7 ms·
> You can put an auth cookie in a browser and achieve 2FA for 99% of use cases without bothering anyone. Confusing, obviously incorrect. > No reason 2FA can't
by staticassertion 4y ago
> You can put an auth cookie in a browser and achieve 2FA for 99% of use cases without bothering anyone.
Confusing, obviously incorrect.
> No reason 2FA can't be just two passwords.
Maybe somewhat less obviously incorrect, but still incorrect. Passwords can be phished easily, are managed by users, etc.
- jacobsenscott 4y agoIf you can phish the pw you can phish the totp. People type it in right after they type in the pw.
- TimWolla 4y agoYes, but the TOTP is only usable once and cannot be reused across unrelated sites ("password stuffing"). And with WebAuthn / U2F the second factor is completely unphishable.
- Conan_Kudo 4y agoYou cannot guarantee "completely unphishable", only that you cannot yet conceive of a way to do it. It's very dangerous to assume that something is completely secure.
- TimWolla 4y agoWebAuthn binds the credential to the domain. Under the assumption that your web browser and security key is operating according to spec this is unphishable. If your web browser or key contains a bug, or the domain is breached then all bets are off anyway.
- staticassertion 4y agoYes, but you can't guess a TOTP. You can guess a password. But I hope that Github will make their FIDO2 support better.
- Wowfunhappy 4y agoOnly if the user chooses a guessable password. If you really must protect the user from themself (which I don't think you should, except in much more extreme circumstances), you can generate the password for them.
- ipaddr 4y agoThat doesn't make his point invalid. All this does is share your personal belief that passwords can be phished easily. You know what is less secure than a password? A phone. A phone is a sim swap away from being hacked at anytime.
- staticassertion 4y agoI am against SMS 2FA.
- IYasha 4y agoYeah, a phone is an endless source of possibilities: every auth SMS is (not "can be", not "may be", but "by design") intercepted and logged. Every app can be breached remotely. Every interface, especially wireless, is a potential point of entry. Abundance of non-user-trusted components (like most processors, controllers and SIM). Possibilities of covert data exfiltration. Lots of sensors and ways of real human identification. Proprietary platforms and OSes that don't receive patches. A phone is the WORST thing to entrust your auth keys to.