Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
It helps to consider the threat model. 2FA is protection against (at least) several things: brute-force password guessing, a stolen password, a hijacked email account, etc. Since password vaults like bitwarden are designed to be uncrackable on their own, the only plausible way for an attacker to compromise one is to gain control of the user's device, at which point they don't really need access to the vault because they don't just have the keys to the kingdom, they have the kingdom.
Any technology that allows users to add security to their assets while still being convenient enough to use daily, leads to greater security overall.
Personally I think we're about a decade or two overdue to switch away from passwords (as currently implemented) and towards public/private keys managed by the browser or an extension, but I don't see that happening anytime soon as it's 100% certain that if it's ever tried, each FAANG will just try to push their own system, break the whole effort with fragmentation, and everyone will still just be using passwords in frustration for the next 100 years.
My 2FA token is just a second password that doesn't get sent over the wire directly -- it's almost like a private key where you auth via challenge... wait a minute, thought you could sneak PAKE on me?!
If an attacker steals at TOTP, its only good for (I think) less than a minute. If they steal the seed, its good forever.
which isn't really destroyed by having a printout of what you entered onto your phone somewhere secure
(now if you store both in your password manager: that completely defeats the point)
The threat model is someone gets your password, not somebody gets access to your password manager.
If the latter is your threat model then yes having your 2F in there is worse, but really the former is the more common thing to protect against and the tradeoff of not having 2F in your 1Password and getting locked out because your phone breaks is worse than the risk of having it in there.
It’s similar to the tradeoff of having a nano yubikey always in your laptop or a large one on your keys. For most people the nano is better (though you should have a second one in either case)
- Site0 leaks your password because they store it poorly.
- It's just one password, but it's still leaked.
- You have 2F in 1Password so even though it's picked up in an account list the attacker can't login.
- Weeks later you learn there was a breach.
This is the common case for most accounts and breaches. Though the sites most likely to leak are also ones unlikely to have 2F so it's not perfect.
They aren't accessed often, are not used during your normal login flow, and provide you a recovery mechanism that actually works.
Yes - you should store them as securely as you can, but I'd say this is better than disabling 2fa entirely, which seems like the other sane approach.
You need to keep the seeds anyway to generate OTP codes. They are just keeping them in their vault in addition to keeping them in their OTP app.
As long as those storage methods are sufficiently secure, it's not a problem.
All screenshot/print/save functionality is disabled when you have the codes up on your phone.
You need an actual camera on a second device to save them in most cases.
I keep the TOTP and only sometimes keep the backup codes
I avoid the issue created from losing my phone, because the next device can generate codes immediately by importing or scanning the TOTP
I also don’t call it “2 factor” I just call it “one time passcode”
And this isn't even a good example of something that is "obvious" to some people, because Google makes it very, very clear that saving the QR code is NOT a backup option. It is labeled only as a mechanism to transfer to a new phone, so one has no reason to believe that it's non-ethereal. Further, the app disallows taking a screenshot. You have to point a camera at your phone. It's mind-blowing to suggest that it might be appropriate to blame the user for not doing this.
it doesn't matter what Google says is normal
is this really people's only experience with TOTP delivered via QR codes?