3 ms·
Asking authentication service to not use risk while using phishable authentication methods is essentially asking them to not bother with any protection from phi
by drivebycomment 4y ago
Asking authentication service to not use risk while using phishable authentication methods is essentially asking them to not bother with any protection from phishing and various password and 2nd factor theft.
If you don't like risk-based auth, use non-phishable authentication method like security keys.
Note that false negative (letting attacker steal) is roughly equivalent as false positive (not letting actual owner access the account) from the owner's access since the owner can't access the account in both cases (most attackers try to take over the account and lock out the original user - if you are a target of sophisticated attackers who would silently steal and watch your information, you wouldn't complain about risk based protection). But the former is worse from privacy obviously, thus any sane provider tend to choose false positive over false negative. The only way out of this bind is to use non-phishable auth, and at this point, security key is about the only one, with app based notification being close.
- xp84 4y agoWhen you say security key are you talking about hardware keys or is TOTP fine in your opinion?
- drivebycomment 4y agoTOTP is phishable. Don't use that.
- pdonis 4y agoHow is TOTP phishable?
- Macha 4y agoThe browser won't help you avoid putting it in the login form at google.com.fakehackersite.com which can then just relay that to real google. I think this is still an improvement over SMS, and personally is something that risk wise I'm happier with than the idea that if I lose a yubikey or it breaks down it's game over.
- xp84 4y agoAh, i see. definitely a concern for if i were administering an org. I still like TOTP vastly better than the only alternative with wide reach, the dreaded and stupid "code sent via SMS" but I hear you on the risk with unsophisticated users who click things. Maybe this WebAuthn thing will catch on and help? fingers crossed.
- drivebycomment 4y ago> I hear you on the risk with unsophisticated users who click things. The evidence says this attitude of "it's other people who get phished and not me" is pure arrogance. Practically all sophisticated security professionals can be phished with sufficiently sophisticated attacks, if the underlying system is using a phishable credential.
- ahtihn 4y ago> asking them to not bother with any protection from phishing and various password and 2nd factor theft. Yes, so? I can deal with phishing myself, especially with TOTP 2FA that risk is far far smaller than the risk of being locked out by some dumb risk heuristic. If the general public can't be trusted, fine. But let me disable these extra "protections"