5 ms·
This sort of defeats the idea of 2FA, doesn't it? If it's implemented as a software service on the same device, it's (well theoretically at least) hackable at t
by ivanhoe 4y ago
This sort of defeats the idea of 2FA, doesn't it? If it's implemented as a software service on the same device, it's (well theoretically at least) hackable at the same time as the device itself. The 2 factors from 2FA are both accessible to an attacker at the same time, so you effectively have just a single factor auth.
- gruez 4y agoIt does, but there's actually a way to do this (ie. u2f without having to buy another device) in a safe way, by using the TPM available on most computers: https://github.com/psanford/tpm-fido https://github.com/psanford/tpm-fido
- cube2222 4y agoThis is actually built-in to Safari on newer Macs.
- mjg59 4y agoUnfortunately without additional hardware support it's hard to tie TPM FIDO to physical user presence, which means compromising the system doesn't give you access to the secrets but does let you sign as many challenges as you want without user involvement.
- gruez 4y agoRealistically speaking if your machine is compromised it's effectively game over. If you're signing into services on a daily basis an attacker wouldn't have to wait long to piggy back off a legitimate request. The chances that you catch the compromise before that happens is slim.
- alrlroipsp 4y agoExactly. This is why 2FA is being discussed, and this software breaking 2FA.
- winnie_ua 4y agoBy the way, I like that tpm-fido is using uhid instead of USB/IP, because USB/IP doesn't have any security and authentication. At least we can restrict what user can create uhid host process etc. But USB/IP seems very insecure!
- Anunayj 4y agoI'm a little confused here, but I thought 2fa was a combination of something I know (A password) and something I have (A authenticator). So a attacker getting access to your computer is same as them getting access to your authenticator? Or do you mean that this leaves the secrets vulnerable to spyware and stuff? Cause in that case as the other comment says, one could use the TPM.
- vertis 4y agoA good example here is 1Password, which stores passwords and also allows storing TOTP. Which means the something I know is stored in the same places as something I have. Granted it is protected by encryption, and another password, but it definitely increases the attack surface. If the computer is compromised it becomes much more possible to get access to both of these items than if it was a security key, physical authenticator or even on a different device.
- userbinator 4y agoIt's still a second factor, just one that isn't as isolated as separate physical hardware. It's certainly more secure than a single password, while still giving the user absolute control over it. I can see this being very useful for accounts which are effectively throwaway, but they still force you to 2FA. The same is true of TOTP generators.
- gitgud 4y agoIs having 2 passwords to login considered 2-factor? Or single-factor because they're both the same type of authentication...
- tzmudzin 4y agoSame factor. It‘s always based on the 1) something you know, 2) something you have, 3) something you are categorisation. Multiple use of a single category still counts as one factor.
- jbverschoor 4y agoBy that, totp isn't a second factor either.. it's something you know. If it's something you have, that would be the same with passwords.. I don't know them..
- racingmars 4y agoPartially, but this still blocks many attacks that password alone wouldn't. I always think of 2FA as insurance against password theft/leaks. If users don't practice good password practices and use the same password for multiple accounts, for example, when ${next web site to be hacked} leaks all plaintext passwords, you can't just turn around and use that password to access ${another site where I used the same password but have 2FA enabled}. Or I'm logging in to a site from someone else's computer and they have a keylogger. [Obviously this virtual 2FA device wouldn't let me log in in that scenario--but in general, this is another case where the 2FA doesn't have to be rock solid, it just needs to exist if you captured my keystrokes.] A direct attack on my workstation to steal my virtual 2FA device and my passwords isn't protected by this virtual 2FA device, but that's low in my list of worries overall for people's account security.
- xani_ 4y agoYes it is for security, but it could be useful for testing
- ivanhoe 4y agoTo reiterate after giving it a bit more thought, this actually could be very useful if combined with fingerprint or facial detection as approval method - a bit like what Apple is now doing with passkeys, but will work with many more services out-of-box...
- jeffalyanak 4y agoIt's definitely not strong against the same breadth of attacks as a physical key, but I'd argue there's a place for something like this. This would still protect against phishing, which is probably the bigger risk for the average consumer.
- deleted 4y ago[deleted]
- winnie_ua 4y agoActually if your PC is compromised, then bad guy can exploit even hardware Yubi, because Yubikey lacks any screen, only button. Adversary can intercept your login in MITM style, authorize themselves on other machine, just using your machine as proxy, and website you tried to login to would just display error "can't authenticate, try again". And thangs to fact that key lacks display, attacker can event authenticate to different site, than you are authenticating now. Trezor is way better device here: > Phishing protection with on-screen verification. Trezor always displays the URL of the website the user wants to log in to, and what exactly is going to be authorized; therefore it is possible to verify that what was sent to the device is what is expected. https://wiki.trezor.io/U2F https://wiki.trezor.io/U2F https://wiki.trezor.io/FIDO2 https://wiki.trezor.io/FIDO2 And it supports U2F and FIDO2 (FIDO2 requires more expensive, newer model). P.S. storing locally in TPM is bit more secure, but still exploitable in case of local privileged code execution.