6 ms·
Are you writing off 2fa as a whole, or just sms? Aside from full database breach, why would requiring me to use a security key, or authenticator app be a bad id
by six0h 4y ago
Are you writing off 2fa as a whole, or just sms? Aside from full database breach, why would requiring me to use a security key, or authenticator app be a bad idea? Physical theft is a lot harder (even just due to physical distance from a hacker) than stealing my password, which can happen at any distance
- sebow 4y agoI assume he mostly means SMS. And I fully agree, ever since I've got my security key I've stopped using SMS (though I never really had problems with people trying to social engineer my telecom provider). It's way more secure and it's somewhat permanent compared to a phone number, especially if left at home(since realistically unless you're commuting a lot you don't need it). The biggest perceived risk imo is when travelling(especially since changing countries will most likely trip any account session). Even authenticator apps are better than 2FA through SMS.
- winternett 4y agoAs a whole for social media at least. For items that are of national security and high sensitivity in the business world, personal devices are regularly being used in many cases (Non Gov Furnished Equipment) as well, and that thoroughly defeats the purpose too. The people that seek that level and volume of data are not usually simple amateurs that stumble upon script tools, they are usually engineers, info warriors, and even massive operations themselves with funding, skill, and human resources to get what they want. The best ways to secure data is at the system level and by not collecting data that is not needed for direct relevance to system function to begin with. Personal phone numbers have no relevance to apps like Twitter or Facebook beyond facilitating their personal information and ID lust.
- kube-system 4y agoToken based 2fa does not leak any information to the service and it has a benefit of preventing other types of attacks on the functions that the system is supposed to do. There is literally no reason to be against TOTP or WebAuthN
- winternett 4y agoHow could you ever guarantee that when registration for many services are conducted on such a wide variety of Internet-based web forms that are integrated into web sites? That's not logical. I've even seen sites where registration is done on sites with expired certs. Not everyone registers directly within the service itself, and there are plenty of cases where config and security are not implemented and managed properly.
- ziddoap 4y ago>I've even seen sites where registration is done on sites with expired certs. Not everyone registers directly within the service itself, and there are plenty of cases where config and security are not implemented and managed properly. I might be missing something, but what does that have to do with the efficacy of token-based 2FA?
- winternett 4y agoWeb forms allow social media sites to capture bare phone numbers and store them in other places than just for authentication services. The places they store these numbers are often exposed to the public and to partners for a fee, along with personal data, which regularly is connected to other personal data on each account user. 2FA does not keep your account secure, and is just a bogus ploy to get your phone number, by social and other platforms) if most of your personally identifiable information on a site stores can be scraped ALONG WITH YOUR PHONE NUMBER, as it was, from a social media site (Which is exactly what happened in the original article cited).
- scrollaway 4y agoYou are missing the point of the GP’s comment. Token based 2fa does not involve phone numbers. Most people who talk about 2fa being good are talking about TOTP or security keys. Phone number based 2fa is awful for a variety of reasons.
- croes 4y ago
- Thorrez 4y ago>personal devices are regularly being used in many cases (Non Gov Furnished Equipment) as well, and that thoroughly defeats the purpose too. U2F and WebAuthN protect against phishing. This protection applies regardless of whether you use a personal device or not. Even more relevant, one of the main benefits of 2FA is securing people who reuse passwords. Similarly, that gained protection is not lost by using a personal device.
- winternett 4y agoSystem rules can, and often are configured to prevent password reuse well before 2FA. They have also enforced password complexity for ages now before 2FA... 2FA was invented and foisted on everyone without real necessity and demand involved. Tying vital security to random, and often personal, mobile devices that aren't properly secured and registered is reckless. Text messages also aren't properly secure, neither is Wi-Fi and Bluetooth in many cases... It's not logically sound to say 2FA creates additional security in any other sense but within the technical complexity added to authentication. None of what you mentioned is advanced security if user phone numbers are stored and accessible along with their personal data. Social engineering alone from being able to call and text users and socially engineer access to their accounts through scams with the sheer amount of personal data that social sites and apps greedily and unnecessarily collect on them. Social media surveillance is a gold mine of data for a social engineer these days, specifically BECAUSE of how invasive it is. 2FA does not protect it, it only creates a secure log in, it does not secure data beyond verifying a user has the phone tied to the account. A mobile device is not a footprint nor proof of ID, it can be physically lost or stolen, or even cloned, which has happened often.
- Linosaurus 4y ago> System rules can, and often are configured to prevent password reuse well before 2FA. That does not at all help people who reuse passwords from one site on another.
- Thorrez 4y ago>System rules can, and often are configured to prevent password reuse How? And even if it's not verbatim password reuse, people often choose extremely similar passwords such that given one password, the other one can be guessed in a few guesses. Password complexity requirements don't stop password reuse. >Tying vital security to random, and often personal, mobile devices that aren't properly secured and registered is reckless. I agree that SMS is the worst form of 2FA. There are others though. >It's not logically sound to say 2FA creates additional security in any other sense but within the technical complexity added to authentication. You're conflating SMS 2FA with all forms of 2FA. There are other forms. The biggest threat that people face today is phishing. That's stopped by U2F/WebAuthN. One of the next biggest threats is credential stuffing. That's stopped by all forms of 2FA, regardless of how weak SMS is. >Social engineering alone from being able to call and text users and socially engineer access to their accounts through scams with the sheer amount of personal data that social sites and apps greedily and unnecessarily collect on them. U2F and WebAuthN protect against these types of phishing attacks. >A mobile device is not a footprint nor proof of ID, it can be physically lost or stolen, or even cloned, which has happened often. So use a different type of 2FA than SMS.
- ipaddr 4y agoYou lose access to the security key or the key stops working.
- staticassertion 4y agoBuy two keys. Your phone is probably a key already, so just one additional key.
- winternett 4y agoGive copies of the keys to all your co-workers, and leave one under the doormat too for a good time... Hah! All the added complexity of implementing minimum character limits on passwords and requiring them to be changed every 3 months literally drove people to write passwords on post its and put them on PC monitors back in 2019... Some things never change... Maybe we should add second and third passwords, and then keep goin until admins lose root access and just use Sudo.... LOL!
- microtonal 4y agoA YubiKey under the doormat protects against one of primary intended scenario: preventing phishing. It's unlikely that a phisher on the other side of the world has access to your doormat. Moreover: - Modern FIDO2 keys allow you to set a password (I think sites have to implement the newer FIDO2/Webauthn standards rather than U2F to use this functionality). So then when someone takes it from under your doormat, it is worthless. - Passkeys are coming. E.g. on Apple platforms they will be secured between devices using end-to-end encryption (through iCloud keychain) and they use biometric authentication to unlock (Face ID or Touch ID). This will make non-password authentication a lot more convenient.
- winternett 4y agoI know, I've used them multiple times. The thing is, no one can explain to me how it's better than just requiring 2+ passwords on each user account. You can't authenticate if you lose the Yubi when tech support is not available without circumventing the very process it was based upon... Nothing is failproof. Of course each specific use case is different. If Facebook demanded I use a dongle or even biometrics, that would very well be the exact point I quit it though.