5 ms·
Just to add, Twitter's 2FA is "broken" because it only has SMS support. You cannot configure an app and I don't want to give Twitter my phone number.
by middleclick 10y ago
Just to add, Twitter's 2FA is "broken" because it only has SMS support. You cannot configure an app and I don't want to give Twitter my phone number.
- zeeZ 10y agoEven if they supported an app (TOTP Google Authenticator style), wouldn't it be likely for the secrets to have been leaked along with the passwords?
- irremediable 10y agoWhat exactly are you asking here? I read it as saying the 2FA somehow "leaks", but that doesn't make sense, so I think I've misunderstood you.
- sitharus 10y agoHardware/Software 2FA tokens are based on a PRNG with a shared seed. If the table with passwords was accessed it's likely the table with 2FA seeds is hacked. Twitter uses a one-time code sent via sms so I don't think this would be an issue unless the hack is persistent.
- irremediable 10y ago> Hardware/Software 2FA tokens are based on a PRNG with a shared seed. If the table with passwords was accessed it's likely the table with 2FA seeds is hacked. Oh, damn. Thanks for pointing this out. I'd never looked into the details of HOTP or TOTP -- I assumed they were using public-key crypto rather than just a hash of shared values. That sucks. :(
- zeeZ 10y agoAlmost everyone here was talking about a leaked database of accounts, so I went with that if the database leaks, shared secret 2FA is useless. The article says data may have come from user input, so yeah, 2FA would actually help there and wouldn't "leak".
- brian_cloutier 10y agoAccording to some guy on reddit you are correct: https://www.reddit.com/r/crypto/comments/3et3va/why_does_totp_use_a_shared_secret_instead_of_an/cti7l7b https://www.reddit.com/r/crypto/comments/3et3va/why_does_tot... The post also gives a justification for using symmetric encryption, it lets the tokens users enter be shorter.
- bad_user 10y agoWhile that's annoying, I wouldn't call lit broken. Most 2FA-enabled services I know want a phone number first, including Google (and from what I remember Facebook as well). If you're worried about your privacy, which is understandable, buy a prepaid sim card, a cheap phone and use it only for your 2FA accounts. Not sure about the US, but in my country prepaid GSM sim cards are cheap and you don't have to give away your ID to buy one (though this may change soon).
- heartsucker 10y agoTo me that's broken because if I travel, change numbers, or have wifi but no cell coverage, I can't access my account.
- cdubzzz 10y agoBy that logic, it is also also broken because if you don't have access to your phone or the Google Authtenticator app or phone OS is malfunctioning, you can't access your account.
- scrollaway 10y ago"Google Authenticator" style 2fa is an open spec. You can build your own authenticator to your own liking. So no, "by that logic" doesn't apply. You can choose to use something else than a phone to auth, but if it's SMS based well... I just came back from a week in France where I had zero cell connectivity. Had I been using any kind of SMS based 2fa, I would have lost access to those accounts with no forewarning.
- heartsucker 10y agoBut I can back up the secret in multiple places, and as another commenter mentioned, TOTP is an open spec, so I don't have to rely on exactly one sim card being in range of a cell tower. I have options. My bank requires SMS confirmation every time I send money online, and when I was in the US for 10 days, even with my SIM, I couldn't get SMS's, and thus couldn't do banking. This is extremely annoying.