4 ms·
Again, I don't disagree per se, but it's such an obvious truism that you have to trust the device you're using it seemed a bit pointless to say it. I'm also no
by PuffinBlue 7y ago
Again, I don't disagree per se, but it's such an obvious truism that you have to trust the device you're using it seemed a bit pointless to say it.
I'm also not sure of the point you're making?
MFA doesn't help you if you open anything like you said. So you're safe until you open something, at which point you've presumably used MFA to open it, but then it's open so MFA doesn't help you any more.
Basically, malicious code on device = game over in all any circumstance.
- acdha 7y agoHere's a simple example: 1. You use AWS 2. You lose your phone, `npm install` the wrong package, etc. and someone gets a copy of your password database 3. The attacker tries to login as you to fire up their bitcoin miners In the case where you're not using MFA or are using TOTP with a shared seed, they're successful. If you use U2F, TOTP on a separate device, etc. they'll fail even though your computer still needs cleanup. Consider also that many attacks aren't full privileged code execution — say being able to read a file or dump browser memory but not installing a keylogger or trojan which would allow them to piggyback on your future sessions. If you're not using MFA, that's all they need to be able to open their own session.
- spookthesunset 7y agoThe odds of your lost phone landing in the hands of somebody who is going to spin up a bitcoin mining farm on your AWS account is miniscule. A much, much more likely risk is one of your accounts getting compromised by some dude running a botnet using a list of a million leaked credentials.... if you have 2FA on the site the botnet is targeting, you are immune from compromise. Besides, my phone as the ability to do a remote wipe. It is effectively a bricked door stop until they can log into the phone.
- acdha 7y ago> Besides, my phone as the ability to do a remote wipe. It is effectively a bricked door stop until they can log into the phone. If they got your TOTP seeds you're in race seeing whether the person who {compromised,stole} your phone can disable your ability to do that first and since a remote wipe requires network access they can simply ignore it and reuse your credentials until you change them. What all of these have in common is that multi-factor authentication is based on having separate factors. If you store your passwords in the same place as your TOTP seeds, you have one factor rather than two. You might decide the risk is acceptable but that should be a carefully reasoned decision, which was … not apparent … from the comment I was replying to.