50 ms·
I think it's worth repeating: at this point, MFA that is not based on Webauthn (https://webauthn.guide/#about-webauthn https://webauthn.guide/#about-webauthn) s
by sullivanmatt 4y ago
I think it's worth repeating: at this point, MFA that is not based on Webauthn (https://webauthn.guide/#about-webauthn https://webauthn.guide/#about-webauthn) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus campaign, a sufficiently-skilled attacker will simply proxy the MFA calls to the real identity provider in real-time, the user none the wiser.
Webauthn, however, binds the authenticator to the domain and port, and requires https as the scheme. If a user gets phished, they cannot be compromised: the phisher's domain will not match and any Webauthn authentication challenge would fail.
So if your workplace is letting you authenticate with SMS codes, push notifications to an app, or 6-digit codes generated by an authenticator app/hardware device, you need to start banging on pots and pans up your reporting chain to get your security team the support they need to make Webauthn + FIDO2 hardware tokens or Webauthn + Mac Touch ID happen.
- saagarjha 4y agoI would be shocked if they didn’t issue all employees YubiKeys.
- bombcar 4y agoI my experience, prepare to be shocked. And even if they do, they likely have a “backup” for people who never seem to be able to use the Yubikey right.
- pm90 4y ago
- metadat 4y agoThis is false, a gross oversimplification. Every organization has complexities, it doesn't reduce to a common idiocy. Even when the net result is idiotic in hindsight.
- kirbys-memeteam 4y ago
- metadat 4y agoIt sounds like you're experience has been at a small firm. At scale, 2fa and yubikeys are a no brainer with regard to risk vs reward/ safety. Do you think all security engineers or whatever you want to call them are total incompetent idiots? If yes, I can't help you. If no, then you don't need further explanation from me. Security requires a complex balancing act, and in this case they got it wrong, end of story. As stated elsewhere in this thread, there are only those who've been breached and those who don't know they've been. End of story.
- kirbys-memeteam 4y ago
- metadat 4y agoThe bigcorps don't make exceptions for Tiny Tony's. If you work at these sorts of firms, you should probably start an anonymous exposé blog, it would be enlightening for the rest of us. It would also probably help get things fixed so they could avoid further embarrassment before it becomes a real problem (like in this case). I bet you could make a fair sum from the ad impressions alone, and feel good knowing you were acting as the force multiplier for positive change. Edit: Your personal jabs aren't in the spirit of a collaborative or curious conversation. You've revealed yourself as just another 007 wannabe. Boring.
- kirbys-memeteam 4y ago
- smegsicle 4y ago
- bombcar 4y agoAnd even when you do get it setup you end up having to make all sorts of exceptions for various people who can’t be told “no”.
- pm90 4y agoPainfully true. And once that exception is made, its easy to poke holes for more requests, until the security systems becomes somewhat pointless.
- BarryMilo 4y agoWhat? Security is the one domain I found where you can't just waltz in because you've heard of a computer. You need to do the work upfront with Sec+ or the like, it would take months for a newbie. Past that point, what more guarantee can you have? Even work experience can be meaningless if they weren't in the right team/role.
- kortilla 4y agoSecurity is a cost center, not a profit center. Most companies cut that investment to the bone, which means paying the bare minimum that lets them check boxes. This is true for basically any non-tech company, and is true for like 75% of the tech companies. > You need to do the work upfront with Sec+ Sec+ is part of the paper mill parent is referring to. A book of terms to memorize for 3 months and then call it good.
- vishnugupta 4y ago+100 Not only is it a cost center it’s also seen as a hindrance to the fast progress. Rarely will you come across an exec who takes security seriously. For them it’s just a checkbox at best and an obstacle at worst. I’m speaking about application security though. It’s possible that IT sec, physical security etc are taken more seriously.
- tyingq 4y agoCuts both ways, of course. There are terrible IT Security departments that don't understand the concept of false positives, create approval flows for critically needed items with 2 week SLA turnarounds, topple the network with poorly designed endpoint security scanners and tons of useless telemetry and so on.
- softveda 4y agoThat is why government intervention is needed. Australia is proposing significant changes to its cyber security framework and legislation. https://www.homeaffairs.gov.au/reports-and-pubs/files/strengthening-australia-cyber-security-regulations-discussion-paper.pdf https://www.homeaffairs.gov.au/reports-and-pubs/files/streng... Mandatory cyber security obligations backed by penalties and direct government intervention for critical national security companies. https://www.homeaffairs.gov.au/reports-and-pubs/files/exposure-draft-bill/exposure-draft-security-legislation-amendment-critical-Infrastructure-bill-2020.pdf https://www.homeaffairs.gov.au/reports-and-pubs/files/exposu...
- marcosdumay 4y ago> Security exists just to check boxes at most firms And then you get the bullshit solutions that the OP was complaining about. Nobody serious ever claimed that SMS based MFA was secure. Large companies implemented it anyway, and pushed it into unknowing developers nonetheless.
- sullivanmatt 4y agoA lot of people still have legacy Yubikeys floating around, and these are replayable. What you need now is something like the Google Titan FIDO2 key or one of the Yubikey FIDO2 keys. Transitioning an entire company to these, getting everyone to self-enroll, and then removing the ability to use all the less safe options across the employee base, contractors, etc is not cheap nor easy, and of course requires a massive amount of retraining. It's not as trivial as just buying them, sadly.
- metadat 4y agoWhat retraining? You install the yubikey by plugging it in, registering it, and using it by tapping it as needed. What is complex? There was literally no training involved for this during my time at ElGoog. One wiki page covered it adequately.
- fphhotchips 4y agoFor someone who claims to have worked in big corporations and accuses others of not having worked in them, you sure are optimistic about the capabilities of the average user. Not every company is Google. For starters, how do you register the Yubikey? On Okta, this is a multi-step process with at least one non-obvious step, and one easy way to screw it up.
- saagarjha 4y agoThe people who work at Google are not smarter than the people who work at Uber, or any other tech company. Getting people to understand 2FA might take a little bit of work but it's not hard.
- allset_ 4y agoWebAuthn (well, U2F, but that's essentially WebAuthn with a slightly different browser API and WebAuthn is backward compatible with U2F only devices) support has been on the YubiKey since the Neo in 2014 [0]. It's basically impossible to have a YubiKey that does not support WebAuthn. You do not need FIDO2 on-key resident credentials to benefit from WebAuthn. [0] https://www.yubico.com/blog/neo-u2f-key-apps/ https://www.yubico.com/blog/neo-u2f-key-apps/
- junon 4y agoThey did for a while but it was too expensive. Uber uses OneLogin, who I'm sure is also investigating. We had apps on our phones that received as "is this you trying to log in?" notification. You had to consciously hit "Yes" in order to continue the login flow. It wasn't offline 2FA like Authy or something. There _was_ a much higher standard of security there. This was _social engineering_, something that even the finest MFA algorithms don't guard against.
- mdeeks 4y agoIt’s too bad the user experience across devices sucks. The best experience by far is a yubikey nano since it is mostly permanently attached to your laptop. It’s always there and you just quickly tap it. Love it. Of course that doesn’t work with my iPhone. So I guess I need a second NFC yubikey that stays on my key chain in my pocket (which I don’t have since I don’t carry keys.). So then I have to remember to register both yubikeys. Then every time I have to login to GitHub or whatever on my phone I have to pull out my keychain (which I don’t have) and tap it on my phone. I wonder when I can just get a virtual yubikey built into my phone. No extra device. My phone is my device. It kind of sounds like what Passkey is but I don’t want to pull out my phone to auth my laptop. I really loved the idea and convenience trade off of SoftU2F. Too bad it’s dead now.
- tadfisher 4y agoAndroid has a built-in FIDO2/webauthn authenticator these days (well, built-in to Chrome, and by Android I mean Pixel phones). I'm sure Apple will build something similar as they have the hardware for it.
- acdha 4y agoHere’s Apple’s documentation from 2020: https://webkit.org/blog/11312/meet-face-id-and-touch-id-for-the-web/ https://webkit.org/blog/11312/meet-face-id-and-touch-id-for-...
- allset_ 4y agoThey called them Passkeys. It's FIDO2 with resident keys only AFAIK though https://developer.apple.com/passkeys/ https://developer.apple.com/passkeys/
- acdha 4y ago> I wonder when I can just get a virtual yubikey built into my phone. No extra device. My phone is my device. Last year, Apple shipped the first version of this: you can enroll your phone (or TouchID-equipped Mac) on sites like GitHub.com and it’ll use the Secure Enclave for WebAuthn secrets. I’ve been doing this since 15.4 came out and it’s great. Prior to that, I used a Yubikey 5 with USB and NFC, which is still handy since that’s where I store TOTP seeds for less secure sites. Passkeys extend that idea further by allowing you to register once and have it synced rather than having to register every device on every site[1]. That last part is important because AWS has a huge barrier: the number of MFA devices you get is one, which means you either need insecure things like synced TOTP seeds or you have to be comfortable never losing your Yubikey. I have been asking our TAM to prioritize fixing that for years so backups can be a real thing. 1. Over simplified a little - hear Adam Langley at https://securitycryptographywhatever.buzzsprout.com/1822302/11122508-passkeys-feat-adam-langley https://securitycryptographywhatever.buzzsprout.com/1822302/... for the right version
- encryptluks2 4y agoHow do you proxy MFA unless you're using a third party service for authentication? Plenty of password apps can bind to specific URLs and ports to support TOTP. In what ways do you think it is more secure if an authentication provider gets hacked? Then they could just as likely proxy the hardware token handoff. I don't think hardware tokens are all that much better than someone who is more security conscious, but they are certainly great for people that have no clue what they are doing or just one step in a MFA process.
- judge2020 4y agoActually using a pw manager for TOTP is quite rare. People using a PW manager at all outside of the tech space is rare in my experience as well, outside of the built-in chrome PW manager. Their 2fa is most likely okta or Duo style, in that the default authentication method is via push notification. > Then they could just as likely proxy the hardware token handoff. You can't do that because the security token itself receives the "relying party" in the form of the domain name it's trying to present authentication for. Requesting "uber.com" when on "ubeer.com" won't work.
- _8j50 4y agoIt's good to have but in the real world that wouldn't have stopped a determined attacker. They could have social engineered them to run code on their PC
- staticassertion 4y agoSo an entire class of attacks would have been removed and the attacker would have moved to another class of attacks. As for running code in the environment there are many, many ways to deal with that. Obviously it's an easier environment to audit, but it's also much easier to control.
- _8j50 4y agoYes, I don't disagree with anything you said. I am not saying MFA may not have at least slowed down the threat actor but the focus here should be how easy lateral movement was. Like you said there are many ways to get in. If the network share was treated the same as internet facing stuff though, that sounds like a deeper issue many orgs face but I am surprised that a fairly new org like Uber is not doing that already.
- cyral 4y agoI sure hope WebAuthn is easier to implement than that site is making it look like. I know nothing about how it works, but the sample code (Under "Example: Parsing the authenticator data") that requires parsing slices of bytes out of the response and then constructing some object with magic numbers looks really hacky. Maybe it is supposed to be exposed at a low level like that so wrappers can be made around it, but if there is any hope of migrating sites over to it, it's going to need to be dead simple to implement without screwing up.
- monocasa 4y agoFor the most part, none of that matters client side. The web client side is mainly just a passthrough to your backend that'll do the actual processing of those binary blobs other than for example code.
- cyral 4y agoI see, if all that is server side then it makes a lot more sense as I assume backend libraries will get created to handle this for various languages. Bookmarking it to check it out later when I have time to read it all, hopefully it isn't as daunting as it looks.
- milkshakes 4y agohttps://simplewebauthn.dev/docs/ https://simplewebauthn.dev/docs/
- pdntspa 4y agoHow would one slice a byte array without magic numbers? Or without constants representing said magic numbers?
- cyral 4y agoBy having an API that abstracts the details away, like any other browser API. I would expect something like attestationObject.getPublicKey() versus whatever is going on in that demo. I believe it was some part of oauth or saml (again not an expert here) where developers were making a common mistake by not verifying everything in the spec, leading to an easy bypass if you knew how it worked. Having devs implement a complex spec relating to authentication is a recipe for disaster.
- raverbashing 4y agoSo, where does it end? Cybersecurity has been playing those silly games of "increasing security" and some 80% of recommendations were frankly BS "longer passwords" yes. "password has to have symbols, numbers and be rotated every 3 mo" no 2FA yes, but not SMS, but not OTP because people get fished, blah blah blah Not to forget the "put everything in a password manager" then you lose or forget your "extra safe random password" and are SOL Meanwhile there are still incompetent people around that think asking for Mother's Maiden Name should be a security question So where does it end?
- SamoyedFurFluff 4y agoI don’t think it ever truly ends, so long as there are secrets and people who want to uncover them. This is the classic arms race, and subsequently people who can’t keep up are just casualties…
- pat2man 4y agoSmart cards have long been mostly phishing proof. WebAuthN is essentially a more convenient interface to the same technology.
- raverbashing 4y agoThen your phishing involves them installing some type of remote access on their machines. Or to get some information you need
- nindalf 4y agoDon’t worry, we’ll cover this in annual mandatory security training.
- jjav 4y ago> So where does it end? It doesn't (can't) ever end because security is a process, not something you achieve and are done. With ~inifite budget, one could achieve perfect security (but only for a clearly scoped threat model) for an instant, but both the infrastructure and the attackers move on, things constantly change, so it's not perfect anymore. And of course infinite budgets don't exist.
- j1elo 4y ago> you need to start banging on pots and pans up your reporting chain to get your security team Not sure how Webauthn works, but as long as it can be stored in the cloud, I'm fine. Industry is going towards this scheme of physical 2FAs that assume some living conditions appropriate for whoever designs things, without alternatives for people who don't fit that ideal way of doing things. Physical stuff gets lost or stolen. I'm optimizing for when I am traveling from home around the other side of the world, 6 time zones away, and my phone / stuff gets lost. 2FA is already unmanageable at this point: "just use your recovery keys" is what people tell you, but that's NOT a viable solution to the problem. Sorry but my recovery codes are in a safe lock, 10,000 Km away from me, I just lost the purse with my phone, or my device broke, or got stolen, or whatever, and need the damn TOTP code to telework _right now_.
- reissbaker 4y agoI think the tradeoff between "the entire company is breached" vs "I lost my device while on vacation and I have a tight deadline" is probably best geared to help prevent the former than the latter. (Webauthn by design requires physical hardware tokens, not cloud storage.)
- deleted 4y ago[deleted]
- jsnell 4y ago> (Webauthn by design requires physical hardware tokens, not cloud storage.) That's not true. As an obvious reductio ad absurdum, you could just build a fake USB driver that presents as a security key. But more practically, I'm pretty sure that iOS the Webauthn secrets are synced cross-device via iCloud.
- Rafert 4y agoWebAuthn does not mandate any kind of form factor[1], external tokens use CTAP for USB/Bluetooth/NFC, Apple FaceID/TouchID and Windows Hello using proprietary interfaces with the built-in hardware. Blink-based browsers ships with a virtual authenticator for debugging[2] and there are a few more[3]. Apple and Google already announced cloud syncing earlier this year, using "passkey" as a friendlier term for end-users. QR codes already allow for cross-ecosystem non-synced use cases, like using my personal Android phone to log in an account with my work Macbook. https://securitycryptographywhatever.buzzsprout.com/1822302/11122508-passkeys-feat-adam-langley https://securitycryptographywhatever.buzzsprout.com/1822302/... is a good listen to catch up on the latest developments. [1]: https://www.w3.org/TR/webauthn-2/#authenticator-model https://www.w3.org/TR/webauthn-2/#authenticator-model [2]: https://developer.chrome.com/docs/devtools/webauthn/ https://developer.chrome.com/docs/devtools/webauthn/ [3]: https://github.com/herrjemand/awesome-webauthn#software-authenticators https://github.com/herrjemand/awesome-webauthn#software-auth...
- traceroute66 4y ago> So if your workplace is letting you authenticate with SMS codes There's an old saying in photography, "the best camera is the one you have with you". IMHO its very much the same thing with 2FA. Any 2FA is better than no 2FA. Sure some 2FA options are more secure than others, but by the same token, there's also a scary number of websites out there that have zero 2FA options. Others make it inordinately difficult to find (e.g. I'm looking at you Slack ... finding where to turn on 2FA in Slack is a nightmare). Ironically there's no 2FA option for HN either. ;-)
- madeofpalk 4y agoThat's like saying MD5 is fine for hashing passwords, because it's better than plaintext.
- traceroute66 4y ago> That's like saying MD5 is fine for hashing passwords, because it's better than plaintext. No, I'm saying we need to come down to planet earth and recognise we live in the real world. Hence SMS or TOTP is preferable to nothing at all. Its a bit like the hardcore open-source types who can't see the wood from the trees and cannot fathom why anyone would possibly want to use anything else other than Linux and fully open-source alternatives to Microsoft Office or Photoshop. Sometimes you have to compromise.
- oblio 4y ago> That's like saying MD5 is fine for hashing passwords, because it's better than plaintext. If for whatever reason you can't have anything else, MD5 is obviously better than plaintext. Not fine, but better. With passwords you don't have external dependencies but with MFA, you do. Things are more complicated and real life is messy.
- hatware 4y agoThey're saying perfect shouldn't be the enemy of good enough. Completely valid.
- highwaylights 4y ago
- Dowwie 4y agoYou think that it is worth repeating that multifactor authentication not based on the latest unproven marketing hype technology, Webauthn, is dangerously insecure? You don't know what you're talking about.
- batch12 4y agoI will grant you that the parent's opinion is a little strong, but fundamentally, they have a point. The weakness here is the human. Standards like this take make social engineering attacks much more difficult. With that said, MFA in some form is better than none. However, some implementations provide better security than others (of course).
- acdha 4y ago> not based on the latest unproven marketing hype technology, Webauthn WebAuthn is an ongoing project but the history goes back almost a decade to U2F, and the ongoing work has been carefully reviewed by a number of industry heavy-hitters. We know that it’s robust against phishing, too, which is why it’s so relevant to this conversation. I’d also like to know more about your rationale for describing a system all of the major players have implemented as “unproven marketing hype”.
- Dowwie 4y agoMaybe "unproven" was a poor choice of words. I'd be willing to go so far as to say that it is "proving" itself as bleeding edge technology. However, if measured by adoption and risk-taking, it is largely unproven. The history may go back almost a decade, as experimental technologies driven by industry working groups tend to do, but that work does not extend beyond the theoretical. If Facebook and Google implemented WebAuthn, they're still not staking their reputations on it. If they did, we wouldn't be using password-based logins nor MFA. Instead, they're slowly testing the waters in the real world, waiting to see how hackers respond to it. Consequently, WebAuthn remains on the bleeding edge, in the very early part of the adoption curve as it proves itself.
- acdha 4y ago
- dustinmoris 4y ago
- mcstempel 4y ago100%. The common thread in all of these recent attacks (Uber, Twilio, Okta, etc) is the “phishability” of the authentication methods involved -- as you mention, the unphishability of WebAuthn is what makes it particularly compelling. What’s head-scratching to me is why tech-forward enterprises haven’t been faster to adopt unphishable forms of authentication like WebAuthn. I’m biased as I run an identity and access management company (stytch.com), but I hope more companies will consider integrating WebAuthn to support unphishable MFA. Today, WebAuthn introduces some nuances that can discourage a B2C company from supporting it today (e.g. account recovery with lost devices), but it’s a clear win for corporate network/workplace authentication and B2B apps. I believe some of the lack of adoption is due to complexity to build (more complex than traditional MFA) and cost for off-the-shelf solutions (Incumbents like Auth0/Okta require ~$30k annual commitments to let developers use WebAuthn). If developers decide to build with Stytch, WebAuthn is included in our pay-as-you-go plan and can be integrated in an afternoon(https://stytch.com/products/webauthn https://stytch.com/products/webauthn)
- trollied 4y agoI’ve not read up about webauthn yet. How does it work & what makes it unphishable?
- mcstempel 4y agoHere's a bit more background on WebAuthn: https://stytch.com/blog/an-introduction-to-webauthn/ https://stytch.com/blog/an-introduction-to-webauthn/ What makes it unphishable is that the authentication is not based upon something that a user can be deceived into sharing with an attacker. Passwords and one-time passcodes (OTPs) can both be remotely acquired from users when attackers convince users to share these text-based verifications with them. Because WebAuthn validates possession of a primary device that was previously enrolled (either the computer/phone the user is leveraging for the biometric check or the user's YubiKey), it's device-bound and cannot be phished.