I Hate MFA
alexmolas.com
alexmolas.com
It would be faster if a password manager is used with browser plug-in.
> It forces me to have a smart phone
Not if we're talking about TOTP. The information for that can be stored in a password manager.
> Or couples online with offline
Not if you use a password manager.
> it can be replaced with other solutions
TOTP + password manager is more convenient (and more online) than yubikey, in my opinion. Especially convenient with a browser plugin.
My chosen pm is KeePassXC, would highly recommend.
One caveat: I hate non-TOTP MFA. It's either proprietary lock-in or less secure.
Agreed. A particular pain point for me is Apple's proprietary (or SMS-based, even worse) iCloud 2FA, it's just awful. I would use TOTP/HOTP for it in a heartbeat if given the option.
Does it matter if they're in the same app?
This is also reductive because it doesn't take into account password managers used on a non-mobile device, where the benefits become obvious in that if one of your devices is comprised it's unlikely that the other is too.
Yes. Call that say 1.25 factors. It is of greater than zero value.
https://blog.1password.com/1password-2fa-passwords-codes-tog...
I don’t use a KeePass or similar device, and I do have my TOTP tokens on my phone (using the great OTP Auth app, no affiliation), but I do most of my work on a computer so I toyed with completely removing password management from my phone and just having the OTP app there. I haven’t committed to that that yet though. Another option is to use a cheap device such as an iPod Touch for OTP, though those are probably more expensive than a dedicated OTP device (I just happen to have one lying around unused).
It's criminal that Google requires you to set up a phone-based or proprietary MFA before you can switch to TOPT.
Your phone number isn't something you "have" - it's something you're renting from another big company, and their security has obvious reset holes made to cope with unsophisticated users, therefore is worse than a password managers.
The only workaround I've found that is non-distracting is to have a dedicated phone-to-web/email system... Google Voice works for this if you're US based.
More convenient than yubikey webauthn, or just yubikey TOTP? Personally I find tapping my yubikey much easier than any 'enter the code' 2FA.
Also it should be noted that storing your TOTP secret in the same place as your password means you're one malware attack away from losing access to that account. While this risk may be acceptable for many accounts, it should at least be considered.
Entering a code is easy because of the password manager plug in. I don't have to find the Key with my finger, I just have to click with the mouse. Much easier.
The private keys stay on your machine
Sinking through a cloud drive is better because it diffuses the value proposition of hacking the cloud drive. If someone hacks The cloud provider they are likely to find a bunch of ripped videos and pictures of children and cats, with the occasional sensitive file here and there. Thus it makes less sense as a hacking target while still having lots of the same protections and professional oversight as any other cloud provider.
The value proposition of hacking a password manager SaaS is much higher so it becomes much more worth someone's time to hit.
It's like the difference between storing gold in a lock box in a bank and storing gold in a lockbox in a storage rental facility. Storage rental still has guards and locks and cameras, but will not attract the attention of dedicated, organize efforts to extract value like the bank will.
I'm not worried about a general cloud beach as much as I am a personal attack if someone gets hold of my phone and manages to unlock it. Then they have 2 of the 3 keys: the cloud drive, and the Auth app. All they need to do is hack the pw manager, which if they have the vault file from the cloud drive, they can brute force until the cows come home.
I agree with you about using a password manager to solve these kind of problems. One thing people don’t understand is we have collaborators that need to deploy to a Chile desert where the environment is so bad that your mobile phone would likely die there. (It’s not recommended to bring one anyway.) So all these solutions requiring a 2nd device, usually a mobile phone, is very annoying. The most annoying part is that these security policy is enforced by central university who don’t care about the requirements of a research project.
But frankly, even if there’s a way to do it with a password manager (using site computing for example so no mobile is necessary), this is not presented as the way to use MFA, and some would consider it a breach of security.
TOTP seems fine to me. Can run it on various devices without a SIM, including just using a password manager like keepassxc on your computer that lets you copy paste the code. Sadly this all gets dumbed down and obscured so most people don't realize what TOTP is or that standard things are being used. We get told to download Google Authenticator or Microsoft Authenticator and keep it on our personal phone against our wishes forever. Hating MFA is quite understandable when it takes this form. Plus some of these TOTP apps make it hard to back up the data for use on another device, making a lost or broken phone rather catastrophic.
Tip, when presented with the setup QR code on a site, decode it and just put the secret into your password manager instead of a phone app (in keepassxc right click an entry and it has a TOTP submenu). Can also be handy to save an image of the QR for later (do at your own risk of course, this is sensitive data) in case you need to set up TOTP again.
People will probably argue this is less secure than letting it all live on your phone, but it still saves you from the most likely threat: websites being hacked and leaking your password. Also it's still protected by your password manager password, which should be unique and only accessible locally.
GitHub recently forced me to use TOTP (not quite the only choice I hear, but bear with me). Well, so I've added my TOTP secret into KeepassXC, and now instead of copying my password from it, I copy the TOTP time code.
I believe the increase in security, if any, is negligible.
Overall there are 2 cases to consider: one where a compromised users screws the user, and one where a compromised user screws the service.
In the first case, which is most online services, the only reason the service cares about the security of an account is to protect the user. They have no business policing how said user handles their own security. Propose and nudge, sure, but verify? That goes one step too far.
In the second case, which would be most enterprise networks, I would recommend that the company issues a security key to each employee, and ensures (with some form of remote attestation if need be) that employees log in with that key.
Scenario 1.5 is non enterprise but with a financial or something of value aspect e.g. rewards/loyalty programs. The service has to protect against fraud
Scenario 2: if we’re having this discussion about the need for MFA, how it ties us to devices and all the other reasons mentioned already, then using a security key with remote attestation is even more difficult for the end user. I don’t see how this is an improvement. It is in fact MFA itself, just with a different, more cumbersome, type of factor
In scenario 1.5 the service has to make sure users are protected. I believe it is counter productive there to force users beyond some reasonable step. For instance, it would be unacceptably discriminatory for a bank to require users to have an Android or iOS phone application to be able to make payments online. (Flip phone users should not be second class citizens.)
Scenario 2 is almost exclusively about employees. Issuing hardware to employees is not difficult. I have 2 company-issued laptops, one from my company, one from my client. If my client wanted to increase security, it would be trivial for them to just give me a USB security key, and it would be trivial for me to just plug that key and touch it whenever there's a pop-up saying I should touch it. I don't see the difficulty here.
In fact, given the choice of installing Okta on my personal phone, or using a security dongle, I would take the security dongle every time. Not only does it better separate work stuff from personal stuff, it's actually more convenient.
Of course it is. Unlocking your passwords in KeepassXC isn't MFA in this context because it's completely orthogonal to phishing, brute force attacks, and data breaches. OTPs are far from great but help with all three, no matter where you store them.
If the password database leaks, the TOTP shared secret can be used by attackers (one can't hash the TOTP shared secret like we do passwords). Phishing? They can just take my TOTP code and redirect it to the legitimate service. I may be able to stop them by asking the service to end the session (if I even find how to do that), but as long as the session is up they can do pretty much whatever they want. At best they'll be barred from doing important operations like changing the password, if the service asks for the TOTP code for such things.
The only thing TOTP really mitigates is brute force attacks, and they do so only for people who use weak passwords. Since I'm using randomly generated passwords with over 120 bits of entropy, I'm basically immune to brute force to begin with.
We have much better than TOTP to stop those attacks.
OTP secrets are stored encrypted, not in plaintext.
> they'll be barred from doing important operations like changing the password, if the service asks for the TOTP code for such things.
Yes, that's what "help" means here. OTPs limit the access lifetime and rights of the session. They help. They're strictly better than a password alone, whereas you claimed they're "not more of an MFA than using the password alone".
To reiterate:
1. The password to unlock a password manager isn't MFA for the services the password manager protects because it's part of the authentication flow of your local system, not of those services. This is also why it does nothing to combat phishing, brute force attacks, or data breaches.
2. Where OTP secrets are stored, on the other hand, is irrelevant for those same threat models. Their value, limited as it is, is the same either way. In fact, if you use a password manager with OTP autofill and never type codes in by hand, you're basically doing as well against phishing as people using FIDO. But again, U2F and FIDO2 are strictly better.
Then so are password hashes. I mean, it would be pretty stupid to make the effort to encrypt part of the login information, and then fail to encrypt the other part.
> Yes, that's what "help" means here. OTPs limit the access lifetime and rights of the session. They help.
Yeah, yeah, they do. How much? "Hardly" In my opinion.
Here’s the thing with TOTP: it’s time based, and therefore remains valid for a couple dozen seconds. Unless the service took special steps to make sure TOTP codes aren’t reused, the MitM can reuse your first TOTP code to change your email & password behind your back, close the session, and lock you out forever. They’d have to be fast, but machines are pretty fast these days. And even if the service does take such precautions, nothing prevents the MitM to ask you for a second TOTP once you make a less than important operation, and if you’re tired enough you’ll just grumble and give it to them.
Point being, there are ways to do long term damage even in the face of TOTP, which are only barely harder than password-only attack.
So sure, TOTP does help. They even help me, by a negligible little bit. But honestly it’s zero vs epsilon as far as I am concerned.
> 1. The password to unlock a password manager isn't MFA for the services—
Irrelevant.
MFA means multiple factors are required to log in. If I’m putting a password in my password manager, I need something I know (master password), and something I have (my password database). That’s 2 factors no matter how you cut it. Whether the service I’m using knows about those 2 factors is immaterial.
> 2. Where OTP secrets are stored, on the other hand, is irrelevant for those same threat models. Their value, limited as it is, is the same either way.
Agreed.
> In fact, if you use a password manager with OTP autofill and never type codes in by hand, you're basically doing as well against phishing as people using FIDO.
Indeed.
> But again, U2F and FIDO2 are strictly better.
They are, if only because the service can be more confident this translate to decent security practices from the user (or at least the user’s machine). And they can be quite non-intrusive, which I like.
I’m wary however of the temptation to use those new credential mechanisms to lock users in. Require FIDO2 if you want, but do not require me to buy a security key from a specific brand (even if it’s the TPM), or store my credential database in some Apple Cloud Shit.
I do not permit anything but passkeys or secure hardware tokens to be issued in our org’s identity providers (no sms, email, totp otps).
https://store.google.com/us/product/titan_security_key?hl=en...
bad: most sites still don't support passkeys so you can't use it yet
In a corp setting, just your idp for SSO requires it. Azure/Entra (Microsoft idp) will support next month. Okta supports today. For those who use Auth0, it’s two checkboxes in your tenant config to enable.
https://passkeys.2fa.directory/us/
https://janbakker.tech/prepare-for-passkeys-in-entra-id/
https://www.okta.com/press-room/press-releases/okta-launches...
https://auth0.com/blog/activate-passkeys-let-users-log-in-wi...
That's kinda the point, as it makes it more difficult for account theft.
Online only solutions are either:
* knowledge based (and problematic for many people due to data breaches and common passwords, though perhaps not for OP)
* public/private key based and not widely supported
> It can be replaced with other solutions
I love my password manager and think it is a great solution for me. But I'm a tech person and know other people who a password manager would be horrible for. Even 1password, what I'd consider to be the leading password manager for "normal" folks has only millions of users[0].
Let's be generous and suppose they have 9M and all in the USA. That's only 2.7% market penetration. Not exactly a mass market solution.
0: https://www.businesswire.com/news/home/20230919527858/en/1Pa...
So yes, they are better but they are still often inconvenient at least when adding a new service.
$ gen-password -len 16 -lower -1upper -1digit -1punct
e$hmvcel9nyghAyw
Another script in the same project generates XKCD-style random passphrases.Passkeys should not require MFA either. I see a good enough future for me and it's:
1. Bitwarden with vault password and MFA
2. Everything else within, passkey
I'm completely unconvinced MFA is necessary if the "password manager at top + passkeys for services" mentality is ingrained in everyone. If you offer a service where I sign in with a passkey and also require MFA you better publish an extremely convincing security paper why, or have an infrastructure critical service that burns the world down if someone unauthorized gets in. There is no other justification for that level of security other than to be an asshole.
My requirements are:
1. Nothing tied to a specific device, especially one that can be easily lost/stolen/broken like a cell phone or USB drive
2. No biometrics
3. It shouldn't permit anyone, outside the website I'm logging into, to know if, when, and/or how often I log into that site.
I'm pretty sure using passwords with an offline password manager is the only thing that satisfies that, but if someone comes up with something better that meets all my requirements I'd be all for it.
If one is lost you grab a second device.
1. Can't be tied to just one device - Must have backup codes or multiple devices that can act as the same to prevent lockout and aid legitimate recovery.
2. No biometrics - Doesn't survive rubber-hose cryptanalysis. Easily impersonated.
I would add the following:
4. Unable to operate without my interactive, explicit permission.
5. Not a device left online 24/7. Preferably detachable.
6. Not an NFC.
Congratulations, we've just reinvented the emperor's new clothes with very long CSHWRNG-generated passwords or key files, password managers, FIDO2 hardware devices, and backup codes.
Also, biometrics generally can't be revoked. Not nearly enough attention is paid to that, and it's very important, IMO.
In the extreme case, let's say you're using actual DNA. On the surface, that looks impregnable to anyone but maybe your identical twin (barring the "rubber hose" thing, of course).
In practice, anyone who's hacked a genealogy site (as happened quite recently with 23andMe, IIRC), or who's managed to grab your used coffee cup or cigarette butt pwns you forever.
Unique 25 character password is much easier to steal than your biometric information. All hackers need is a successful MITM attack (key logger?) or a database dump containing unhashed passwords. They could be some script kiddies from Russia or India running an automated attack on some old version of WordPress. For biometric information they would need to get access to it first and hacking your device (or getting physical access to you) if you protect it properly may not be feasible for majority of them.
Nullifies most of the benefit of MFA though so maybe keep your critical stuff like email logins out of it.
Absolutely correct, if you pay. Which is their right, but I'd argue you shouldn't have to to get such a basic convenience in the digital age as "just works when I want to log in".
If it's a budget thing, self hosted bitwarden/vaultwarden with premium features has been a thing for a while now.
It’s not linked to a single device (you can get your codes on a computer, phone or tablet), it doesn’t require you to be “online”, and you use them for OTP, passkeys and whatnot.
* Press "windows" key * Type the first letter or couple of letters of the name of the code, press enter to copy (which also closes the expose style view and returns to the previous application) * Paste
Very smooth, with this setup I have no issue using 2fa with codes.
Not sure if it can be simplified to this extent on other operating systems / window managers
Just let me have an MFA program like Authy on my laptop, or even make it a Chrome extension. It would be so much more convenient.
MFA is not generally trying to stop the use case where someone steals your laptop while it's open, it's trying to prevent the case of someone stealing your password remotely.
Lastpass is in and of itself a solid argument against the infallibility of a password-manager-only approach.
Say no to proprietary hardware enclosures that deny you access to your own keys. Only use them as secondary auth of convenience, store all your passkeys in a software vault you control.
I don’t disagree with the sentiment, but I’ve certainly never heard of this commandment - at least, not until the author conveniently declared it one to make the point.
Instead it’s the Microsoft Authenticator and it’s different MFA styles:
- sometimes faceID is enough
- sometimes I need to select a matching number in a list of 3
- sometimes I need to type the number myself
- sometimes I need to type a TOTP from my phone to my computer (much worse)
What REALLY annoys me though is places that do support U2F keys, but only one. Last I checked AWS was broken in this regard. And honestly that adds enough friction that I'd rather do experiments on GCP, which doesn't have this bug.
Not that my experiments affect AWS's bottom line. But it does mean that I learn GCP better, and maybe will recommend it in a work context. Not recommend it because MFA, but because I will better be able to say what GCP product can and can't do, than AWS, because of this.
PayPal, on the other hand, only allows a single U2F token.
Ugh, but yeah Paypal… that's why I'm still on SMS (SIM hijackable) and TOTP (phishable) with them.
The author deserves to have a way to work that fits their needs, but really they need to realize that this is an extreme neurodivergence. This is honestly shocking to hear.
When I do more physical things like counting objects or putting away groceries I have far more trouble, dealing with multiple physical objects at once is a lot more overwhelming than writing the same boring code I should probably just pay for Copilot for...
At risk of stating the obvious, this misses the point of MFA.
Password managers are not an alternative to MFA. Also, how do you enforce the usage of a password manager such that you can confidently remove the requirement for MFA?
The whole idea is to protect the one account. If you “only” lose one account that’s still a bad day. Service1 has no ability to protect Service2, so protecting all of your accounts is not something MFA tries to solve
What's especially shocking is when I encounter employers insisting that I setup MFA using a smartphone. Even employers that should clearly know better, working in security-sensitive areas where employees are developers with commit rights to cloud software/operating system code, making lucrative targets. There's a lot of cargo-cult negligence out there.
Fortunately there are better approaches to MFA. MFA is not the problem, smartphones and cell carriers are just raging dumpster fires.
Websites concerned about password use should provide an option to use a randomly-generated password (generated by the website, not the user) in leu of MFA. This guarantees the password is unique and complex, and practically ensures that the user has a password manager.
How is this different from the way we handle e.g. api keys?
I loathe MFA and all this security theatre that makes everything janky.
But I will admit, as someone working professionally as a specialist in the cyber domain, that mfa saved my ass more than once.
I've been consulting with a business on their website, many people have left the company before I got involved..
Godaddy MFA - can't change DNS to new server, no way to renew domain name. What a process to get documents and things together to bypass that -
Cloudflare MFA - if I'm at another IP location I can't clear a cache without getting an email to another person and getting codes.
I like MFA for bank account type stuff.. and I'm serious about security.
However for many things, I would prefer a multi-message that a login has occurred (Send me three emails to different addys and an SMS text) - send me a message that a change has been made, log the ip and changes made.
I feel that an sms and email sent to all known things would help with sim swap issues even more than MFA to swap one..
I mean for some things do both - but many things MFA is a drag, especially domain name related stuff that is easy to reverse if a change is detected.