3 ms·
This annoys me a lot - I do sympathise with the fact that these services are regularly bombarded with users unable to log in, but modern authentication tools ha
by roxgib 4y ago
This annoys me a lot - I do sympathise with the fact that these services are regularly bombarded with users unable to log in, but modern authentication tools have existed for a while now and it's time everyone learned to use them. A lot of services insist on including your phone number as a backup authentication method, making you vulnerable to simjacking, or your email address for the same purpose (basically offloading the authentication problem to someone else). That's if you can't bypass it altogether.
For services that allow it I have both a TOTP app on my phone and a YubiKey registered, which I figure is sufficient redundancy. Other people could have an old phone registered as well if they don't want to buy a security key. It's a very minor hassle to set up and I can't see why people can't do it.
- Brian_K_White 4y agoYou can duplicate the totp too. Either save the initial seed generated by the site(s), or depending on the app it may provide a way to export the seeds. You don't go through the setup process on the sites again. The sites have no knowledge that you have 1 or 21 new totp apps set up. You just enter the saved seed keys into the app and it starts spitting out the same correct codes as the other apps you already had setup. Gnome authenticator can export a json file containing the keys to all the sites you have in it. You can then take those (just manually read them in a text editor), and enter them into Google Authenticator on a phone, and now you have 2 working authenticator apps, both spitting out the same correct codes every 30 seconds. Further, you take that same json and paste it into a note in a keepass record, or save the individual seed keys in individual site entries just like the passwords, and copy that keepass db file all over the place including cloud drives, and including places you can access without the totp. Now you can reproduce a working authenticator from scratch on any device at any time no matter where you are and no matter what happens to your phone or laptop. Buy a brand new phone or laptop, have a way to get a copy of your keepass db without needing the totp app, and in a couple minutes you have a working totp app again. You never really have to even use the single-use emergency bypass codes. Keeping copies of the initial setup seeds is really no different from keeping copies of the emergency codes, but the setup seeds reproduce a fully working app not just a one-time access to a site. And even if some app doesn't provide an export like gnome authenticator, you can also just record the key the first time it is generated instead of just scanning the qr code. Once you've saved it, you can use it as many times as you want.
- mook 4y agoIf you're putting it in keepass anyway, you might as well use it (either the original C# one with plugins or KeepassXC) as your authenticator app. Mobile keepass applications support the same.
- Brian_K_White 4y agokeepass (xc, and Keepass2Android) can act as a totp app? And displays or exports the seeds? I am ashamed to say it never ocurred to me to even look! I don't think my android app can do it. I don't see anything about it in the ui and no plugin about it. Not at my laptop to check keepassxc, but I'll obviously look when I can, so the question was rehtorical. Just wanted to say "what?!?! what is this you speak of?"
- roxgib 4y agoThe disadvantage of this approach is that you can't invalidate those devices individually - if one is compromised (i.e. lost), they're all compromised.
- Brian_K_White 4y agoI don't see hlw this makes any difference vs a single device. If I only have a single device set up, and I lose that device, I still have to go to all the configured sites, only now without my auth app. What prompted me to figure out how to clone the setup was when my phone screen broke while away from home, and 2fa enabled on both google and Ting. I couldn't even just buy a new phone because how could I migrate the number? Luckily I never had to find out if Ting has an answer for that, since I was able to get the screen replaced without wiping the phone. I wasn't really screwed because I did have recovery codes for Ting in keepass, and had access to that. And that would have allowed me to move my number to a new phone, where I could once again receive sms to recover everything else. But I did not have recovery codes for anything else, because I just didn't fully understand the process when I first set them up, so for a few other things, I was maybe almost screwed if I couldn't regain access to that one special golden device. So, no more one special golden device.
- jzb 4y ago"but modern authentication tools have existed for a while now and it's time everyone learned to use them" It's a nice thought, but overall computer literacy is still highly varied, and it likely will be for a very long time. We still have a large percentage of users who use computers sparingly and by rote. I have family members who need a lot of help to do day to day setups and are going to have a hard time with MFA devices or apps. "Other people could have an old phone registered as well if they don't want to buy a security key. It's a very minor hassle to set up and I can't see why people can't do it." Minor hassle for you. Major hassle for a lot of users. Try real hard to put yourself in the place of a 77-year-old user who has limited sight and only needs to use a computer to accomplish very specific tasks - and has zero interest in doing more than basic email, banking, and a few other things that can only be done online. They have a smartphone only because it's a connection to their grandkids. Because of the smartphone they're saddled with a Google or Apple ID that they'd otherwise never bother with. A TOTP app or YubiKey? That's well outside their comfort zone. This isn't because these users are dumb. But the assumption that "it's time everyone learned" is based on the idea that everybody is using computers regularly and has resources for educating them - which is simply not true. My kids, my wife, and my in-laws all use computers very differently than I do and it's extremely educational how people outside the industry see and use computers. My 17-year-old only uses a Chromebook for school (grudgingly) and would rather do everything on their phone. My wife is fairly computer savvy, but still hits roadblocks. (She does enjoy forwarding me screenshots of particularly bad Phishing attempts...) And my older in-laws occupy most of their time far, far away from their computer. Singular. Anyway - it'd be lovely if folks had way more empathy for the huge swaths of people who have less experience with computers. It's not the priority for them that you imagine that it should be.
- roxgib 4y agoScammers and thieves don't care that you're old and scared of computers. Even if you don't think someone is going to want to bother hacking your email or instagram, surely we can all agree that online banks needs to be as secure as possible? I have trouble believing that someone can be literate yet unable to download Google Authenticator and scan a QR code if they really need to. It's just not asking that much. Someone with accessibility issues will no doubt find it harder, but everyone else is going to need a much better excuse. These are exactly the people that are most vulnerable to being robbed. It shouldn't be up to these users anyway, a bank can and should insist on MFA. I think you'll find most people will figure it out just find once they don't have a choice.
- plantain 4y agoI run a SaaS for what you might imagine would be highly technical, educated clients, and despite this I am bombarded by users who seemingly have never done a Register -> Activation email workflow. Users are hard.