5 ms·
Can someone explain why people seem to be so happy with hardware tokens that they're okay with doing away with a password entirely? Doesn't that bring us back d
by timwis 4y ago
Can someone explain why people seem to be so happy with hardware tokens that they're okay with doing away with a password entirely? Doesn't that bring us back down to single factor authentication (now just 'something you have')? Or is the argument that if the majority of users only have a single factor anyway, hardware tokens are a better single factor than passwords, and that ideally everyone would still have two factors?
- panny 4y agoIt depends on how you're using it, but the hardware token generally requires a pin for most operations. I think the real argument is that hardware tokens absolve the web host/service of responsiblity for passwords. With tokens I'm just presenting the challenge given a public key. Nobody can hack all the tokens at once like they can a database full of passwords.
- lloeki 4y agoWith devices that have biometric validation it becomes something you have (unextractable private key in secure enclave in laptop, phone, or hardware token) + { something you are (face or fingerprint that unlocks secure enclave) || something you know (pin or password that unlocks secure enclave) } Of course recovery codes are a single factor, so to have it be 2FA still they should not be memorised (to keep them as something you have, not something you know) and be locked away in a way that adds a second factor, e.g in a safe locked by biometric or gated by an id check (bank, notary office) for something you are, or a pin/code/password for something you know. Sounds cumbersome? Maybe, maybe not. It all depends on your trust model + threat model. Maybe a bank is too much and a trusted friend or neighbour is fine for "id check", maybe not. The less you trust the less options you have for recovery. As an example: What if one dies? Is there a recovery procedure? Does it entail someone mentioned in a (paper or digital) will having a death certificate at hand? Then one has to trust the designated person not to fake a death certificate, and so on and so forth.
- michaelt 4y agoThere is a standardisation process with multiple stakeholders. Some stakeholders want hardware devices that are secure even if the OS has been completely compromised - even if they have to trade off usability and price to achieve it. Other stakeholders think iPhone biometrics are pretty great, and if you've logged in with full credentials and indicated indicate the phone is trusted, going forward the combination of recognised phone + biometrics is good enough, even if it doesn't secure against a compromised OS. And in a spirit of standardisation and vendor independence, if iphone face recognition is good enough, why shouldn't the face recognition on a phone from Honest Abraham's Used Cars And Android Phones also be good enough? It is the latter group of stakeholders that are currently ascendant.
- worldsavior 4y agoPasswords are a bad way to authenticate. They allow stealing, hard to keep up and easy to forget. Also they are not very comfortable... With FIDO, your device can be stealed but it's much harder to penetrate. It also allows easy sync between multiple devices, and you don't have to worry about having high entropy.
- lesuorac 4y agoDoes nobody else here have an actual key to unlock their car / housing? Like this was a solution that has worked for a long time. Sure houses/cars get broken into all the time but so do online accounts and judging my my spam mail, more people I know have had their online account hacked than their car/house broken into. And I know many more instances of people forgetting their password and reseting it than them locking their keys in the car.
- lolinder 4y agoThe difference between houses/cars and online accounts is that a physical key must be joined to the single matching physical lock, which reduces the number of possible attackers dramatically and forces them to operate in meatspace. This means that a less secure solution is viable because there are fewer attackers and they are more likely to get caught. It also means that an easily-lost solution is more acceptable because it's easier to persuade a locksmith or police officer that I actually own the property: I can hand them my driver's license in person, and I'd be risking immediate arrest by even trying to pull off a social engineering attack. This allows recovery of a key to be far easier in the real world. Physical keys to digital accounts cannot be as easy to replace because if they were, anyone anywhere might be able to persuade the digital "locksmith" that they're me, and the worst case scenario for the social engineer is that their attack fails and they try again later.
- lesuorac 4y ago> The difference between houses/cars and online accounts is that a physical key must be joined to the single matching physical lock, which reduces the number of possible attackers dramatically and forces them to operate in meatspace. Sure but a digital physical key uses a much more difficult password than you could memorize so even though there are more attackers the difficult of breaking the key has gone up. > Physical keys to digital accounts cannot be as easy to replace because if they were, anyone anywhere might be able to persuade the digital "locksmith" that they're me, and the worst case scenario for the social engineer is that their attack fails and they try again later. I fail to see how this is different from the current password status quo. This is quite literally a well published attack vector into accounts, call up support and pretend to be the other person using their data from w/e leak happened recently enough. With a physical key there's going to be way less people forgetting their password so the same staff can spend more time verifying that somebody is who they say they are (or a company can do the same quality will less staff).
- postalrat 4y agoMost our maybe all hardware tokens when used too eliminate a password will require biometrics or a pin. No different than unlocking a phone.
- rstuart4133 4y agoCharacterising FIDO2 as a single factor is over simplifying it. You have to convince the FIDO2 token to prove it's presence. Yes, for many, all it takes is plugging then into a USB socket. And yes that's just one factor - having the token. But some tokens ones require a fingerprint. That's two factors - having the token, and a fingerprint it recognises. But move to a device like a phone and the games changes. It could just be the presence of the phone. More likely it will probably insist the phone is unlocked. But the app could demand a fingerprint, or face recognition, or a PIN, or be in a particular location, or see other devices it knows, or some combination.