3 ms·
Yes, that's the part that's wrong/misleading (or at least one interpretation of it). See my earlier comment.
by CyberShadow 8y ago
Yes, that's the part that's wrong/misleading (or at least one interpretation of it). See my earlier comment.
- Borealid 8y agoLet's describe the attack in detail. You know: - A username In order to gain access to this system, you must supply: - A username - The corresponding password - A TOTP code valid for the time you make the attempt If any piece of information you give the server is wrong, you get an "auth failed" message which reveals nothing about which part(s) you got wrong. It is an oracle which answers only "yes" or "no". Assuming you can guess (ask the oracle) once per second, that there are 52^8 possible passwords and 10^6 possible OTPs, and that every thirty seconds the valid OTP shifts to a new totally random value within the valid range, estimate the number of guesses necessary to find (with 50% probability) the correct combination of information. Now repeat the exercise, with the changed situational parameter that you no longer need to supply a correct TOTP. I think you will find that the estimated time to crack is increased by much, much, much more than a factor of two by having the OTP. I would be interested to see any alternate answer and the reasoning behind the same.
- deleted 8y ago[deleted]
- CyberShadow 8y agoAssuming the attacker has neither the password nor the OTP seed and must brute-force both (which is what 2FA is all about), the OTP doesn't add more security than the bits it has (about 20 for a 6-digit decimal number), plus the 1 bit because it's not constant. For this reason, I think it's misleading to say that there are moving goalposts or such. Neither the entire attack nor any part of it must be completed within 30 seconds or whatever the refresh interval is of the OTP token. Cracking both is still a classic brute-force attack.