5 ms·
The article mentions Yubikeys, but it doesn't mention that Yubikeys implement U2F. The article reports that Google internally switched from TOTP, but doesn't r
by my_first_acct 8y ago
The article mentions Yubikeys, but it doesn't mention that Yubikeys implement U2F.
The article reports that Google internally switched from TOTP, but doesn't report what Google switched to: U2F.
The article describes, in some detail, how TOTP and SMS two-factor authentication can be phished, but doesn't describe a two-factor authentication method that is quite a bit harder to phish: U2F.
There is a pattern here, and it is puzzling, to say the least.
EDIT: Changed "phish-proof" to a more realistic adjective.
- Phlarp 8y agoDeclaring U2F "phish-proof" seems premature at best. It is certainly much better than other existing options, but I wouldn't suspect it to stand up very long at all against a nation state adversary. Feels very much like "air-gapped networks can't be actively infiltrated" before Stuxnet.
- my_first_acct 8y agoYou are right, of course. I have corrected the parent comment.
- Phlarp 8y agoA commenter above even provides a source for a novel U2F phishing attack, although it appears to rely exclusively on bugs in the chrome webUSB feature and is likely already patched. This argument does quickly devolve though; if an advanced persistent threat is taking an active interest in you the only technique that is even close to effective is to cut out as much technology as possible; Bin Laden or Unabomber style