4 ms·
> I don't think it can be done without hurting seriously usability (like having one 2fa verification each time you use a credential would work) I wouldn’t mind
by konha 4y ago
> I don't think it can be done without hurting seriously usability (like having one 2fa verification each time you use a credential would work)
I wouldn’t mind tapping a YubiKey or my MacBook‘s Touch ID every time a password is accessed from the vault.
That’s essentially how ssh keys work with smartcards or security keys as a second factor.
- execveat 4y agoUsually non-technical management are the ones that are against this kind of measures. This recent Passkeys initiative (that's what allows using secure enclave as a Webauthn key) is amazing though, I really hope it changes the game and maybe finally obsoletes passwords as a whole. Also, as an aside. While correctly implemented Passkeys (without fallback auth methods) would make my life as a red teamer much harder, that would have only prevented this attack if the infected machine was engineer's private PC where they used corporate LastPass account and nothing else from their work. If the machine that's used for DevOps work gets infected, that's still and endgame because you're generating all sessions I need during your regular workday, so I don't really need the passwords / decrypted vault.