3 ms·
> I guess the other challenge is if you have to do a (full) app reinstall Yeah, that's true, if the user does a full app removal and re-install then they woul
by EB66 5y ago
> I guess the other challenge is if you have to do a (full) app reinstall
Yeah, that's true, if the user does a full app removal and re-install then they would need to re-enroll in MFA. But for app updates they'd be ok.
> The only downsides I can think of is that if the app local data is exposed, you possibly lose your cached creds and the TOTP seed..
That's a good point too, but what you're describing would probably require someone to fully compromise (root) a phone. If that happened, you'd be SOL on many fronts. At my company we try to safeguard against rooted phones by 1. only holding user credentials in memory and 2. pairing our app with a public key that encrypts the password as soon as it's entered (our servers then decrypt it with the private key upon receipt).
- nicoburns 5y ago> Yeah, that's true, if the user does a full app removal and re-install then they would need to re-enroll in MFA. But for app updates they'd be ok. How would they re-enroll without their MFA token? Surely the whole point is not to let them login without it?
- EB66 5y agoIt'd be the same process that you have to follow if you lost your phone and, along with it, all the TOTP seeds that were stored in your Google Authenticator. You'd have to go through whatever process the company requires to confirm your identity through alternative means and allow a re-enrollment in MFA.