4 ms·
There are also problems with that: https://news.ycombinator.com/item?id=15068567 https://news.ycombinator.com/item?id=15068567
by tectec 9y ago
There are also problems with that: https://news.ycombinator.com/item?id=15068567 https://news.ycombinator.com/item?id=15068567
- luke3butler 9y agoThat's not Authy/Google Authenticator. That's social engineering their way into getting a persons text messages for SMS 2FA.
- chatmasta 9y agoIf you can compromise the iCloud account of an iOS user (pretty sure iOS 2fa is only SMS based), then you can install google authenticator on your own device. I'm sure it's more complicated than that in reality, but if you have SMS access, you only need to find one weak link in the chain including iCloud/google, email provider, app provider, etc.
- 15155 9y ago> install google authenticator on your own device. You sure can, but will you then have the requisite TOTP secrets?
- joosters 9y agoNo. iCloud backups don't contain keychains, where the Google authenticator stores its seeds.
- chatmasta 9y agoDoesn't iOS keep keychain synced with iCloud keychain? Or at least, it's user configurable. I'm pretty sure I opted out of it. Good news is according to apple [0], you can protect your icloud keychain with a six digit code required to move the keychain to a new device. [0] https://support.apple.com/en-us/HT204085 https://support.apple.com/en-us/HT204085
- Shorel 9y agoThat's a cellphone network security issue. If instead of SMS the 2FA use only a software token generator, then highjacking the cell network would not be a successful attack vector.
- laumars 9y agoThere are problems with any method of authentication when being targeted by a determined enough theoretical attack. The key is to find a process that balances risk against inconvenience. Google Authenticator (which, by the way, isn't what your link refers to. That only covers SMS) is a great middle ground for most reasonable security requirements. If you feel the need for something stronger then go for 3 factors, alerting systems, disable remote logins entirely or whatever extra steps is recommended by your pen testers. I should also add that to just highlight problems with one specific method of 2FA without establishing that it is still more secure than a single factor password, let alone acknowledging that other methods of identification are available, somewhat misses the point of 2FA.