This elimilates passwords altogether, but are there any pitfalls?
This elimilates passwords altogether, but are there any pitfalls?
With a long enough session life and a good refresh strategy, it's less of a problem. If an app clears sessions after a week, then I would argue they are doing it wrong.
So pretty insecure, but probably suitable for some systems with low security requirements or other mitigating factors.
This elimilates passwords alltogether, but are there any pitfalls?
Coincidentally, I just mentioned that I did this: https://news.ycombinator.com/item?id=40878150
(of course, I leave it as a user preference: The user chooses whether to use standard passwords or to use one-time-passwords)
An easy counter-measure would be blocking consecutive TOTP logins of the same or similar codes.
The attacker has a 1 in 1 million chance of guessing right, assuming 6-digit codes. This isn't acceptable for most applications.
That's assuming there's no throttle of login requests and all authentication were made under one minute against one single user.
I think you're misreading "1 in 1 million" as "1 million in 1 million".
Actually it does change. Even if you hit the exact correct TOTP code, the system still deny your login because of throttle rules and you can't tell on the client side.
> An easy counter-measure would be blocking consecutive TOTP logins of the same or similar codes.
Which was in response to this attack:
> therefore try an attack where they attempt to log into all of the accounts in parallel with the TOTP ‘000000’
That class of attack is a legitimate threat. Your proposed mitigation (quoted above, not some other mitigation) cannot work. That's because the attacker does not actually need to try consecutive or similar codes, it'll work exaclty as well with random codes.
That you later changed to talking about a totally different attack (of trying a lot of codes on a single account) and a different mitigation (rate limiting of attempts on a single account) is irrelevant to that discussion.
1. hack into any account then call it a win
2. hack into a specific target account for a win
idk man. Maybe for some systems #1 is important.
The goal is to replace passwords. So TOTP is is about as secure as, if not better than logins that requires 6 digit PIN, no?
1 absolutely is important for real systems. Think of the account system for Google, Facebook, Steam, etc. Those accounts will have real value to an attacker even if you're only getting a random account.
And no, TOTP is not as secure as a password specifically for a single-factor use case. It's brute-forceable in a way that passwords aren't, in a way that can't be fixed without a lot of collateral damage, and in a way that a high risk user can't even protect themselves against with better password hygiene[0]. A 6-digit TOTP is a decent second factor, but a horrible single factor.
[0] The attack you described of trying out the password 123456 on all users is called password spraying. (Obviously you'd just not use that, but the top 100 to top 1000 passwords). But that's an attack that single users can guard against, and that systems can mitigate with basically no collateral damage. The mitigations for a TOTP-spraying attack would need to be quite draconian.
Hey man you don't have to be so aggressive. I was asking a question "is it secure?" or "are there any pitfalls?"
If it's not secure then naturally I am curious what can be done about it. I don't need to defend to prove anything.
I am happy to learn that such design is inefficient against #1 scenario, especially if such "account system for Google, Facebook, Steam, etc. Those accounts will have real value" were at stake.
A rate limit strategy should limit the rate of the attacker not the victim.
Rate-limiting per email address is just a DoS vector, anyone can prevent a legitimate user from logging in.
I have a system I use where you enter your email and get a one-time code.
The goal in that system is not to securely authenticate you, merely to identify you. "Good enough" for the use case.
But that's a general problem. 2FA should really mean 2 separate devices.