4 ms·
Biggest issue is single point of failure for total access to all devices. Get\guess\beat out the master password and its game over on all connected devices.
by syn0byte 8y ago
Biggest issue is single point of failure for total access to all devices. Get\guess\beat out the master password and its game over on all connected devices.
- IshKebab 8y agoThe way it works now is with SMS authentication which is not really secure at all.
- eridius 8y agoWhere does Keybase use SMS authentication?
- chupasaurus 8y agoNowhere, IIRC you have to add new device from an already trusted ones. GP probably thought about other messengers.
- eridius 8y agoNot only that but this also enables offline attacking of the password. If you can compromise the Keybase server and grab the encrypted passwords, you can then attack it at your leisure with whatever computing power you can scrounge up, over whatever time duration you want. And when you break it, as long as any of the included devices are still on the account, you'd have complete access to everything. Requiring existing devices to be actively involved in provisioning a new device prevents all of this.
- Pxtl 8y agoAh, that makes more sense. So in Keybase, what does device to device provisioning look like? "Hey, you've just set up this device - a message has been sent to all your other devices, OK the message and come back here and you'll be good to go"
- nickik 8y agoYou just scan a QR code. Or if you want to do an offline device you can type in a a set of words that represent the key.
- Pxtl 8y agoYes, but you can use 2-factor auth to control downloading the keystore, so in order to hack the person's account you need to already have physical possession of one of their devices and the master password (either to access their keystore or to get through 2FA). And if it's not a 2FA device, the victim can use 2FA to push a disavowal of the old keys and set up new keys. That's an ugly and server-centric solution, but "halp I got hacked" is going to be an ugly case no matter what.