4 ms·
For comparison, here's GH Policy: https://docs.github.com/en/github/authenticating-to-github/recovering-your-account-if-you-lose-your-2fa-credentials https://d
by EdJiang 6y ago
For comparison, here's GH Policy:
https://docs.github.com/en/github/authenticating-to-github/recovering-your-account-if-you-lose-your-2fa-credentials https://docs.github.com/en/github/authenticating-to-github/r...
> Warning: For security reasons, GitHub Support may not be able to restore access to accounts with two-factor authentication enabled if you lose your two-factor authentication credentials or lose access to your account recovery methods.
I think it's hard to securely restore an account that is using MFA without being vulnerable to social engineering, SMS takeover, etc. If it's on a corporate account it's easy -- just talk to IT. But for semi-anonymous free accounts? I'm not sure what the expectation here is. What are some good strategies you've seen other providers take?
- toomuchtodo 6y ago> What are some good strategies you've seen other providers take? Fallback to SMS auth if you've lost your MFA and recovery codes. It's not good per se, but the users who need it will love you and the users who get SIM jacked/swap attacked will hate you. You're not going to please everyone. I've been trying to figure out a good way to handle this, but at least in the US, there isn't a good government provided identity provider you could rely on to true up identity issues when auth factors are lost (login.gov just ain't there yet, but it might get there as it's what US DHS uses to auth you for Global Entry, and what you're looking for is essentially a programatic/digital notary to attest to you that the person is whom they say they are). IAM is hard.
- EdJiang 6y agoIf I'm going to allow my account to be recovered via SIM, why not just use "poor man's MFA" by just authing via SIM? Security is as weak as its weakest link. I looked at GitLab's recovery options, and you have the option of recovering your MFA if you have access to any SSH key used to publish to GitLab. That seems like a reasonable backup for now.
- toomuchtodo 6y agoI agree with your points. Really depends on the service, what auth factors you have available to you, what your risk appetite is, etc.
- cjbprime 6y agoMake the reset take three days, during which time emails and SMS are sent to the addresses on file alerting them that they may be being attacked and should cancel the recovery if so.
- tialaramex 6y agoThough note this will still work for a targeted attack. You wait until your target will be out of the loop and then begin your attack run. But it would definitely help.
- cjbprime 6y agoI'm not sure there are many attractive targets left who are uncontactable by email and SMS for three continuous days.
- mcherm 6y agoDoes no one else take real vacations these days?
- belltaco 6y agoEven on vacations people do connect atleast once a day. Even if to just check on possible family emergencies.
- usr1106 6y agoThat depends on the country. In Europe 4 weeks of summer holidays are common, in some countries even the law. An increasing number of people logs in to work accounts during holidays, but generally it's considered poor work-life balance. I don't take pressure either way, I might or might not log in once or twice during my 3 weeks (twice a year) if I am curious about something. My private mail I scan occasionally, but it has happened many times that I haven't done so for 2 weeks. There is enough stress in my life, I don't need to be connected every day of the year. There is a phone for personal emergencies. And if someone is afraid someone is dying before they get there they probably can never move out of their parents' home.
- the_svd_doctor 6y agoWhat about using time ? Let support reset MFA, but with a mandatory x days (3? 5? 7?) “cooling period”. And spam the user email with notifications during that time period.
- dx034 6y agoThat's probably why their corporate resets take at least 3 business days. For companies, if you send warning emails for 3 business days to all accounts, someone will see it and social engineering is nearly impossible. For individual accounts that's different though. Even with a three day waiting period it's not guaranteed that a user will see it. It also is a big cost on Gitlab which isn't justified for free users.
- jrochkind1 6y agoGithub does (for better or worse) support SMS for MFA though.