13 ms·
1password does mitigate it to some extent by automatically copying the code to your clipboard after filling the form, these 2 things only work on the right dom
by meroje 8y ago
1password does mitigate it to some extent by automatically copying the code to your clipboard after filling the form, these 2 things only work on the right domain. Of course you can still copy the values from the app but at least it hints at things being wrong.
- tptacek 8y agoIf you're using 1Password-generated passwords and storing TOTP codes in 1Password, how are the TOTP codes not just theater?
- arachnids 8y agoParent's argument is that it mitigates phishing - i.e your normal workflow is you go to a site and your credentials are automatically filled in, so you'd be suspicious if that doesn't happen. In my experience, the autofill breaks so much that I've started copying my password in manually all the time.
- closeparen 8y agoThe TOTP code does not add anything to phishing mitigation.
- Fnoord 8y agoDepends on the exact attack. If its a full MITM (including TLS), no. If its a fake website who don't forward after password-based authentication, yes. U2F would also detect the domain is incorrect, though so does my password manager. Though that's based on a browser extension. I suppose if the browser gets mislead, as would the password manager. And that did happen with LastPass (XSS attack IIRC).
- toasterlovin 8y ago> In my experience, the autofill breaks so much that I've started copying my password in manually all the time. FWIW, this has not been my experience with 1Password at all.
- mason55 8y agoI use LastPass but have had the same experience - autofill is very, very reliable
- ReidZB 8y agoThey are time-limited, at least? But yes, I've had similar arguments with coworkers who've started using 1Password for TOTP in the same way.
- jedberg 8y agoNormally I would reply back and explain, but you know more about this than I do, so instead I will ask a question. Does it not protect against your password being compromised in some other channel? Sure you're probably not reusing passwords, but what if they compromised it some other way? What if the website had a flaw that allowed someone to exfiltrate plaintext passwords but not get at other application data? Or to put it another way, if you're using a password manager, why use TPOP codes at all if you believe there are no other attack vectors to get the password that TPOP protects against?
- tptacek 8y agoThe website and the password manager in this scenario are storing the exact same secrets. If you're going to store them in a password manager, it is indeed reasonable to ask "why bother"? TOTP is very useful! Just use a TOTP authenticator app on your phone, and don't put them in 1Password.
- jedberg 8y agoBut the secrets serve different purposes, they aren't the same. So why not keep them in the same place? I'll admit that it is less secure of course, since someone could compromise your 1Password. But it is still more secure that not using TPOP at all, is not? Again, is there no attack vector that exists that makes TPOP worthwhile when you're already using a password manager that makes it not worthwhile if it's in your password manager?
- Groxx 8y agoSeems like they'd still protect you from anything that records your password and TOTP, but doesn't gain access to your store? E.g. a website gets some JS injected that skims your login. Which doesn't seem all that unlikely. Basically it becomes "just" replay prevention. Which is a nonzero benefit, but totally agreed that it's not at the same level as a separate generator of some kind.
- jwr 8y agoI always wondered what was the point of using 1Password for 2FA. After all, if you store your 2FA secrets in 1Password to generate codes, you've just reduced your 2FA to one factor?
- Woofles 8y agoWhile that's true because you have a single point of failure, I think it's more likely that your passwords get leaked through site security than 1Pass security (depending how you sync/if you use their cloud version) so it's still more (not the most) secure because if they find your password in a database they still don't have your 2FA code.
- SpaethCo 8y agoIf you're using a password manager to have unique passwords for every site, what does TOTP 2FA even protect you against? Since 2FA only comes into play for protection if the password is compromised, if you're using a password manager that should mean that data breaches at unrelated sites shouldn't be a risk. So we're down to phishing and malware/keyloggers being the most likely risk -- and TOTP offers no protection against that. If you're already at the point that you're keying your user/pass into a phishing site, you're not going to second guess punching in the 2FA code to that same site. I'd even argue push validation like Google Prompt would be at a significant risk for phishing, unless you are paying close attention to what IP address for which you're approving access.
- bad_user 8y ago> If you're using a password manager to have unique passwords for every site, what does TOTP 2FA even protect you against? Man in the middle attacks of course, which are possible on insecure connections. With the prevalence of root certificates installed on people's computers as a corporate policy, by shitty anti-viruses, etc, it's very much possible to compromise HTTPS connections. The TOTP 2FA code acts as a temporary password that's only available for a couple of seconds. A "one time password" if you will. Yes, it still strengthens security. Read 1Password's article about it: https://blog.agilebits.com/2015/01/26/totp-for-1password-users/ https://blog.agilebits.com/2015/01/26/totp-for-1password-use...