3 ms·
Isn't manual TOTP MFA (using codes generated by Google Authenticator or similar) significantly more secure than those MFA prompts? I don't understand the push f
by rmsaksida 5y ago
Isn't manual TOTP MFA (using codes generated by Google Authenticator or similar) significantly more secure than those MFA prompts? I don't understand the push for MFA prompts when the previous technology worked just fine and was probably more secure. What's the benefit to MFA prompts other than slightly better UX?
- 6yyyyyy 5y agoIt forces you to install the vendor's proprietary authentication app on your mobile device.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- woeh 5y agoIn case of one time passwords you can ignore the proprietary app and use your favourite authenticator to generate an otp password. If the site or app poses no choice, just say that you want to use their "Proprietary Authenticator" and you just continue with your own password manager. It works for me with 1password. As a sanity check too see if it works; you always have to use a first OTP to activate the multifactor authentication.
- 6yyyyyy 5y agoThat's my point: OTP lets you use your own app. Notification-based OTP requires a proprietary app.
- Melatonic 5y agoI dont think either are more or less secure than the other - they both verify you have the physical device on you (which theoretically you need to unlock) and they are time-based. I would say the TOTP MFA is easier because you do not have to deal with re inputting the code (which expires) but also then you need another app installed.
- rmsaksida 5y agoI meant the MFA variety where you have to reinput the code versus the one where you need to confirm a login via a mobile prompt. The former seems safer, because it requires a lot more activity from the user.
- Melatonic 5y agoYou mean where it triggers the MFA prompt on the phone and then it asks you to match which one is correct? And it shows three sets of numbers? I agree those are great
- Fishkins 5y agoI agree TOTP is much better than MFA prompts or calls/SMS. TOTP does protect against the first two attack methods the article lists. However, it's not quite as good as a hardware key, because it's still vulnerable to the third method the article lists: "Calling the target, pretending to be part of the company, and telling the target they need to send an MFA request as part of a company process." I generally consider TOTP "good enough" for a lot of applications, whereas prompts and SMS are not "good enough."
- flatiron 5y agoWe take training constantly to not click our Duo notifications for people on the phone, etc. Few months ago I couldn’t log into the vpn. Posted to the slack channel and got a slack asking my phone number. Ok so I know this guy is really my it and I’m asking for help. Then he sends me a freaking Duo notification! I say “I’m not supposed to click this” and he goes “well yeah but I’m IT” It’s all very stupid.