4 ms·
I like that they're setting such a high bar, despite the potential difficulties of achieving that broadly. One question I have: I've yet to encounter an entity
by treatmentteam 5y ago
I like that they're setting such a high bar, despite the potential difficulties of achieving that broadly. One question I have: I've yet to encounter an entity (including login.gov) that allows FIDO2/WebAuthn without also requiring a HOTP/TOTP or other 2nd-factor. So what's the point of allowing the security key option if an attacker has the option to attack the authentication code (which is often sent via SMS)?
- toomuchtodo 5y agoLogin.gov has to serve a diverse customer base made up of every American resident/citizen, therefore its threat model and approach to securing identity is different than that of someone, say, storing cryptocurrency (where the risk of loss and lack of recourse is much higher than someone seeing your Social Security benefit statement). Consider an older citizen losing their hardware token, and unable to login to their Social Security or IRS account. The current model is to be expected until the government builds out its identity functions. Security is about trade offs and compromise. (no affiliation with login.gov or related federal agencies, just a fan of their work)
- MadVikingGod 5y agoI'm not sure about the public facing entities, but the Federal Government already has a VERY widespread PKI system in place that I'm sure they will leverage. Most federal departments already have a process for distributing a smartcard with a Federally signed key to all their employees and some contractors. I'm hoping that they can extend that to non-employees.
- toomuchtodo 5y agoIf DHS would issue Global Entry smart cards that were part of the CAC platform [1], that would be a convenient shim until national ID cards could be deployed. I picked up a TWIC card [2] thinking I'd be able to use it with Login.gov, but no such luck. [1] https://www.cac.mil/common-access-card/ https://www.cac.mil/common-access-card/ [2] https://www.tsa.gov/for-industry/twic https://www.tsa.gov/for-industry/twic
- acdha 5y agologin.gov does allow you to have FIDO2 setup without a phone number — my account currently only has hardware tokens — but I think you want to look backwards from the challenges of supporting a service like this. If you're serving the general public, people reliably lose their tokens and you can't require them in general since multiple $20 tokens is a complete non-starter so there's a lot of appeal to things like SMS which don't require additional purchases. The other question I'd ask is how bad SMS really is: it's definitely not great from a security perspective but for the average person it seems unlikely that they're worse off from having it. Maybe we can start phasing that out now that common clients have integrated WebAuthn support (e.g. Apple's FaceID/TouchID for the web) but if you have to support the general public you probably have a different threat model than a more targeted audience.
- brightball 5y agoI haven’t found a bank that will allow FIDO2 yet.
- tialaramex 5y ago"or other 2nd-factor" includes another WebAuthn factor. This is one of the things that bothered people about login.gov before, they're like "But I already have a Security Key, what other factor can I use?". Another security key is fine, they're each independent factors, it just wants to make you won't lose your only route in to the site. My login.gov has my two Security Keys plus my phone (a Pixel 2, via WebAuthn) as possible second factors. You can indeed choose TOTP, or use a Government ID (a few million people have Federal jobs with IDs) and if you must yes you can use SMS So if you need better security, just don't choose the weaker options. Suddenly that goes from "automated attack launched by a school kid on the far side of an ocean" to "Government black bag job", and it's enough that most people should sleep soundly. Also, the other benefit of Security Keys as an option is that we can teach users that their Security Key is safe, because it can't be phished. That exercise where you try to train users to check they're on the right domain and realistically you know adversaries will confuse or terrify them into skipping that step? No need with Security Keys, that's the Web Browser's job and the browser isn't confused or terrified, it's just calling memcmp() as it does many times every page load.