5 ms·
As a user I find SMS-based 2FA much easier to use. It's a tough challenge to make authentication both secure and user friendly. I've recently appreciated the G
by helipad 9y ago
As a user I find SMS-based 2FA much easier to use. It's a tough challenge to make authentication both secure and user friendly.
I've recently appreciated the Google and Facebook iOS apps just letting you tap 'Yes' to confirm identity. It still requires me to go and find the relevant app on my phone, but it's relatively low friction. Much better than Google's own Authenticator app. How secure is that method?
- packetized 9y agoAny ‘push’ method to an app will end up being more secure than pure SMS 2FA, because it’s relatvely hard to MITM/hijack it, unlike social engineering your way into porting a cell number.
- Spivak 9y agoIf you're at the point where your biggest threat is a SE attack on a major cell provider I think you're doing pretty good with security.
- jkaplowitz 9y agoI used to agree, but those attacks are pretty easy to do and have been reported on this site many times. Whereas the other solutions described in the post don't have that attack vector.
- Twisell 9y agoWell it however come with a big con, you become dependent of a third party implementation with dependencies and specifics rules whereas sms is amongst the most used and understood communication standard. This blog post publicise Microsoft implementation but it’s the same problematic for every possible GAFAM specific solution. Apple approach to include a secure and synced password manager in all their product is far more standard friendly approach imho.
- jkaplowitz 9y agoTOTP codes like Google's and Microsoft's apps can use, as well as the U2F security keys, are standardized with multiple implementations in existence. No lock-in with those solutions.
- always_good 9y agoWell, security is only useful when it protects you when you're actually attacked. Social engineering has shown that it's just about effortless to take down someone once they are targeted. It's about as hard to target someone as it is to read their whois address to a customer support rep.
- packetized 9y agoWhat about being targeted for $40k in your 401k? How about your one-or-two-letter Twitter nick? These are things that have actually happened.
- s73v3r_ 9y agoI know I recently got something from T-Mobile asking if I wanted to set up a password that I had to give in order to port my number out. I called up T-Mobile and set it up.
- Buge 9y agoA push method that contains a code, or a push method where you just tap "yes"? Because just tapping yes is much easier to MITM/hijack. The attacker just has to log in at the same time as you're trying to log in, and you will tap accept and let the attacker in.
- falcolas 9y agoAgreed with the easier comment. Any replacement has to be at least as easy as SMS. I honestly don't think that a replacement which requires an individual app on the phone is going to reach the same levels of use as SMS. Google Auth style rolling OTPs get frustrating anytime there's a poor server implementation - where time drift is not well accounted for. I've had my company VPN reject valid tokens too frequently. 30 seconds, plus any drift in time (insert general rant about setting up VMs without ntpd), is just not always enough time.
- CodeWriter23 9y agoIMO, 1Password with TOTP integration is even easier. When I pop 1Password to log in to a site, it copies the TOTP to the clipboard so I can paste it at the next prompt.