4 ms·
> I guess this is a dumb question, but is it still "multi factor authentication" if you only use a single physical device to complete the login process? This
by chimeracoder 8y ago
> I guess this is a dumb question, but is it still "multi factor authentication" if you only use a single physical device to complete the login process?
This is a common misconception. The threat model of 2FA is not "I lost my device, and it is now in the hands of someone who knows the password".
The threat model of 2FA is one of:
1) "An attacker has gained remote access to my computer, but not physical access"
2) "I have been targeted by a sophisticated phishing attack, and I trust the machine that I am currently using"
TOTP (and even SMS) protects against (1) in most cases, though U2F is still preferable. U2F is the only method that protects against (2).
- decasia 8y agoThat's interesting, thanks. I always thought the 2FA threat model was "Someone acquired my password" or else "someone has access to my email account and may try to do password resets by email."
- wool_gather 8y ago> U2F is the only method that protects against (2) Would you be able to elaborate on this? I'm not understanding the difference between TOTP and the physical key from the article for this scenario.
- toast0 8y agoWith TOTP, a sufficiently clever phish may convince you to enter the one time code. With U2F, there is communication between the browser and the device, requesting authentication for a specific origin hostname -- that can't (shouldn't) be fooled by a phish hosted at Google.com-super-secure-phishing.net
- tzs 8y agoWhere do password managers fit in here? If a phisher convinces me to try to login to google.com-super-secure-phishing.net using my google account I'm going to notice something is wrong when my password manager refuses to fill in the login form.
- SpaethCo 8y agoThis is where it comes down to user behavior. One of the security engineers from Stripe gave a talk about this at Blackhat last year -- she had phishing campaigns that had users ignore that autofill didn't work and manually copied/pasted their password manager credentials into the phishing sites. https://www.youtube.com/watch?v=Z20XNp-luNA https://www.youtube.com/watch?v=Z20XNp-luNA
- chimeracoder 8y ago> If a phisher convinces me to try to login to google.com-super-secure-phishing.net using my google account I'm going to notice something is wrong when my password manager refuses to fill in the login form. You say that, but the overwhelming body of evidence from real-life phishing attacks and red-team exercises demonstrates that even very technologically-literate engineers will not consistently notice.
- agildehaus 8y agoGoogle and Apple both have mobile (non-SMS) based two factor prompts that seem equally immune to phishing?
- SpaethCo 8y ago> Google and Apple both have mobile (non-SMS) based two factor prompts that seem equally immune to phishing? Any "type in a code" or "approve this login (yes/no)?" authentication factor is technically vulnerable. All the phishing site needs to do is proxy the authentication to the actual site in real time. These guys put together a great overview of the approach: https://www.wandera.com/bypassing-2fa/ https://www.wandera.com/bypassing-2fa/
- SmellyGeekBoy 8y agoThe current domain is sent to the device and used to generate a private key that is used to authenticate. If it's a phishing domain, the device will return a private key that won't work on the real domain.
- kibwen 8y ago> U2F is the only method that protects against (2) A bit of clarification: U2F protects against phishing attacks by automatically detecting the domain mismatch when a link from a phishing email sends you to g00gle.com rather than google.com, which is something that a human might overlook while they're typing in both their password and the second factor they've been sent via SMS. However, if someone were to use a password manager and exclusively rely on autocomplete to fill in their passwords, then that would also alert them to the fact that something was fishy when their browser/password manager refuses to autocomplete their Google password on g00gle.com. So this isn't exactly the only method that protects against the second scenario above... though I will concede that using a password manager in this way sort would sort of change 2FA from "something you know and something you have" to "these two somethings you have" (your PC with your saved passwords and your USB authenticator), which is something that might be worth considering. Regardless, these physical authenticators are a huge step up from SMS and I'm very happy that an open standard for them is being popularized and implemented in both sites and browsers.
- chimeracoder 8y ago> However, if someone were to use a password manager and exclusively rely on autocomplete to fill in their passwords, then that would also alert them to the fact that something was fishy when their browser/password manager refuses to autocomplete their Google password on g00gle.com. Lots of websites do weird modal overlays, domain changes and redirects, redesigns, or other tricks that break password autocompletion. I've never seen a secure password manager that's robust enough against all of these that it would eliminate the human factors causing the phishing opportunity here. Apparently Google hasn't either, because that was their motivation behind developing these schemes.