This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
Average person reluctantly moves from 123456 to P@55word!
8 years ago "no passwords such, use a pass phrase"
Average person reluctantly moves from P@55word! to correct-horse-battery-staple
6 years ago "ok but you need to use different passwords on each site"
Average person reluctantly moves to different passwords per site
4 years ago "but you can be phished, you have to use 2FA"
Average person reluctantly moves to SMS
2 years ago "no in some countries it's easy to take over SMS, use TOTP"
Average person reluctantly moves to TOTP
Today "no TOTP is rubbish, you can be phished, use this hardware authenticator"
Normal people don't like new shiny ways of working every year or so. My house's front door lock is broadly the same interface as my great-grandparent's front door lock, but technologists think changing the way things work every couple of years is acceptable.
Nobody should ever suggest you use TOTP or SMS 2fa to prevent phishing.
> 6 years ago "ok but you need to use different passwords on each site"
Really the only one that matters in practise. TOTP is basically just a work around to get users to actually do this.
Edit: i would also add this is a corporate environment where its reasonable to be more picky. And webauth really is the best (only?) Solution to phishing.
It also depends on how sophisticated the attacker is. Do they fake log you out so they could capture a second 2fa token in order to change the totp token to a new device and change your email?
And of course, for the most part damage can usually be done in minutes - copying confidential files does not need long term access.
True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an internet-connected computer.
Moreover, while the threats against your front door have remained marginally the same as those against your great-grandparent's door, computers and the network they are operating in change extremely frequently. All the security recommendations you're naming were quite reasonable for their time but rapidly became outdated.
They very explicitly said they're paying enormous amounts of money to avoid being robbed (I'm not missing the irony here).
Something I found out recently is that my lockable desk drawer can be thwarted by giving it a sharp shove to the right while pulling the drawer. It juuust about pops the metal locking rod out of the mechanism for a moment, if you're pulling on the drawer it'll just open.. Found it out when I misplaced the key, haha.
The safety glass in cars is especially difficult where I expect much less from that in a home.
With the obsession over insulation I suspect they're stronger than I remember, but brute force always works - if not, just use more. Maybe introduce leverage
While surely nothing offers complete security, it massively increases the effort required to break in (from essentially zero).
The list you are describing could as well be seen as every service trying to implement the simplest and least disruptive technology, only to find out two years later that it was insufficient and switching to the next best thing, only for the cycle to repeat each time.
Which of course from the users perspective doesn't make a difference, but it gives a different perspective on how to solve it for the future.
I'm sure authentication technology will settle down in a decade or two.
Most regular users never moved beyond using 'P@55word!' everywhere.
I don't even think it's realistic to get him to use a smartphone for this, he hates the things.
WebAuthn works great for your Web 3.0 startup but as soon as you're talking about the average user, who is likely decades older than the commenters here, and far less interested in keeping up with these things, and far less patient with the hassles... asking them to carry hardware is a nonstarter for so many.
I don't know anyone using "Hello" but I suppose it's an option. Most Windows users would likely have to use a hardware key though.
That's surprising. As in, the fact that that happens is to be expected from the firmware's point of view - updating the firmware changes the measurements made to the TPM so any secrets can no longer be unlocked. But I would've expected Windows to update the expected measurements before applying the update to prevent that from happening.
It can also be defeated by any idiot with a bump key in about 10 seconds.
A reluctant move is still a move, and thus beneficial. But we definitely have different ideas of the “average person”. I sincerely doubt the average has moved on from P@55word, and even then only because the website they’re trying to register an account with imposes the rule. I’d be happy to be proven wrong; do we have data on it?
8 years ago "no passwords, use a pass phrase"
Average person reluctantly moves from "P@55word!" to "P@55word! P@55word! P@55word!"
6 years ago "different passwords on each set"
Average person shrugs and changes nothing
2 years ago "use TOTP 2FA"
Average person already using SMS changes nothing, and the sites allow this as a grandfathered exception effectively indefinitely
Your front door doesn't have thousands of anonymous bots a day trying to brute force it.
I'd be glad to personally, but if a site supports 2fa at all, then it's mostly likely TOTP. And some require TOTP first and allow webauth only in addition to it.
While not as secure or convenient as a security key for initially logging in there is no need for a new device in many cases.
besides the fact that the webauthn yubikey is $20 vs $50-70 for it's more popular and well known versions.
If this was Meta, or Twitter that got breached via there would be outrage everywhere as to why employees did not use hardware keys.