3 ms·
Require the second factor for decrypting the vault. It seems the second factor is "removed" as soon as you cache the vault on your machine.
by bobleeswagger 4y ago
Require the second factor for decrypting the vault. It seems the second factor is "removed" as soon as you cache the vault on your machine.
- secabeen 4y agoOkay, but the attacker has RCE on the system doing the decryption, so they can scrape the encryption keys or the vault data out of memory. This appears to be a APT, probably a State-level actor. Once the production work machine was compromised, it's all over.
- bobleeswagger 4y agoI get what you're saying, but the implementation of 2FA is still broken. If we don't fix that, we can't fix what comes next either.
- secabeen 4y agoI'm not aware of any 2FA that could be successfully integrated into a symmetric-key encryption algorithm. How do we fix 2FA without making the entire password vault system dependent on network access to a central LP server that is not compromised?
- trallnag 4y agoGood job moving the goal post.