4 ms·
I've been working on something similar to what you described[^1], using Shamir secret sharing to split the TOTP secret. Once enough key holders get together, a
by gioazzi 4y ago
I've been working on something similar to what you described[^1], using Shamir secret sharing to split the TOTP secret. Once enough key holders get together, a server generates some TOTP tokens, but only for a limited period of time.
I wanted to use it in an enterprise environment to limit the access to AWS root users in a break-glass scenario. Now I no longer have such need and haven't developed it further, but the core features are there. As usual though with this kind of tools, any security problem becomes a key management problem and it'd need a bit more work to use it in the real world.
[^1]: https://github.com/borgoat/farmfa https://github.com/borgoat/farmfa
- hn_throwaway_99 4y agoThanks, this actually helped give me a good idea about how I would like to do this now: 1. Generate the password for the owner account, store that in "standard" secrets storage where admins can access it. 2. Also require TOTP MFA for the owner account. Take the seed for the TOTP, and split that into N shares (where N is equal to the number of admins you want to share it out to) requiring K threshold (where K is the minimum number of admins that must come together), and give that out to your admins.
- gioazzi 4y agoYes exactly, that's the idea with that tool, this would make the process compatible with most services (I'd hope, that all services that require this level of attention also offer TOTP). I believe the sensible next step would then be to implement a mobile authenticator app for this protocol, that can scan QR codes, perform the initial "split", send out the shares, and then orchestrate the generation with other players. The initial step is the weak link: the user could just store that TOTP secret and everything else becomes pointless. It'd be great to have the service itself (e.g. AWS) generate those shares on their end and send them out individually. But then again, a malicious actor with that kind of access to begin with would have a thousand other ways to do some damage.