TOTP Authentication with Free Software
lwn.net
lwn.net
It is possible however that a vendor can choose to obfuscate the key in an app or through some other method. Technically it's in there somewhere, but may be hard to extract. In the case of this phone however the only way in is to have a key.
It won't help me much if I lose my phone while abroad on holidays but if I am close to home this is no big deal. Most services still allows you to use email or sms as other 2FA anyway.
And by devices I mean proper smart cards personally, not old phones, but whatever floats your boat.
This https://developers.yubico.com/ykneo-oath/Releases installed on a java card (cheaper than a yubikey) is perfectly usable with Yubico Authenticator on a modern smartphone over contactless interface.
Ideally I would like a standalone device to display TOTP codes, but the only devices I've found only have a support for a single code.
I guess a feature phone with a custom app is the next best thing.
e: I think you added a reference to this as I was writing my comment :)
https://github.com/dlenski/python-vipaccess/blob/cc4366f7bce...
https://github.com/dlenski/python-vipaccess/issues/39#issuec...
https://github.com/arachsys/totp
It is a very simple application that can be reviewed quickly. I use it from a separate local account that does nothing else to make it at least a bit more second factor-y than a different application in the same account as the browser. You could use the scrypt utility on the data and "scrypt dec data.enc | ./totp" to get the TOTP.
Backups can go to local or cloud storage.
Backups are encrypted with a passphrase that you enter when you set the app up, so the cloud storage providers can't grab your keys.
Is there any way to use a single FOSS app instead of the crap each bank is serving me?
Both desktop and phone apps would be ok.
BitWarden is a good Open Spurce option, it’s cross platform but the TOPT stuff is available only with a paid plan.
Probably same with Googles app.
If there is a move in this area, I predict it will come from something like EU regulations on interoperability (we already have rules on Open Banking to some extent) - something to bear in mind next time the EU's approach to regulation is criticised as "anti-tech".
This would actually be really cool! Over here in the Baltics most banks expect you to use SmartID, which admittedly is fine and has some source up on GitHub, even some nice documentation: https://github.com/SK-EID/smart-id-documentation
But more implementations and support for less vendor lock-in is nice, except that in the case of confirming bank authentication/transactions, there's probably a rather serious matter of trust and security at play (made harder by all of the complexity that you have to deal with). That said, if there was a large community effort, I'm sure that the end result would still be good for creating something like that.
Having a separate device may not be what you're looking for, but for me it beats installing a closed-source app on my phone.
https://www.masteringemacs.org/article/securely-generating-t...
I securely store the master key using Emacs's builtin support for GPG and then decrypt the file on-the-fly to generate a TOTP token, which I select from a dropdown. All-in-all, I can have a key in seconds and paste it anywhere.
It’s an excellent tool that has great encryption and handles multiple accounts and can paste into your clipboard with `totp account.name|pbcopy` and asks for a password on stderr. Pretty cool stuff.
TIL that you can manually edit the otp URI - so I'm guessing it's possible to use it for Blizzard Battle.net too?
https://bitwarden.com/help/authenticator-keys/#support-for-m...
https://discussion.enpass.io/index.php?/topic/14284-totp-for...
(From the last one - relevant URI):
> blizzard otpath string in this format: otpauth://totp/BattleNet:Battlenet?secret=<SECRET GOES HERE>&issuer=BattleNet&digits=8&serial=<SERIAL GOES HERE>
(Looks like bitwarden drops the issuer-param)
Personally, I think storing your password and TOTP secret is worthwhile, but it ultimately depends on your threat model.
If your threat model is someone walking up to your unlocked desktop and unlocked password manager, then it's not very effective. That being said, I believe a determined enough attacker will always win -- just be more annoying to pwn than others and you will sift out the majority of attackers, imo.
But, if your threat model is that a website you use suffers a data breach and your username/password hashes are stolen, you have an extra line of defense with that second factor. This pretty much happens or will happen to everyone with online accounts at some point.
So my long-winded answer is that I do still consider it two factor auth, and I do think it's worthwhile -- but all effective security should be layered with extra defenses when possible.
EDIT: fixed some grammar, added some extra context.
The risk with same-device (or same-manager TOTP) isn't necessarily in a physical adversary (who's going to win anyways), but in a digital adversary who can run code (or read files) on one device but not several. That's one of the main reasons users are encouraged to use physical factors or, lacking that, an on-device factor that requires some kind of OS-mediated privileged interaction.
Yes, correct.
> So my long-winded answer is that I do still consider it two factor auth.
Ok, thanks for sharing your thoughts.
TOTP isn't an ideal second factor, for most of the reasons above (combined with poor adherence to the standard, meaning that only the most basic subset of features tend to work). But is is still a second factor, unless you can do HMACs in your head :-)
But the typical totp-in-password-manager setup is missing the other factor, there is nothing you know in such setup.
But yes, I agree. I keep my TOTP on my phone (I use Aegis) and my password manager on my desktop computer.
Ok. Thanks for sharing your thoughts.
While PCI DSS 4.0 says nothing specific about TOTP, it on page 171 also has this phrase about certificates:
"A digital certificate is a valid option for “something you have” if it is unique for a particular user".
So it is not an unreasonable analogy to claim that the TOTP seed stored in a desktop application is also "something that you have", as not having it prevents you e.g. from logging in from your friend's laptop.
Oh, ok. This is very convincing. Thanks for sharing.
If you have two different passwords, aren't they still only one factor (knowledge)?
> specially if you have...
You mean to say in case the password and the TOTP seed are stored in the same password manager, then it is no longer 2FA?
The shortest one I have is a 6-line Python function using only the standard library.
I noticed that all the major tech companies support TOTP 2FA - e.g. Google, Amazon, Uber, Dropbox, etc. At the same time, I am very annoyed that seemingly none of the Canadian banks or CRA support it. They either use SMS/PSTN or a proprietary mobile-only application (no desktop version). Is the industry standard not good enough for ya?
1. On Android: Authenticator pro
2. On desktop: KeePass (with totp support)
[1] https://play.google.com/store/apps/details?id=me.jmh.authent...
TOTP is great, but developers need to start adding it to their apps by default.
Screw "Duo," the company running my workplace that won't let me have my generating token without hackery.
Of course people who don't know better don't even understand the complaint and say "It's just an app on your phone".
If you do want something like Duo for an organization, possibly self-hosted, and free-software-friendly, then https://www.privacyidea.org/ looks like a good option, but i have no experience with it.