6 ms·
SMS is not reliable for 2FA, it's trivial for a determined party to sniff SMS messages. TOTP is the best way for typical users to do 2FA, as most people wont ha
by timcosta 5y ago
SMS is not reliable for 2FA, it's trivial for a determined party to sniff SMS messages. TOTP is the best way for typical users to do 2FA, as most people wont have a Yubikey or anything like that. Google Prompt is the equivalent of iCloud's cross-device prompt where you must allow the action from another device that's already logged in to the account.
The Google Authenticator app isn't the only app that can be used to generate TOTP tokens, even though many sites directly refer to it. Anywhere that you are given a QR code to scan you can use any TOTP app you'd like. I use Authy personally because it allows me to back up my TOTP tokens behind a master password and access to my phone number, so in the event my phone is lost or replaced I'm able to restore 2FA access by going through the process to configure Authy again and re-enter my master password from another password manager.
- sneak 5y agoSmartphone secure enclave U2F is the best for users. TOTP is still easily phished.
- necovek 5y agoI think phishing is an entirely different matter. Any access is easily "phished" with pliable people (which is not necessarily a set of people, but also a question of timing and circumstances: everyone is sometimes more or less pliable): "please log in with your U2F device, download that document and upload it to this URL https://your-company-confidential.s3.amazonaws.myurl.com/ https://your-company-confidential.s3.amazonaws.myurl.com/, before we can reinstate your access to company systems".
- UncleMeat 5y agoIt isn’t a different matter. It is the core matter. Phishing and stuffing completely dominate the actual attack space. SIM swapping and other theft of SMS messages is tiny in comparison. The advantage of U2F is that it isn’t phishable. You can only sign the message for the pre enrolled URL. Yes, you can still fall for more elaborate instructions but you cannot simply give the attacker your credentials through a normal looking flow.
- necovek 5y agoNot sure what's "normal looking" in the flow where you are supposed to dictate/type-out a TOTP code to someone while not being allowed to use it to attempt a log in (and that they have <60s to make use of). "Be quick and type me out your TOTP code from your phone before it changes, darn, that one didn't work, let's try again". I also disagree it's that far fetched to get people who'd do that to also do whatever else you want them to. And while SMS swapping is miniscule in comparison, the big difference there is that there is no signal at all that you are under attack. With phishing, there is no way you are not feeling something is at least a bit off, so you know to check soon after, even if you've been compromised.
- UncleMeat 5y agoThe phishing flow is precisely the same as the normal auth. You click a link. It takes you to evil.com that looks like your bank page. You type in your password. The system takes your password and starts an auth flow with the actual bank. You are shown a TOTP page. You type in your code. The system takes your code and completes the auth with your bank. This is 100% automated and the only observable different is the URL. After this happens it takes you to a “something went wrong” page and has a link back to your real bank website. With U2F this impossible because you cannot sign a message for bank.com when visiting evil.com.
- afandian 5y agoI use 1Password for Google and it works fine. Follow the 'Google Authenticator' setup and don't believe the wizard -- it's not exlusive to Google Authenticator.
- unqueued 5y agoAs it becomes easier to emulate hardware tokens[1], Google may start limiting which ones it accepts. I believe they can use attestation keys to do that. This is just a softer layer of security to slow down less sophisticated mass signup attempts. Google may very well eventually phase out TOTP, under the justification that it is not as secure, but I would be shocked if they ever retire the highly insecure SMS verification.
- stavros 5y ago> As it becomes easier to emulate hardware tokens[1], Google may start limiting which ones it accepts. Why? I hope they don't, as I'm relying on my password manager to emulate a hardware token so I can finally log in to websites without needing a username/password. At its core, FIDO2 is an authentication API, so the site can ask your browser to authenticate you (in whatever way the browser wants). If that's "talk to the password manager to authenticate the user using some fancy cryptography", why does the authenticating site care? I'm looking forward to the day when my password manager only has one credential in it, my soft-FIDO2 private key.
- necovek 5y agoIf your password manager has control of both your password and your "2nd" factor auth, it defeats the purpose of it being a 2nd factor. You are still protected from your password hash being stolen from the target website, decrypted and then used for log-in, but if password hashes were accessed, potentially a bunch of other stuff that you'd care about is too, so that's a somewhat moot point. But someone stealing your laptop and getting access to your password manager gets access to your 2FA too. Making it not a "second" anything: it's akin to using two passwords for log in to a single site and keeping them in the same place. Physical separation of the two authentication factors, thus, matters. That also means that you should not have your password manager on the phone, or at least only have a separate one: ideally, password managers would integrate between desktops and mobile devices to pass short-lived access to passwords for Oauth/OpenID Connect auth instead. Yeah, bridging convenience and security is a long standing nightmare of a problem to solve. :)
- rawbot 5y agoKeepassXC has pretty good support for 2FA. I use it for all my TOTP needs. On mobile, I also use Aegis, which is free open source and can backup your TOTPs.
- Geezus-42 5y agoBitwarden does TOTP as well if you give them $10/yr. It's handy as with most logins it will auto-fill UN and PW then put the code in your clipboard for you to just paste and hit enter.
- Pooge 5y agoThe developers don't recommend storing your TOTP secrets in the same database as your passwords [1]. I used to do this, but now I'm using andOTP [2]. [1]: https://keepassxc.org/docs/#faq-security-totp https://keepassxc.org/docs/#faq-security-totp [2]: https://f-droid.org/en/packages/org.shadowice.flocke.andotp/ https://f-droid.org/en/packages/org.shadowice.flocke.andotp/
- Fatnino 5y agoCoinbase refuses to work with Authy. I first heard about Authy when it was recommended to me by coinbase but sometime last year coinbase forced me to change to Google authenticator.