9 ms·
HTML attributes to improve your users' two factor authentication experience
- stockkid 7y ago> In a sign up form, make sure to use the "new-password" value as it triggers password suggestions in some browsers. Nice. I didn't know about that.
- cyberferret 7y agoThis is a really cool and informative article. I had head of the 'pattern' attribute before, but I hadn't come across 'inputmode' before. This will solve a ton of headaches for my future development work.
- skunkworker 7y agoI wish more sites would follow these protocols. When you have a numeric 2FA with a regular keyboard it feels less polished.
- tobyhinloopen 7y agoDidn’t we just learn you shouldn’t use SMS 2FA?
- reaperducer 7y agoA lot of people say that. But SMS 2FA is better than nothing.
- JshWright 7y agoIs it though? Implementing SMS 2FA often means a site will never bother implementing anything better.
- jimbobimbo 7y agoNot implementing SMS 2FA doesn't mean a site would implement anything either.
- JshWright 7y agoNo, but it's increasingly becoming the expectation that 2FA should be available. Going from no 2FA to some 2FA is a more likely transition than going from bad 2FA to good 2FA (since bad 2FA still checks the 2FA box).
- hombre_fatal 7y agoNope, not if it introduces common customer support backdoors.
- zulln 7y agoIf it is enough with access to the phone number, no password needed, then it is no longer 2FA.
- Thorrez 7y agoSure, but 17 websites do this. For those websites you introduce significant weaknesses if you enable SMS 2FA. https://www.issms2fasecure.com/ https://www.issms2fasecure.com/
- robbya 7y agoSure, everything that has a backdoor is bad. But what does that have to do with SMS 2FA? Surely SMS 2FA (without a backdoor) is better than nothing. Sites should still offer something better than SMS for 2FA as it has widely documented issues. But as an end user presented with SMS 2FA or no 2FA; SMS 2FA is the safer option. Is there a reason to assume an arbitrary SMS 2FA implementation would have a back door? That would be news to me.
- colechristensen 7y agoThe back door is either automatic or human account recovery tools. These tools generally put way too much trust into the phone number and allow someone who has compromised that number to take control of anything it has ever touched. Phone numbers are very public and easy to steal in ways which are difficult to defend against. Imagine someone in a domestic abuse situation having their phone taken, with sms 2fa, how hard would it be for that person to recover and retain access to their accounts and services? With SMS 2FA someone who knows you personally and has control of your phone number is nearly impossible to escape. All the adversary has to do is say "oh this was linked to my old number" and account support is super likely to just give access away. You would have to be somewhat of an opsec expert to escape that hell, and even if you know everything it becomes impossible to defend yourself against the owners of your accounts giving access away. The only real defense is to never associate your phone number with personal accounts which even then is often not possible.
- colechristensen 7y agoNot really, it becomes very difficult to remove a phone number from an account and anyone who gains access can use various account recovery mechanisms which rely heavily on access to that number for authentication.
- Thorrez 7y agoSMS 2FA introduces problems that no 2FA doesn't have. Sites can start spamming my number with notifications, or using my number for ad targeting.
- philnash 7y agoSMS 2FA is still stronger than no 2FA.
- 9HZZRfNlpR 7y agoTaking over accounts is mainly American thing, the rest of the world is using same method to identify yourself to a telecom company - by providing your ID card or passport.
- sneak 7y agoTwilio offers a service to send SMSes via an API. Of course they're going to tell you to use this.
- sansnomme 7y agoFor low-stakes auth or simply duplicate user prevention SMS is sufficient. E.g. dating apps, sharing economy services, e-commerce sites.
- duxup 7y agoIf I'm doing verification I usually need more than"pattern" will allow, usually providing more feedback or something more complex.
- noodlesUK 7y agoWhat this write up on 2fa is missing is that rather than using proprietary solutions like authy, we should be moving towards what we’ve now standardised as webauthn. If we had platform authenticators or we had a google/apple first party implementation of something like Krypton, we would be in such a better place security wise.
- notlukesky 7y agoSAASPASS has a much better 2FA user experience on the mobile phone than SMS including URL callback to the 2FA app and app to app with SDK. For desktop environments configurable MFA methods include scanning encrypted barcodes and push login. More on the developer environment is here: developer.saaspass.com I work for an IAM consultancy/reseller and work on SAASPASS implementations.
- philnash 7y agoHello! I’m the author of this article. Thanks for posting! Here’s to the power of HTML attributes and better sign in experiences for everyone.
- sneak 7y agoI know you're probably paid to do so, but please stop recommending that site operators use SMS for a second factor. https://www.issms2fasecure.com/ https://www.issms2fasecure.com/
- philnash 7y agoI’m actually paid to say that too ;) . In fact, SIM swapping isn’t the only weakness of SMS, take a look into the SS7 network and how that allows for a rogue operator to redirect SMS messages too. At Twilio, we have APIs for two factor authentication and we recommend implementing via push notification to the Authy app with “approve” and “deny” buttons. This is more secure and a better experience than SMS. The API also allows for regular app based 2FA, with a TOTP code, which is more secure than SMS. But it also allows you to fallback to SMS, which is still more secure than no 2FA. You do have to consider the threat model for your own application when considering these sort of security measures. If the value of an account takeover is high then a targeted attack can, and will, break SMS 2FA. Which is why the Twilio 2FA API allows you to turn off SMS 2FA if you choose. Ultimately I’d prefer SMS over nothing when it comes to 2FA, but I also encourage developers to use more secure options that can also have a better experience.
- jxcl 7y agoIf you allow fallback to SMS instead of TOTP, your solution may be more secure than no 2FA, but it’s no more secure than SMS either.
- philnash 7y agoBut as I said towards the end of the previous comment, if you deem the threat to your users great enough that targeted SMS attacks are a problem, you can turn off that fallback.
- ayberk 7y agoThese are all super nice and I really wish more developers made use of these, but my main complain is not having username and password fields on the same page :/
- ljoshua 7y agoOy, me too, and though I love Twilio they are an offender here! What is the point of this pattern? Something to do with SSO validation or something?
- philnash 7y agoIt is to do with SSO. I will pass off to my Twilio colleague Kelley to answer this with a post she wrote last year: https://www.twilio.com/blog/why-username-and-password-on-two-different-pages https://www.twilio.com/blog/why-username-and-password-on-two... The nice thing about using autocomplete with username and current-password is that it can help your password manager auto fill these fields across pages if they are implemented like this.
- pixelcort 7y agoIn the article they mention that: > You definitely want to consider using these attributes if you are building a login form with the username and password on different pages.
- jffhn 7y ago>my main complain is not having username and password fields on the same page :/ This! Our new Linux login has username and password entry fields in separate (and successive) windows, and they look quite similar. Since I enter my password much more often (to unlock) than my username, I built up a reflex of entering the password, and the rare times I have to enter my username I often type in the password instead, visible to anyone looking at the screen. I see this new design as a security issue.
- crazygringo 7y agoThat happens whenever certain usernames trigger different authentication pathways. There's just nothing you can do about it if some users have passwords but other users have different authentication mechanisms.
- casca 7y agoWhile Twilio does a lot right, they still only offer SMS and their own proprietary Authy solution for 2FA for their website. No TOTP (and still no plan to offer the industry standard) means that this has a whiff of hypocrisy.
- philnash 7y agoThe Twilio 2FA API actually allows you to generate secrets and QR codes for generic authenticator applications now. Check out the documentation here: https://www.twilio.com/docs/authy/api/one-time-passwords#other-authenticator-apps https://www.twilio.com/docs/authy/api/one-time-passwords#oth...
- booi 7y agoThe argument then goes back to, why pick up an external dependency and cost for open standard authenticator when you could just include a library and generate it yourself.
- philnash 7y agoThis allows a developer to have all the benefit of the Authy API, including enhancing the experience using push authentication or dropping back to SMS if needed, as well as allowing users to use an authenticator app of their choice. It's the best of all worlds in this case. But if building and maintaining app based TOTP using a library is good enough for you, then go for it. I'm certainly not going to make you use Twilio's APIs, but plenty of businesses do see the benefit.
- casca 7y agoPerhaps, but you still cannot use this to authenticate to Twilio itself. Twilio requires either using unsafe SMS or some version of EEE[1] in their console. [1] https://en.wikipedia.org/wiki/Embrace%2C_extend%2C_and_extinguish https://en.wikipedia.org/wiki/Embrace%2C_extend%2C_and_extin...
- inopinatus 7y agoTwilio seems to have some great engineers and I'm often impressed by the quality of their technical writing, but you'd never know it from their console horrowshow UX. See also: AWS.
- motohagiography 7y agoDealing with 2FA ux right now. There is a massive gap between threat intel people, product owners, and end users. From an identity assurance perspective, SMS is the best available. From an authentication perspective, it's increasingly dodgy. Reality is telcos have user enrollment almost on par with bank KYC, where everything else has great authN but with user asserted identity. Critics of SMS are technically correct, but 9/10x I don't think they have had to solve identity in an open or federated environment.
- techsupporter 7y ago> Reality is telcos have user enrollment almost on par with bank KYC, where everything else has great authN but with user asserted identity. Are you sure? I don't mean that to sound hostile, genuinely asking. Because, at least in the States and Canada, I can get all of the +1 numbers I want on real SIMs for around a dollar apiece--or less if I work at it instead of just trotting down to Walgreens--and attach any name I want during the sign-up flow. In point of fact, I have a vanity 212 number I've owned for years. It is currently parked on a SIM registered to the name George Crabtree (that name even shows up on CID/CNAM). Best part? The MVNO that provisioned the SIM is using a white-label service from one of the big four. Even the ICCID prefix is from the actual carrier and not the MVNO. That means that all of the automated API checks show it as a "normal" phone number provisioned on a "regular" SIM...and owned by Constable Crabtree.
- latchkey 7y ago^^^ this. SIMs are super easy to get.
- motohagiography 7y agoIt's the credit check part of the KYC for telcos that makes them like banks. The pay as you go SIMs, absolutely arbitrary, but there are back end id verification services offered by telcos that have been in design a very long time. Not sure their current status, but they have the KYC data.
- hk__2 7y ago> For older browsers there is another trick to trigger the numeric keyboard and include a bit of extra validation for free. A simpler one that the pattern attribute, but more hacky-er, is using input type="tel", which I’ve also seen used for credit card number inputs.
- QuinnyPig 7y agoI’d give a lot to be able to forcibly delete Authy-specific 2FA accounts from the app. Today I’m stuck with old dead account tokens.
- akersten 7y agoIs type supposed to be "text" instead of "number" in the inputmode snippet? Wouldn't it still strip leading zeros the way it is now (with type set to "number")?
- gsich 7y agoI want a one-step-login. Not two step (first username, then password) and certainly not three step (username, password, 2fa, all in seperate pages). This braindead concept needs to die. If no 2fa is active on the account, just accept anything (including empty strings) in that field.
- aurbano 7y agoI get the point, but I’d be afraid that non-technical users would be confused to the point of not even trying... You could obviously add some info message below or above, but people tend to be terrible at reading. Maybe if the 2FA input field is below the login button, after some text explaining it’s function..? I’d love to see some UX test results on this with a bunch of real users of varying tech skill levels.
- gsich 7y agoIf people want to use the service, they will figure it out. You can't create services with the dumbest user in mind. Sometimes a little nudging helps. Besides you can always dynamically hide (or show) the 2fa option if the email or username doesn't have 2fa enabled.
- homero 7y agoTwitter has the worst one where they don't trim whitespace so pastes can fail. How hard is adding trim()
- amatix 7y agoAuthy’s iOS app still doesn’t have an actions/app helper, so every time you need to switch to the home screen, find & launch it, search for the site, close the keyboard (the copy button is obscured by it), hit copy, then switch back to Safari/wherever and paste. So much friction. Kind of implies the engineers who build it never ever use it?
- mnoorenberghe 7y ago> You can use more than one autocomplete value at a time too. If your username is also an email address you can give the browser and any associated password managers a hint with ‘autocomplete="username email"’. This whole paragraph is incorrect. While the attribute value does allow multiple tokens there is a very specific syntax defined in the HTML standard and it doesn’t support multiple field names (types) i.e. autocomplete="username email" is invalid. If you access ‘input.autocomplete’ on an input with that attribute value “” will be returned indicating this.
- philnash 7y agoYou are absolutely right and I don't know where I read that (or why I believed it, given I had the spec open at the time too). I've updated the post, thank you for your help!
- daveFNbuck 7y agoI didn't know about the one-time-code autocomplete. How do they prevent this from being used to steal one-time passwords sent by other sites?
- 0xff00ffee 7y agoThe article is about how to improve a UI/UX using lesser known HTML properties. The article does a great job: these tags are helpful and not everyone reads the spec for fun. The article is NOT about the merits of 2FA across SMS: that discussion is happening in about 10,000 other threads on Hacker News. Please go talk about it there.