8 ms·
If you're using a password manager to have unique passwords for every site, what does TOTP 2FA even protect you against? Since 2FA only comes into play for pro
by SpaethCo 8y ago
If you're using a password manager to have unique passwords for every site, what does TOTP 2FA even protect you against?
Since 2FA only comes into play for protection if the password is compromised, if you're using a password manager that should mean that data breaches at unrelated sites shouldn't be a risk.
So we're down to phishing and malware/keyloggers being the most likely risk -- and TOTP offers no protection against that. If you're already at the point that you're keying your user/pass into a phishing site, you're not going to second guess punching in the 2FA code to that same site. I'd even argue push validation like Google Prompt would be at a significant risk for phishing, unless you are paying close attention to what IP address for which you're approving access.
- bad_user 8y ago> If you're using a password manager to have unique passwords for every site, what does TOTP 2FA even protect you against? Man in the middle attacks of course, which are possible on insecure connections. With the prevalence of root certificates installed on people's computers as a corporate policy, by shitty anti-viruses, etc, it's very much possible to compromise HTTPS connections. The TOTP 2FA code acts as a temporary password that's only available for a couple of seconds. A "one time password" if you will. Yes, it still strengthens security. Read 1Password's article about it: https://blog.agilebits.com/2015/01/26/totp-for-1password-users/ https://blog.agilebits.com/2015/01/26/totp-for-1password-use...
- SpaethCo 8y agoIf there's a MitM attack, you've already lost. Sure, they can only login one time, but they're in once you provide the authentication steps. Phishing sites collecting and using the 2FA creds in real time was discussed here, among other places: https://security.stackexchange.com/questions/161403/attacker-circumventing-2fa-how-to-defend/161545 https://security.stackexchange.com/questions/161403/attacker... With available open source like https://github.com/ustayready/CredSniper https://github.com/ustayready/CredSniper readily available, you're only going to stop lazy phishing attempts. You only get protection if you assume the scripts are just passively collecting information for use at a later time. If they're actively logging in to establish sessions while they're phishing, it's game over.
- testvox 8y agoYeah that's why codes don't make for a good second factor. You should use something like Fido or a client cert such that a MitM can't continue to impersonate the client.
- toasterlovin 8y agoBut don't many sites require a second authentication to modify access to the account (change password, add collaborator, etc)? In that case, an attacker would need a second one-time code.
- joshuamorton 8y agoNormally I believe they just require the password. The threat model there is someone leaving their account logged in.
- toasterlovin 8y ago> Normally I believe they just require the password. Shoot, you're right. Not sure what I was thinking. My bad.
- tptacek 8y agoThis would make sense if virtually every website in the world didn't react to the short-term TOTP secret by handing back a long-term HTTP secret.
- lmm 8y agoIf there's no point improving client authentication until you've improved website security and no point improving website security until you've improved client authentication then neither will ever get better.
- anfedorov 8y ago> If you're using a password manager to have unique passwords for every site, what does TOTP 2FA even protect you against? Sounds a little obvious to write it out, but it protects against someone stealing your password some way that the password manager / unique passwords doesn't protect you against. Using a PM decreases those risks significantly, mostly because how enormous the risks of password reuse and manual password entry are without one, but it certainly doesn't eliminate them entirely.
- SpaethCo 8y agoThis is the thing I struggle with: name a scenario where you would have your unique site password compromised but not have at least 1 valid 2FA code compromised at the same time. The best answer I have for where TOTP can provide value: you can limit a potential attack to a single login. I wanted to say you could stop someone doing MitM decryption due to timing (you use the 2FA code before they can), but if they're decrypting your session they can most likely just steal your session cookie which gets them what they need anyway.
- dgacmu 8y agoBecause you accidentally type your password for site A into the login for site B.
- leokennis 8y agoSomeone “hacking” the 1Password web service Logging in to a site on a public computer and the browser auto-remembers the password you typed A border agent forcing you to log into a website (this scenario only works if you leave your second factor, which will most likely be your phone, at home)
- Damogran6 8y agoUsually in a higher security environment, we'll make sure the authenticator is a separate device (phone or hard token) and expressly forbid having a soft token on the same device that has the password safe.
- tptacek 8y ago
- jchw 8y agoThe point is that one time passwords are only valid once. If your password is stolen, it's stolen. If a TOTP code is stolen, it's probably not even useful because it's already invalid when they log in (including for time based, in well-designed software.) There's obviously a class of attack that hardware tokens protect against (malware) that password managers can't entirely (unless your operating system has good sandboxing, like Chrome OS for example.) But it really does protect against phishing to a degree, as well as certain attacks (key loggers or malicious code running on a login page on the browser) Hardware tokens are the winning approach, but even when you put TOTP into a password manager it is far from useless.
- betterunix2 8y agoIt only protects against the most naive phishing attacks, where the attacker just accumulates passwords for use at some later date. More sophisticated phishing attacks will just copy the OTP in real time: https://www.schneier.com/blog/archives/2015/08/iranian_phishin.html https://www.schneier.com/blog/archives/2015/08/iranian_phish... U2F defends against that sort of phishing as well.
- jchw 8y agoSure, but most people aren't targeted by advanced adversaries, so using your password manager for TOTP can be a lightweight way to make most hackers completely disinterested in attacking your account. U2F requires an additional investment. Depending on the type of physical security you want, it's normally a good idea to invest in at least n+1 U2F keys, so you have a spare key you can keep with you and permanent keys in all of your devices. (Obviously, the latter means that your U2F can be stolen easier, but the reality is that this is not nearly as big of a deal as stealing a password, since you can unprovision a U2F key immediately upon realizing that it's gone.)
- SpaethCo 8y agoProxying the authentication isn't really an "advanced" attack. In a 19 minute video[0] the author of CredSniper[1] gives a complete walk-through for setting up his proof of concept tool, including building the login pages and registering for LetsEncrypt SSL certs. The hardest part still remains choosing the domain name and getting people to click the link, and still people find ways to overcome those hurdles. As TOTP use has increased, the basic phishing toolkit has evolved to match. Attackers want accounts, not passwords, so they're just adjusting to get working sessions. The passwords were only ever just a means to an end. [0] https://www.youtube.com/watch?v=TeSt9nEpWTs https://www.youtube.com/watch?v=TeSt9nEpWTs [1] https://github.com/ustayready/CredSniper https://github.com/ustayready/CredSniper
- DEADBEEFC0FFEE 8y agoYou may not be the best example of how this can help, sounds like you have good security sensitivity. Where I'm working now, we deal with several credential loss incident each month. Invariably, our users are tricked into authentication via a bogus site. 2FA would protect the credentials from being used by unauthorised people. Our staff are encouraged to use password managers, but that does not help this situation.
- dwaite 8y agoTOTP can protect against knowledge leakage as it is a second factor. For example, it will prevent someone successfully using a shared password a LinkedIn, associated with a corporate email address, to log into Gmail/O365. It doesn't prevent any sort of active phishing campaign, because the login process can just ask for and immediately use the TOTP credential. User gets a possible failure (or just content based on what they thought they were accessing), phisher gets account access.