sites.
[1]: https://developers.google.com/identity/passkeys/use-cases#si...
[2]: https://support.apple.com/en-gb/guide/iphone/iphf538ea8d0/io...
Not necessarily, FIDO supports attestation.
I don't see it myself, but they really want it, and in niche environments it's not crazy. If you issue all 5000 employees with Fictional Corp. very secure fingerprint authenticators, checking for the Fictional Corp. attestation means you can be sure nobody used their factory default Solo Hacker Key FIDO device and then pasted the resulting values into a GitHub Gist. Would anybody really do that? Well, maybe, after all there were various SecurID tokens facing public webcams so that their owners could use the OTP from the token without risk of losing it...
However, on the public web no relying party (~ web site) should use this, especially one which offers some other unattested alternatives; and you as user shouldn't allow attestation if attempted -- at least Firefox and I believe Chrome let you say "No" and you should.
Do you mind elaborating on that?
Non-standards based "authenticator" dedicated apps phone home and spy on you. Intentionally trying to break or block actual TOTP.
I don’t understand it completely, so would appreciate an explanation.
That's underselling it, mains frequency is deliberately controlled to keep average frequency very accurately in long-term periods.
It's a cool little box, unfortunately hobbled by a terrible screen, interesting timing on seeing this here today.
Of course, most TOTP systems allow for a little clock drift, so being out by a few seconds should be fine.
What a delightful hack. It makes me want to drag my BBC Micro out of the loft to try something similar!
C-64 + 2FA feels sort of ... blasphemous? Besmirching?