4 ms·
How does that mitigate against the one machine being stolen? The convention is that the chances of two devices getting stolen together are smaller. That's why
by adyus 10y ago
How does that mitigate against the one machine being stolen?
The convention is that the chances of two devices getting stolen together are smaller. That's why offsite backups are a thing.
- scrollaway 10y agoIt can, eg. if the seed is encrypted, but that's not what you're warding against. If the machine is stolen, one might install a custom CA or even custom web browser to MITM any https connection and just steal all your credentials, sessions and what not. When Battle.net authenticators were introduced, the primary threat was keyloggers and leaked passwords (from reuse). Both of those threats are eliminated by TOTP, wherever it is.
- jjnoakes 10y agoIf the machine is stolen and someone changes your software (browser, CA, whatever), that only hurts you if the machine is later returned to you and you don't wipe it. But this discussion was more about if the machine was stolen and the bad guys logged in to your online accounts from it. In that case it is true they would have your OTP, but they shouldn't have your Blizzard password.
- jjnoakes 10y agoIt doesn't. Passwords (on the OS account and on the Blizzard account) mitigate against the machine being stolen. OTP mitigates against the password being stolen. It is what you know and what you have so that if someone gets one they don't automatically get the other.
- scrollaway 10y agoAs an aside: The "What you know and what you have" paradigm is failing, imo. We often say passwords should be autogenerated, unguessable and unlearnable, stored in password safes like Keepassx. This removes "what you know" and you end up with "two things you have" (An OTP seed and a password in a safe). When both the password and the TOTP seed are on the same machine - assuming you autogenerated your password - they are both autogenerated and out of your sight so they really are just two things you have, and you have them in the same place. The difference is, it's impossible to capture the TOTP seed from the TOTP token being input - passwords are vulnerable to that. Am I crazy or does that make the password completely redundant?
- jjnoakes 10y agoIf you lock your password database with a long, secure password that you know, then you are still doing it "right". If your password database is not encrypted with a strong passphrase, then you are right, they both become "what you have".
- scrollaway 10y agoAh, that's true.