5 ms·
Yet they still don't have a way to disable the 2FA prompt offered in the Gmail app (called "Google prompt"). It's a shame that you can add hardware security ke
by madjam002 3y ago
Yet they still don't have a way to disable the 2FA prompt offered in the Gmail app (called "Google prompt").
It's a shame that you can add hardware security keys to your Google account and all of that can be bypassed just by pressing "approve" in the Gmail app when you're trying to login.
The attack vector that I'm thinking of here is your phone being stolen while in public while unlocked, it doesn't even prompt for further biometrics when approving a login from the app.
- judge2020 3y agohttps://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/ AFAIK this removes the ability to use a phone prompt as 2fa.
- madjam002 3y agoAdvanced Protection is nice but practically a non starter or very difficult in a lot of situations, e.g if you're travelling and all of your security keys get stolen and your backup security key is half way across the globe, you'll wish you had 2FA backup codes then.
- toomuchtodo 3y agoI have a trusted family member who maintains a copy of all of my recovery codes. In event of disaster, I call and provide a previously shared pass phrase, and recovery codes will be provided. Something to consider depending on your daily driver threat model and tail risk considerations. (frequent international travel while having strong opsec)
- madjam002 3y agoBut if you enable Advanced Protection then recovery/backup codes are disabled right? (Maybe I’m wrong) So the only option to have recovery codes available is to not used advanced protection and then have this “Google Prompt” forced on you, which I’d like to disable as it is another physical attack vector which is undesirable especially when travelling.
- remus 3y ago> Advanced Protection is nice but practically a non starter or very difficult in a lot of situations, e.g if you're travelling and all of your security keys get stolen and your backup security key is half way across the globe, you'll wish you had 2FA backup codes then. All security is a trade off. For a good chunk of people that is a rare enough occurrence that it is a good trade off for them.
- madjam002 3y agoYeah for sure, which is why I’m not fussed about not being able to use Advanced Protection because I don’t fit in with their target audience. But I do wish that people on standard accounts could just disable their forced “Google Prompt” authentication method and just use their own 2FA security keys with fallback to backup codes.
- icf80 3y agoSkip password when possible You’ll be able to sign in securely with just a passkey or device prompt.
- TheNewsIsHere 3y agoMy only complaint about the tradeoffs made in Google's current implementation of Advanced Protection is that I can't (even if awkwardly and with difficulty) allowlist any given third party OAuth. So, if I want to, say, authenticate my Gmail account with Fastmail or ProtonMail, I can't also be using Advanced Protection. [0] With Google Workspace, admins can allowlist OAuth applications registered with Google APIs for users who use Advanced Protection. Consumer accounts have no such feature. I am not arguing the logic; I understand it. I just wish it were different. I suspect that passkeys are one stepping stone on the road to increasing account security baselines to be more like Advanced Protection, which may ultimately give me what I want one day. Wishful thinking, perhaps. [0] These are OTOH examples, which may not be accurate as of this writing.
- TeMPOraL 3y ago> All security is a trade off. For a good chunk of people that is a rare enough occurrence that it is a good trade off for them. Except most people are operating under a flawed assumption that the trade-off with Google is like a trade-off with any other institution - that is, if the worst happens, you can get a human on the phone, or visit a branch office, and get the issue sorted out. This critical fallback is, unfortunately, missing for Google and many other on-line service providers.
- lxgr 3y ago> Yet they still don't have a way to disable the 2FA prompt offered in the Gmail app (called "Google prompt"). There used to be a way to intentionally (after 2FA) add or remove devices to "Google prompt". These days, it just seems to be any device I'm logged in to, sadly.
- explodingwaffle 3y agoYep. I complained about that on HN recently- https://news.ycombinator.com/item?id=35692884 https://news.ycombinator.com/item?id=35692884 though since then it has, at least started working again. I didn’t mention it in that post but that is _exactly_ the attack vector I had in mind also- even if someone stole my phone, Touch ID should stop them from getting at my passwords.
- dheera 3y ago> The attack vector that I'm thinking of here is your phone being stolen This is exactly why I'm a big fan of larger, heavier devices, such as my rack-mounted desktop PC, being their own 2FA device. It's pretty hard to steal my 4U desktop that is bolted down, there's no reason why it should depend on anything else for 2FA. Similarly, laptops should be their own 2FA device and not depend on a phone, since people are generally more careful to not take laptops into high-crime areas.
- icf80 3y agoThey added a fix for that, see it in your security settings Skip password when possible - You’ll be able to sign in securely with just a passkey or device prompt.
- madjam002 3y agoThat setting doesn’t affect what I’m saying. I want to disable Google Prompt as it’s insecure for my threat model. All “skip password when possible” does is give you the option to use a passkey to login without a password, it doesn’t prevent an attacker from using a password + Google Prompt to login, bypassing the need for any of the configured 2FA security keys or passkeys.
- icf80 3y agopassword is still available, even with passkey