6 ms·
> but not to keep would-be-two factors in one vault. So where? Having them physically spread around my house? in my PO BOX? Each have been cracked before, or a
by yonixw 5y ago
> but not to keep would-be-two factors in one vault.
So where? Having them physically spread around my house? in my PO BOX? Each have been cracked before, or are lost all the time (even by a simple fire).
What can an average person do better than remember one strong password?
- Aachen 5y agoMy recommendation for keeping second factor key material would be on a supported smartphone and make backups of that device (I use termux and restic but anything goes here, so long as your desktop can't get at the data). The app isolation makes it a lot harder to get at data compared to when malware makes it onto your desktop. Most people also don't have full control of their phone from their desktop and vice versa, making it independent devices where the compromise of one doesn't compromise the other - even if you have photo sync and remote wipe, you usually can't simply get app data. I looked into different apps for a family member (I don't have a secure phone myself because I use the hardware longer than there are updates, so I don't use this personally) and the winner at the time, this was 2017 or so, was Keepass2Android. This is considering both usability and security, but mainly security - I'd probably not be able to teach my grandparents how to use this. An alternative specifically for codes that you should never need is indeed something like a bank vault, or using Shamir's Secret Sharing Scheme to split it up and give one part to a friend in addition to your own share.
- yonixw 5y agoBut then, once a phone get lost, how do you recover those second factor keys? Or do you mean to have encrypted backup but the "active usage" is on another device? If so I agree and do the same.
- RealStickman_ 5y agoI keep my recovery keys encrypted with a different password on my desktop. You could also export the 2FA codes from some apps.
- dividedbyzero 5y agoWhere do you keep that password? Rarely-used ones are easy to forget after all.
- yonixw 5y agoI love this comment and this thread. It is literally what happens in my head every time I need to sign up to a new site (having an existential security crisis). Good to see I'm not the only one!
- Aachen 5y agoYeah it's definitely a valid concern, though the considerations for different solutions are a bit too elaborate for me to type out on mobile atm. Some ideas - regularly testing backups also ensures you still have the key material - Shamir's Secret Sharing Scheme, in combination with putting it on paper or multiple devices or... - bank/company vault - hardware security token - give the master keys to the company's master (some tech director) and make it someone else's problem, if you want to be evil :)
- dividedbyzero 5y agoI thought we were discussing personal (i.e. non-work) security? At least that's what TFA appears to be about. Besides, Shamir's Secret Sharing can be outright dangerous even for companies, I really wouldn't recommend that to any private person.
- DennisP 5y agoYes, stored at your house is fine for most people. There's a big security jump between "needing your password" and "needing your password plus having to steal something from your house." There's also a big jump between "stealing something from your house" and "stealing something from your house plus figuring out your password."
- dividedbyzero 5y agoThat makes it impossible to get into your email if you use your phone on vacation, though.
- DennisP 5y agoA decent tradeoff for that case is to use your phone as the "something you have," with backup codes stored somewhere reasonably secure.
- TacticalCoder 5y ago> What can an average person do better than remember one strong password? Use as 2FA a physical U2F device which is itself protect by an HSM and a PIN and erases itself after 3 failed attempts (which, granted, comes with its own problem if you lose it / forget your PIN / have it stolen). It's kinda a big fraud that Yubikeys have been "sold" as the be-all / end-all of 2FA when they are, themselves, not protected by a PIN (for costs reasons and costs reasons alone: there's no way on earth a pinless Yubikey is better than a U2F device protected by a HSM+PIN, but that costs way more to build). And here you'll get the ultimate argument: "you have to understand the threat model" / "this is not the threat model a Yubikey defends you again" etc. Oh really? Then why then do we have now Yubikey protected by fingerprints? The threat model changed or what?
- nopcode 5y agoThreat is not the only factor. The control (entering a PIN) has a cost (it's tiresome) and only a certain risk reduction value (if they can steal my key, they can probably steal my PIN).