5 ms·
> But that also means that if your password manager is compromised, 2FA is broken as well. You either trust the implementation or you don't. If you think a bre
by PuffinBlue 7y ago
> But that also means that if your password manager is compromised, 2FA is broken as well.
You either trust the implementation or you don't. If you think a breach of your password manager will result in the hackers ability to decrypt the vault them you need a new password manager.
At some point you have to trust the encryption.
Plus, if it's really on your mind you can store the keys in an offline vault with something like Keepass.
- Operyl 7y agoSo, by that definition, every password manager is broken. If your machine is compromised, it's kind of game over there.
- pilsetnieks 7y agoThe point is defense in depth. If you must rely on one app, no matter how secure, it does nothing for depth. The whole point of MFA is to have multiple unrelated authentication steps so that when (not if) one is compromised, you're still protected.
- shawnz 7y agoIt still does provide protection against the attack where someone looks over your shoulder while you type the password, since the TOTP is a rolling code
- PuffinBlue 7y agoI don't disagree with at all and I should be clearer in what I'm saying. One has to think logically about where the dangers are and what MFA is used for. If a cloud based password manager is breached and that leads to decryption of the password vault then that password manager is not fit for purpose under any circumstance, whether you store TOTP keys there or not. So by default we have to approach from a position of trusting encryption, right? MFA in the realm we're talking about here plays no role in encrypting the vault (yes you can use keyfiles or hardware keys as part of the decryption/encryption process), under this context MFA is about authorising access to an account. So you can go ahead and store your keys in a second vault, but that vault must have as good security as the password one in order to be secure - i.e. it must not be decrypt-able. So if each of the vaults much not be able to be decrypted in order to be secure there is no reason to use two, as one will be 'good enough'. not decryptable x not decryptable =/ more not decryptable. What I would say is that there are key accounts that need to be secured with offline physical protection. For me, and I'm guessing this is the point you're making, those would be the password managers MFA. If you trust your password manager then you only need to secure access to it in order to secure any other keys/passwords stored inside. So you only need to remember a password (something you know) and use a keyfile (something you have) to get access. You can substitute MFA TOTP key here to if you like, but you just have to secure those two things. If you trust your password manager, you don't need more than that. You obviously have to trust your machine, that's a rather obvious truism I shouldn't have to point out. So my point is, be realistic about where you store thing and what you store and recognise where the defence in depth is of value.
- shawnz 7y agoI think you are missing the parent's point. It's not just a matter of "secure/trusted" or "not secure/trusted". You could trust your password manager but that doesn't mean that compromise is impossible. One reason for having a second factor is to hedge your bets against the possibility that you mistakenly trusted a service that turned out to be insecure or to have attacks that you didn't consider or know about at the time.
- PuffinBlue 7y agoBut that leads to something this whole discussion has made me think about - if the service is insecure my data can be hacked anyway. Add that to the fact I should be using unique passwords for each account I have. So if both of those things are true - what does MFA get me?
- shawnz 7y agoYou mean if BOTH services are insecure. That's the point, with 2FA you'd have to compromise TWO services to get access to all your accounts. As opposed to storing your TOTP keys in your password manager, where only one service would have to be compromised to get access to all your accounts.
- acdha 7y agoYou need to think about the security of the whole system, not just the storage encryption: very few people get compromised by someone running an offline brute-force attack compared to the number who get malicious code running on their system. Password managers can make an effort to harden against that kind of attack but ultimately that's why things like MFA exist since there's a high likelihood that someone will be able to ready anything you have open.
- PuffinBlue 7y agoAgain, I don't disagree per se, but it's such an obvious truism that you have to trust the device you're using it seemed a bit pointless to say it. I'm also not sure of the point you're making? MFA doesn't help you if you open anything like you said. So you're safe until you open something, at which point you've presumably used MFA to open it, but then it's open so MFA doesn't help you any more. Basically, malicious code on device = game over in all any circumstance.
- acdha 7y agoHere's a simple example: 1. You use AWS 2. You lose your phone, `npm install` the wrong package, etc. and someone gets a copy of your password database 3. The attacker tries to login as you to fire up their bitcoin miners In the case where you're not using MFA or are using TOTP with a shared seed, they're successful. If you use U2F, TOTP on a separate device, etc. they'll fail even though your computer still needs cleanup. Consider also that many attacks aren't full privileged code execution — say being able to read a file or dump browser memory but not installing a keylogger or trojan which would allow them to piggyback on your future sessions. If you're not using MFA, that's all they need to be able to open their own session.
- spookthesunset 7y agoThe odds of your lost phone landing in the hands of somebody who is going to spin up a bitcoin mining farm on your AWS account is miniscule. A much, much more likely risk is one of your accounts getting compromised by some dude running a botnet using a list of a million leaked credentials.... if you have 2FA on the site the botnet is targeting, you are immune from compromise. Besides, my phone as the ability to do a remote wipe. It is effectively a bricked door stop until they can log into the phone.
- tptacek 7y agoI think you're thinking about this the wrong way. I trust 1Password. I trust it so much that I don't bother storing TOTP secrets in it, because I don't need a small extra dynamic password tacked on to the strong password it already generated for me. The threat stories where someone somehow captures my password but hasn't fully compromised either 1Password or the site I'm logging into (thus invalidating the credentials anyways) are extraordinarily narrow. 1Password TOTP is mostly just theater.