4 ms·
Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of
by balazer 5y ago
Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not.
To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup codes would stop working, as would any third-party apps that need access to data in your Google account.
The YubiKey, by the way, is a great hardware TOTP key, in addition to being a FIDO U2F key. TOTP has an advantage over U2F in that you can keep backup copies of the TOTP secrets. Of course TOTP is less secure because it is phishable, but U2F is a real pain because you can't make backup copies of the key.
- d110af5ccf 5y ago> U2F is a real pain because you can't make backup copies of the key Dogma: If it isn't backed up then it doesn't exist.
- dandanua 5y agoImpossibility of U2F key cloning is a security feature. As a backup you use another keys, registered in the same service.
- balazer 5y agoSure, not being clonable is a security feature, but it's a huge pain to keep multiple keys registered on all of your services. For real backup resiliency, you should have at least 3 keys, one of which you keep off-site. Presumably you keep one at home and one with you. Want to sign up for a new service? I hope you're at home where you can access two of your keys to register them. Then sometime later you need to go to your off-site location to swap that key, bring it home, and get it registered also. Do that periodically so all of your services are on all 3 keys. Unclonable hardware keys work well enough when it's for a corporate service. Lose the key? Just visit IT and have them give you a new one or overnight it. But unclonable hardware keys are a huge pain when used personally with multiple services. TOTP secrets, while less secure, are much easier to manage. You can write them down, store them on a USB stick, or store them in an online account. You can send them in a message or even read them over the phone. Ultimately the average user is more concerned about losing access to their account than being attacked by a nation state.
- riffraff 5y ago> It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not Don't you have a second authentication factor to login on your phone? Fingerprint, pin, faceId. I don't see how this is worse than a yubikey.
- buzer 5y agoHardware key is offline device, phones are online devices. While phones might have arguably quite good security, their attack surface is many times bigger than offline device that you keep with you. There is almost no way for remote attacker to gain access to offline device (though local attacker will likely have easier time getting that than phone). With phone it comes more down to cost/luck (pay/develop 0days until you have full chain).
- graton 5y ago> but U2F is a real pain because you can't make backup copies of the key. The backup is to have multiple U2F keys. I have over 10 U2F keys. Most (but not all) providers allow you to register multiple U2F keys. Amazon AWS for some foolish reason (in my opinion) is one of those outliers which only allows one U2F keys to be registered. I've read people's reasoning on why that is and none of it makes sense to me.
- xyzzy_plugh 5y ago> I have over 10 U2F keys. Can you walk me through your workflow with these? Are some stored offsite? Do you have to gather all your keys together when you are signing up for a new service with U2F support?
- graton 5y agoI do have over 10 U2F keys. Do I make sure every single one is synced with every service? No. I have 4 main ones that I try to keep synced with every service. Though I usually try to sync up a few more if I have them handy. For me those four are: Laptop (Yubikey 5C Nano) Desktop #1 (Youbikey 5 Nano) Desktop #2 (Yubikey 4 Nano) Keychain (Yubikey 5 NFC) I also have one in my work-laptop but it is only registered for work related sites. I also register some of the previously mentioned ones for my work related sites as a backup.
- balazer 5y agoAnd what a pain it is to keep multiple keys registered on all of your services. At least one of those keys should be stored off-site, which means making trips to the off-site location to swap that key, bring it home, and get it registered also. Do that again when you want to register a new service.
- imdoor 5y agoIn principle, there is a way for you to have U2F backup keys. Here's a great write-up https://dmitryfrank.com/articles/backup_u2f_token https://dmitryfrank.com/articles/backup_u2f_token The basic idea is to have two U2F devices with with the same device_secret but one of the devices (the backup) is pre-programmed to add a large offset to the so called counter value. Upon login the service must check the counter value and ensure that the received value is greater than the one it's seen previously. If you happen to lose the first key, you can use the second key to log into all of the affected online services and upon doing so, the service would accept the new larger counter value and thereby invalidate the lost key.