6 ms·
Another advantage of sms over dedicated 2FA apps is that even a 10 dollar phone or decade old phone running palm OS can be supported through it. (provided ther
by _nedR 10y ago
Another advantage of sms over dedicated 2FA apps is that even a 10 dollar phone or decade old phone running palm OS can be supported through it. (provided there is network coverage).
A problem with sms though is that you need cell phone coverage. I have been in situations where my transaction has timed out while waiting for the sms text to arrive.
- scrollaway 10y agoYou don't need a phone at all with TOTP. Just a TOTP client, which could even run on the same machine. Fun story about this: When Blizzard introduced TOTP, I wrote a Blizzard Auth library and client so that I could use their 2fa on my desktop (https://github.com/jleclanche/python-bna https://github.com/jleclanche/python-bna). Why? Because I was sharing my Blizzard account with someone else, but still wanted to use 2fa. And people kept telling me "2fa must be on a different machine otherwise it's not secure", so I was using 2fa wrong and shouldn't use it at all. Well that's bollocks. Same-machine 2fa is more secure than no 2fa at all. There's another comment below that talks about "perfect being the enemy of good" and that's exactly it. So we absolutely should start promoting the fact that you can use TOTP on desktop, even if it's less secure. A lot of users don't use 2fa because they either don't have a phone, or don't have their phone constantly with them.
- vog 10y agoCan "same-machine 2FA" be still called 2FA? Where is the independent second factor if it all runs on the same machine?
- scrollaway 10y agoFactor 1 is the password, factor 2 is an ephemeral 1-time-use token. If the token's seed is secure (YMMV), it doesn't matter if it's on the same machine.
- adyus 10y agoHow does that mitigate against the one machine being stolen? The convention is that the chances of two devices getting stolen together are smaller. That's why offsite backups are a thing.
- scrollaway 10y agoIt can, eg. if the seed is encrypted, but that's not what you're warding against. If the machine is stolen, one might install a custom CA or even custom web browser to MITM any https connection and just steal all your credentials, sessions and what not. When Battle.net authenticators were introduced, the primary threat was keyloggers and leaked passwords (from reuse). Both of those threats are eliminated by TOTP, wherever it is.
- jjnoakes 10y agoIf the machine is stolen and someone changes your software (browser, CA, whatever), that only hurts you if the machine is later returned to you and you don't wipe it. But this discussion was more about if the machine was stolen and the bad guys logged in to your online accounts from it. In that case it is true they would have your OTP, but they shouldn't have your Blizzard password.
- jjnoakes 10y agoIt doesn't. Passwords (on the OS account and on the Blizzard account) mitigate against the machine being stolen. OTP mitigates against the password being stolen. It is what you know and what you have so that if someone gets one they don't automatically get the other.
- scrollaway 10y agoAs an aside: The "What you know and what you have" paradigm is failing, imo. We often say passwords should be autogenerated, unguessable and unlearnable, stored in password safes like Keepassx. This removes "what you know" and you end up with "two things you have" (An OTP seed and a password in a safe). When both the password and the TOTP seed are on the same machine - assuming you autogenerated your password - they are both autogenerated and out of your sight so they really are just two things you have, and you have them in the same place. The difference is, it's impossible to capture the TOTP seed from the TOTP token being input - passwords are vulnerable to that. Am I crazy or does that make the password completely redundant?
- _nedR 10y agoMy point is someone should have written a TOTP client for your particular platform. Also different services use different TOTP systems. I am not well-versed in the matter. For example Steam uses its own app, many apps use google authenticator, microsoft uses its own, others still use authy. AFAIK they aren't interchangeable. I can't be bothered installing all these apps, each of them has their own nefarious agenda to hoover data off my phone. SMS just works. (except when it doesn't)
- scrollaway 10y agoTOTP is a standard. It just works, and it always does, even if you don't have internet on your phone. Even if you don't have reception. Even if you're out of credit. Even if you're out of the country. Even if your telecom provider hates you. Authy is TOTP. Google Authenticator is TOTP. They are all interchangeable. You can use FreeOTP if you don't want to deal with those: https://fedorahosted.org/freeotp/ https://fedorahosted.org/freeotp/ Steam is SMS, and I heard they now have a shitty custom 2fa but what you're describing is services that don't use an established standard, which is compatible with hundreds of established clients. SMS isn't merely nonstandard (and now deprecated), it's more expensive for both the user (requires an active sim card) and the server (requires sending SMS to numbers all over the world).
- _puk 10y agoThe argument I've heard for why steam requires a custom 2fa is to do with trading on the marketplace [1] The custom component makes sure that marketplace activity is valid (somewhat like the custom banking dongles you get that require both your pin and some transaction identifier). They'd be better off allowing the option of standard TOTP auth for login, so users can use a standard authenticator app, and then layer on a custom app for trading if needed. 1: http://steamcommunity.com/discussions/forum/0/494631873668954229/ http://steamcommunity.com/discussions/forum/0/49463187366895...
- scrollaway 10y agoCan you elaborate? I don't use the marketplace; how does the custom component achieve any of that?
- mseebach 10y agoYour problem isn't with 2FA, TOTP or SMS, it's with sharing an account that isn't meant to be shared. When you use a feature in a way it isn't meant to be used, sometimes you're going to get some sub-par user experiences. Should Blizzard support multiple users of the same account? Perhaps, but that's out of scope here.
- scrollaway 10y agoThe reasoning behind why I wrote the library is completely and utterly irrelevant. I regret mentioning it.
- icebraining 10y agoThere are TOTP clients for both PalmOS and J2ME phones: http://developer.sysco.ch/php/mobile-dispatcher/mobile.dispatcher.demo.php?a=otpauth http://developer.sysco.ch/php/mobile-dispatcher/mobile.dispa...