7 ms·
2 factor authentication is key here. The ubikey is a gold standard for business - no one should do serious business without it! For everyone else, I think the
by ryanobjc 10y ago
2 factor authentication is key here. The ubikey is a gold standard for business - no one should do serious business without it!
For everyone else, I think the new 2fa Google App approach is better. When you go to login, your Google App pushes a notification to your phone and you have to click on it. This raises the bar to doing a simultaneous login, which isn't impossible, but even if it weeds out a large number of attacks for now, it's worth it!
- shelbyfinally 10y agoIt's Yubikey. Google Authenticator doesn't do any kind of push notification when you log in. Each endpoint uses a shared secret (the server and the mobile app share that secret beforehand) to generate a time-limited code.
- kbar13 10y agoop isn't talking about totp, it's the push notification you get when you log in on a new device (the "review your recent login" notification)
- ryanobjc 10y agoActually I was talking about another method: http://lifehacker.com/google-prompt-lets-you-use-two-factor-authentication-wi-1782413235 http://lifehacker.com/google-prompt-lets-you-use-two-factor-... Essentially its like 2 factor auth, except you arent conveying codes from your phone to the computer. This is a nice feature because it is a lot more user friendly than normal 2fa, it's free if you have a smart phone and well, it works.
- probably_wrong 10y agoI'm waiting for the day in which I can sign up for 2FA without giving my phone number. At this point, I believe they are holding it on purpose, as my phone number is a much more reliable unique identifier than my username and/or cookies. (Yes, you can use the Google authenticator, but no, you can't do it if you haven't given your phone number first) Edit: by "they" I mean GMail - other sites work just fine.
- torbjorn 10y agoTo use google authenticator you do not need to give out your number. Most sites will have a qr code you can scan with your phone and the google authenticator app uses that to generate 2fa codes that are valid within a certain time frame.
- probably_wrong 10y agoI just checked. The first screen I got says "Step 1/3: we'll either call you or send you an SMS. Please give us your phone number". You cannot skip this step on GMail, or at least I couldn't find how. I know you can use the app afterwards, but not before. Other sites just give me the code, as you say. But not GMail.
- calvano915 10y agoYou could create a Google Voice account with a free number and link to that. Set it up so calls/sms/etc go nowhere but can be changed if you need to restore your Gmail account later with that number.
- throwanem 10y agoHow recently have you tried to do so? I tried a couple of months ago to set up a Gmail account with a Google Voice number for verification, and it refused to let me with a message which I recall as being vaguely like "This is not an acceptable verification number".
- 10y ago
- tjohns 10y agoTo be precise: Google's hardware 2FA support will work with any security key supporting the FIDO U2F protocol. Yubikey devices are U2F compatible. (And in my opinion one of the best devices out there, thanks to PGP/SSH smartcard support.) But there are also cheaper versions on Amazon that work just as well if you're on a budget.
- kovek 10y agoWell, on a phishing page the user could still type in the username and password before clicking submit. Only after submitting the username and password do authentication layers require the user to interact with their mobile device (which is usually how it works). Some users might forget that they are supposed to 2FA (say, on their first few days at the job). What if the password input would only be shown after the user typed in their username, pressed submit and confirmed that they were trying to log in using their mobile device? * Input username * Press submit * Interact with mobile device for 2FA * Input password * Press submit
- andrewla 10y agoAdding 2fa does not completely close the exploit window, but it does reduce it considerably. Even if the phishing page prompted for 2fa, those credentials would only be valid for the next ~60-120 seconds, so any attack would have to be staged very quickly. In this example, they waited three days before trying to utilize the broken account; with 2fa they would not have that luxury. And this (asking for 2fa in the phishing page) would entail a risk as well; if they prompted a user who did not have 2fa for their 2fa credentials, then they would immediately be (at best) confused, and possibly suspicious, so they would have to decide to take the risk as to whether to attempt to target 2fa'ed accounts. And if they don't offer a 2fa prompt, then the phishing attempt has fizzled, as even with the password, they only have one factor. Any sort of re-ordering of the login process by the good guys is only effective if the customer is extremely suspicious of changes in the login process, which nobody will be. The phishing site is under no obligation to match their flow to that of the faked website unless not matching by itself would be suspicious.
- _delirium 10y agoI don't think I'd call what Google does 2-factor authentication. Unless I'm missing some option to change this behavior, it's still 1-factor, but what changes when you enable it is which factor is the fundamentally required one. With it disabled, you have one factor, the password; anyone who gets it can log on. With it enabled, the password is no longer the single factor, but it is also no longer a required factor at all, because the password-reset mechanism goes through the same phone number used for the 2fa SMS pushes. So now the phone (or more specifically, ability to receive SMSs to the saved number) becomes the single factor. To be actual 2fa, someone in possession of only one of the two factors shouldn't be able to override the other factor. There are obvious reasons Google does it this way, and it is probably a net increase in security, because a phone as a single factor is less often compromised than a password as a single factor. But I don't like calling that particular arrangement 2fa.
- x0x0 10y agoAlso, you can steal someone's phone account in about a hot minute. Watch: https://youtu.be/bjYhmX_OUQQ?t=98 https://youtu.be/bjYhmX_OUQQ?t=98 This phishing test company has one of their employees steal a reporter's cell phone and it's amazing. She basically plays a crying baby on youtube and just grabs the account without knowing anything... (posted by @nbadg https://news.ycombinator.com/item?id=12598989 https://news.ycombinator.com/item?id=12598989 )
- dublinben 10y ago2FA using a phone number isn't really 2FA, as you've said. There's a reason this method has been deprecated by the NIST and other folks making recommendations about this. Used correctly, their TOTP app is a real second factor, because it only lives on a single device that you have.
- deleted 10y ago[deleted]
- pbreit 10y agoShouldn't Google easily be able to mitigate a login from Africa (or just a different country or even a never-before-used IP)?
- laurencei 10y agoDoes 2 factor prevent phishing though? If I was going to do a Google Phishing page - I would take the username + password that the user supplied into MY fake page, and POST/CURL that to the Google login. If Google returns asking for a 2factor to MY fake, I would display the 2 factor prompt to the user, and get them to type the 2-factor into my page, which I would pass back to Google. Basically you can use a phishing page as a MITM attack. When you auth against Google with 2-factor, there is a "remember this computer" option - giving the attacker at least 30 days of access to your email without needing a further 2-factor code. So if the person is tricked enough to type their username+password into a fake google page, they are just as likely to follow through with their 2-factor code.
- deleted 10y ago[deleted]
- closeparen 10y agoUnder FIDO U2F, the token and website authenticate each other. You're right, though, TOTP is not enough.
- fredericmartin 10y agoTo be clear, there is no real mutual authentication between the server and the token. The server can authenticate tokens (after first registrations) but not the other way. (You have to get outside FIDO U2F specifications if you want to do so.) With standard FIDO U2F USB tokens, the server authentication is done through SSL on the client application level (most of the time : a web browser).
- acdha 10y agoThis is where the type of MFA matters a lot: with a TOTP code, that phishing attack will be successful. With U2F, however, a per-host keypair is generated during the setup process and the public key is given to the remote server. Critically, the hostname as seen by your browser is part of the key identifier: see http://security.stackexchange.com/a/71704/311 http://security.stackexchange.com/a/71704/311 That means that if in the future even if someone convinces you to visit their phishing site and activate the token, the login attempt will still fail because the hostname as seen by the browser won't match a key on the token.
- deleted 10y ago[deleted]
- m4dc4pXXX 10y agohttps://tozny.com/ https://tozny.com/ sells a service that enables this for any app, not just Google. I have a Yubikey and I find it too obnoxious for day-to-day use. I'd rather use an authenticator app (such as Google's or LastPass'). For TOTP on non-Google sites, I find LastPass better than Google's Authenticator. First, LastPass locks the app with a PIN. Second, it can work with the browser extension to fill out those 6-digit codes for you.
- oarsinsync 10y agohttps://duo.com/ https://duo.com/ also provides a service (with free and paid tiers) to enable this in a range of applications.
- maxt 10y agoIf you accidentally delete the Google 2FA app, or your phone is stolen / lost, you have to regenerate all the tokens, which can be quite a pain. This happened to me once, and I was lucky I had several 'recovery codes' which I then used to reset the tokens. Personally I would stay clear from a Google-issued 2FA app as they have more reason to track you and the services you use. Go for something like FreeOTP: https://freeotp.github.io/ https://freeotp.github.io/ Also 2FA can sometimes be overkill, especially if you're constantly logging into accounts which you know will get old and dusty over time (think Yahoo Mail for example)