11 ms·
OT: With the current state of smartphone operating systems, I would need one of those to be release every other month or so. I cannot get to data on 'my' system
by asimops 4y ago
OT: With the current state of smartphone operating systems, I would need one of those to be release every other month or so. I cannot get to data on 'my' system, because an app decided to put it in their app folder, which I cannot access at all for 'security' reasons...
I mean, I get it. It should not be easy to just unlock my phone and dump all my 2FA tokens. But if I want to back them up, i.e. because steam blocks my account for 7 days if I change to a new device, I want an option to get them!
Make me reboot the thing into a special state, connect it to a computer on blood moon and dance in front of the cam to authenticate myself if you must, but for fucks sake, I want to access my data.
- yoavm 4y agoThat's why I still root my phone. It's hard to explain, but it's simply the only way to actually be in control of my own device. For the specific use case you mentioned, however, I recommend Aegis with Syncthing. Very easy to set up a periodic back up and sync, encrypted at rest and on transit.
- remram 4y agoAegis doesn't support Steam. [edit: yes it does, although Steam doesn't use the standard, Aegis has special support for it]
- stoltzmann 4y agoIt does (or at least did a couple months ago) - you could have it import Steam keys and generate the codes in the actual Aegis app. I'm not sure if it requires root or not.
- tecleandor 4y agoIIRC (I tried to do it a couple months ago), it requires root to extract the key file.
- PufPufPuf 4y agoNope. You can use a special app on PC that will simulate the authenticator and extract the OTP key, which you can then enter in Aegis. I'm using it like this and have no problems.
- oefrha 4y agoFound https://github.com/Jessecar96/SteamDesktopAuthenticator https://github.com/Jessecar96/SteamDesktopAuthenticator, not idea if it works.
- 0xdeadbeefbabe 4y agoWhat is so great about Steam on mobile?
- remram 4y agoI'm not trying to say it's great, just that a few websites insist on using their own home-brewed 2FA and therefore don't work with the apps that support the standard. For example Twilio/SendGrid, Steam, etc. Someone in this thread already pointed out that I'm wrong and although they don't use the standard, Steam is supported by Aegis.
- asimops 4y agoThe problem with rooting the phone is that it actually compromises features like verified boot and selinux namespacing. I still want those security features for daily use. I still need a way around this, but it at least has to be technically secure. It will obviously still be open to social engineering attacks. For your suggestion, sadly you somehow need to get steam's otp secret first, which is held in the apps data directory. Therefore you would need root/priv-esc to get to it.
- feanaro 4y ago> compromises features like verified boot and selinux namespacing It only compromises those features because vendors refuse to build in the functionality to have full control over your purchased hardware out of the box. Make it protected behinds loads of warnings and even hidden behind a trick like what you have to do to enable developer mode, but leave it baked into the OS.
- asimops 4y agoWell, I don't deny that there should be an option. Look at the parent post. But having root in the running OS seems to be a bad idea. I got this position after an extensive talk on this with some of the graphene os developers. They explained pretty good how rooting the device would impact the security measures taken in graphene. This is why I suggested putting the access behind a special boot mode.
- yoavm 4y agoCan you be more specific about your concerns? It's not like "having root" means "everything runs as root". You can enable/disable it per app, you always grant it explicitly when you want to - it's not very different from sudo on Linux.
- feanaro 4y agoI'd also like to hear these arguments, as I can't think of a technical reason why it would be unconditionally a bad idea.
- collsni 4y agoYes exactly, this is why I still root my phone. My phone my files.
- hparadiz 4y agoI'm constantly frustrated with techies on HN and other social media claiming my rooted phone is somehow not secure. I've always rooted my phone ever since Android was a thing and have never had any issues.
- heavyset_go 4y agoI was spoiled for years with rooted phones, and ended up making a lot of assumptions because of it, one being that I could always access apps' SQLite databases and cached files if I needed to. I ended up with a new phone, decided not to root it, and found myself in a situation where I needed to get some cached data out of an app I could no longer access normally. That's easy on a rooted phone, but it's next to impossible on a locked down phone. Lost a bunch of pictures and whatnot as a result.
- narrator 4y agoYou can use authy if you want to back up your 2fa codes. Google Authenticator is a lousy piece of software because you can't easily switch devices.
- charcircuit 4y ago>I cannot get to data on 'my' system There is not a great way for a phone to know whose system it is. Possession of the device doesn't necessarily mean that it is theirs. >But if I want to back them up, i.e. because steam blocks my account for 7 days if I change to a new device, I want an option to get them! Do you not see the irony in this? If you make it possible to switch to a new device without the 7 day lock then an attacker can bypass it too.
- yjftsjthsd-h 4y agoThere needs to be some way to tell the device that the user is authorized, otherwise it can never do anything that could possibly be security sensitive - forget taking a backup; why should the 2FA app give you a one-time code if you could be an attacker? Edit: Thinking about it more, I suppose it all comes down to a cost/benefit analysis. It's true that taking a backup of 2FA secrets does give an attacker more than a single code. But when that trade is leveraged against the legitimate user being unable to control their own device, I think it's a terrible trade, to the point that I'm not convinced it's ever worth taking. And of course my real objection is that the user is rarely if ever actually asked; rather, a company tells the user that they can't control their own device, which is unacceptable.
- charcircuit 4y ago>why should the 2FA app give you a one-time code if you could be an attacker? Because the app aims to prove that someone has possession of the device. If someone has the key instead they can give back the device and generate codes later without possession. They can also resell the key online without having to ship a physical device. They can sell the same key to multiple people.
- deleted 4y ago[deleted]