5 ms·
Even though TOTP is provably safer than SMS, it looks like the reason why they want SMS/push as a "primary" is so that they can suck in more phone numbers, sinc
by skynet-9000 5y ago
Even though TOTP is provably safer than SMS, it looks like the reason why they want SMS/push as a "primary" is so that they can suck in more phone numbers, since hardware keys have an additional cost that most people won't have. Phone numbers will let them do better ad targeting.
- amk10 5y agoThat is Silicon Valley's reason for 2FA in a nutshell. Phone numbers can only be obtained with identification in many countries. It is a privacy nightmare.
- minhazm 5y agoIt may be safer but it is way less user friendly. If you lose your phone with Google Authenticator (or any competitor), you will lose access to your accounts. You'll need to find your backup codes or go through the process to reset your accounts, which can be very cumbersome. Once someone has to go through this process they won't want to use 2FA anymore, I've seen it happen to many people. But if you break or lose your cell phone you can just get a new one, and you have access to your 2FA token again immediately. It's much easier for people to work with. Yes it's less secure technically, but that sacrifice is worth it for a lot of people.
- 1cvmask 5y agoThere are authenticators out there that can run on multiple devices and have multiple backup and restore options (with SIM Swap prevention) like saas pass.
- jasonjayr 5y agoYou can backup your 2FA TOTP qrcodes to physical cold storage, and you can keep backups. Most non-technical people understand the process of "keep this print out safe + secure" However you can lose control of your SMS phone number any number of ways that are beyond your control. It's frustrating that so many providers push SMS as the only 2FA, when there are so many problems with it, and TOTP is provably better, privacy preserving, and much easier to work with.
- foxrider 5y agoI don't know if you ever worked with tech-illiterate people, but there is no way that they would print out or write down a list of codes or keep something in cold storage. Hell, even if they know how to. It's too much effort for something like email, and yet they wouldn't realize the importance until it's too late. I personally had to deal with an aging woman who had her online banking password set to her name followed by the year she was born in, and was unwilling to use the USB security key that the bank started providing. There was more than a million in her account. She couldn't be fucked to secure that kind of money with a free-of-charge easy to use key. It was not a case of an elderly woman struggling to remember her password or not understanding how to use it. In her mind she deserved the access to her account just on the merit of it being "hers", and she saw the security as an unnecessary ritual that the bank used as a barrier between her and her money and nothing could convince her otherwise.
- jasonjayr 5y agoThat is a fair assessment in some cases, but I have also assisted tech-illiterate elderly folks with bank accounts in non-US banks. Keeping a printed list of codes (one time passwords) was in-scope for accessing the bank online, as well as other silly tricks as an on-screen keypad with rearranged numbers. I think there is too much emphasis on catering to the lowest denominator to the point of sacrificing privacy and autonomy , rather than raising awareness and education.
- tialaramex 5y ago> Even though TOTP is provably safer than SMS This seems like it would depend heavily on your threat model, especially keeping in mind that we're talking about second factors here. For example, one threat is that bad guys gain access to the authentication data of the Relying Party. For example, maybe they find the daily backups are in backups.tgz on the web server for convenient downloading. Or maybe you never changed the password on the MySQL server. This is of course one way bad guys might have everybody's passwords, the first factor... For TOTP the stored credentials include a "seed" value used to generate those six digit codes, and so by the relying party to confirm your code is correct. So for that credential access threat, the bad guys also have your TOTP codes and you're no better off with TOTP. Whereas for SMS the stored credentials just include a phone number to send the one use codes to, bad guys having that isn't great news necessarily, but it doesn't actually give them the codes. Even if the one-use codes are stored in the same place as permanent credentials (which they may not be) and thus accessible to bad guys, the bad guys can't necessarily arrange to see them before you use them, and in any case can't arrange for you not to wonder why you're getting all these one-use SMS codes suddenly. In contrast notably Security Keys don't end up with the Relying Party having any secrets at all, and so bad guys do not learn how to impersonate your users even if they somehow have access to the same means you use to authenticate those users.
- skynet-9000 5y agoRead more about HOTP and TOTP here: https://en.wikipedia.org/wiki/HMAC-based_One-Time_Password https://en.wikipedia.org/wiki/HMAC-based_One-Time_Password https://en.wikipedia.org/wiki/Time-based_One-Time_Password https://en.wikipedia.org/wiki/Time-based_One-Time_Password Implementations vary, but TOTP was developed on top of HOTP and presents a standardized method to expire OTP codes.