4 ms·
Having a high-security option will be useful for more than executives and politicians. Lawyers, doctors, Equifax employees — anybody who touches highly sensiti
by jforman 9y ago
Having a high-security option will be useful for more than executives and politicians. Lawyers, doctors, Equifax employees — anybody who touches highly sensitive data will benefit.
Email is used as a privilege escalation path to pwn almost every other service we use. And we're finding that 2FA isn't the ultimate answer — OTPs are easy to phish, SMS can be socially engineered around without much difficulty, etc. As the value of digital data keeps going up, the sophistication of hacking groups and governments has gone up as well.
A highly secure browser connecting to an account with limited API access using a physical token is an excellent step. I'll buy it myself if it isn't obscenely expensive.
- KGIII 9y agoSome sort of 2FA done on a USB device might help. I'm thinking something open and free. The user can just extract, probably programmatically, the software to their own USB device and enter/configure any needed information. Then, online accounts could query the device and see if there's a key that matches what was made when they setup the account or added 2FA. Each account could have its own key, associated with the owner's master key, and it'd have to match the one on file - something like that. I imagine it's have to be standardized and easy for site owners to implement. I guess it could also be done at some central location using something like OAuth, though individual sites should be able to add it - and fairly easily, and for just the cost of learning to add it. Maybe make it fairly simply, as easy as LetsEncrypt - or even easier. Now, in my head, they'd enter their username (no password yet) and that's when the check would be performed. The site would request the token from the USB and the USB would request the token from the site. If the two match whatever criteria the security gurus come up with, they are prompted to enter their password. I suppose there could be additional checks and maybe even periodic poling from either the USB or the site. Because the phishing site wouldn't have the correct key, it would fail and the user wouldn't even be asked for their password. Ideally, the user wouldn't have t do much more than carry their USB drive with them. I suppose it should be easy for the owner to clone the USB key. It should also require some sort of master password to even authorize it to hand out keys. I imagine enterprises can lock them down to a key and a workstation, meaning that they can can only work in certain computers and certain computers will only accept one physical key. I am sure this can be refined and monetized. Selling solutions to businesses and services would be nice. Recovery should be possible but difficult. I'm sure it can be layered with additional features. It should probably be optional, and not mandated by law for the general population and for personal computing - but available for them. I'm sure there are ways one can think of to get by it but it does seem like it'd be a good place to start. It also doesn't seem like it'd be technologically difficult to accomplish, or even necessarily expensive.
- tonyztan 9y agoIt seems like U2F fits most of your criteria: open and free, standardized and easy to implement, foils phishing, etc. It can't be easily cloned though. https://en.wikipedia.org/wiki/Universal_2nd_Factor https://en.wikipedia.org/wiki/Universal_2nd_Factor
- KGIII 9y agoThat looks like a good starting point. Does the site exchange tokens with the USB key, so that the device also confirms the site is who they should be? My thinking is that the site should have a custom token to exchange with the device and the device should have a custom token to exchange per site. I'd also love to see it easily replicated and free for the user to put on their own devices. People are going to lose them, in droves. They'd be password protected, of course. I guess you could make them delete their data if there are too many mistaken password attempts, as well as make it destroy the data if used in an unapproved computer - things like that. I figure they can layer different features atop it, depending on how much security is needed.
- emmatoday 9y agoU2F has a per-site key. The browser acts as an intermediary between the site and USB authenticator. My simplified understanding is that it works like this: The first step is registration of the authenticator with the site. The site sends a registration request to the authenticator. The authenticator generates a new key pair. It encrypts the private key with a symmetric key that never changes and never can be extracted from the authenticator. Then it sends a registration response to the site, which includes BOTH the public key and the encrypted private key. The site is responsible for keeping the keys. Then you are ready to authenticate. The site sends a challenge request to the authenticator which is unique and probably has an expiration time. Inside the challenge is the encrypted private key. The authenticator uses the never changing symmetric key to decrypt the private key, sign the challenge, and return it to the site. Then the site checks the signature against the public key on file. The key benefit here is that the browser will not allow a site to send a challenge which is not for it's own domain. Which means there is no way a phishing site can MITM the 2FA process. Even if they get a challenge from the real site, the browser won't let them present it to the authenticator to sign. As opposed to TOTP where the OTPs can be easily phished and used within the time window they are valid.