6 ms·
You're doing two-factor authentication wrong
- eimrine 3y agoYou're doing two-factor authentication wrong because of not allowing me to use a single factor only (maybe I do not want to check e-mail and/or to carry smartphone with me and/or your website has too miserable value to me to take care about it).
- cyberbanjo 3y agoIn that case, doesn't your password manager support TOTP?
- alias_neo 3y agoYou missed their point, they might not want to carry a smartphone and 2FA requires you to _have_ something.
- j-pb 3y agoYou missed their point, accessing a website also requires you to have _something_, namely a device with a browser. If you have a device with a browser, then you have a device with a password manager. Unless you only access that site via public infrastructure like a library, but that might not be infrastructure that you want confidential information to run over, because everybody and the milkman has access to it. And even then, 1Password for example also has an online version that you can access in those cases.
- b112 3y agoNo, you missed the point that the point was pointing to. A paasword manager is also "your brain". A website can be happy with just a password. For crying out loud, people don't need 2fa for a knitting forum!
- sigio 3y agoThe password manager being 'your brain' implies that you have only a hand-full of passwords... my brain has no way of remembering 1000+ passwords and logins, while I prefer to use random usernames and passwords. Sure, I don't need 2fa for a knitting forum, but I still need something to remember my login and password... try to never re-use either.
- b112 3y agoI have two categories of passwords. One for knitting forum class, and one for password manager class. No, it isn't a crisis if someone gets my credentials to the knitting forum, the pics of acrons forum, and the local 'reserve space at the county pool' website... all in one go. I can just change them all at once, from the letter 'a' to the letter 'b'.
- alias_neo 3y agoTo further support your argument, I'd suggest that requiring a login at all for this class of "service" is bullshit. I've set the bar pretty low these days for "if you require a login, I go somewhere else" because there are plenty of places that just don't need it in my opinion. To be honest, I class Twitter as one of those places; I go there to read certain information from specific "outlets" but Twitter as we all know have made it very difficult (as with other social sites of this type) to be read-only.
- charcircuit 3y ago2FA is about _proving_ you have something. For someone else to prove they have that same thing they have to physically steal it from you and possess it at the time of authentication.
- chromanoid 3y agoYou are probably not lazy enough ;). I even hate to generate a password for a site. Having to open an authenticator app is too much of a hassle to be worth it for many sites. And it doesn't really make sense if the second factor is available on the same device...
- oneeyedpigeon 3y ago> If you have a device with a browser, then you have a device with a password manager. I dispute that. Does the Nintendo Switch have a password manager?
- eimrine 3y ago> You missed their point, accessing a website also requires you to have _something_, namely a device with a browser. If you have a device with a browser, then you have a device with a password manager. My point from the root of this tree was that I do not want to make a shit travel (github asks me to prove identiny by mail > gmail asks me to prove my identity by phone > my phone is somewhere else because I am not addicted to it) just to have an ability to use my github from web-interface. If I can successfully use my bitcoins without any 2fa/totp security theater than github is just shitting me with no good reason for me and for my helloworlds collection. Probably just saving cookies solves the problem of the shit travel, but since every few hours session of browsing makes me to store tens megabytes of cookies with no value to me (except of not un-logging from github) I use to clear all cookies every time I close my browser.
- masklinn 3y agoHell you can literally run TOTP via pen and paper if you want to (though you probably need to compute it a few windows in advance, especially with the hmac_sha1).
- eimrine 3y agoThe world is too complicated already to care that much about some insignificant websites.
- alias_neo 3y agoI see you're being downvoted, but I see your point. Twitter has so little value to me, I don't see the point in requiring the extra security (for me). I guess if you're some sort of public figure it might be, but selling blue badges to anyone kinda destroyed any credibility it had as a platform for those people.
- catmanjan 3y agoThe problem is these platforms double as identity providers so your twitter hacked can give access to other websites - it’s crazy that this was ever a thing
- megous 3y agoThat's still often times an optional feature, so if you don't want to use it as IDP, you may not want to opt in to 2FA.
- magicalhippo 3y agoUbisoft's UPlay tries to get me to sign up for 2-factor every now and then. For some it might be a good idea, if they have a large library and maybe use their account on internet cafes and such. But they have a "Skip" button which so far works just fine. And I'm very happy it's there. So regardless of other merits, at least Ubisoft did that right with UPlay.
- EGreg 3y agoWhen we were implementing blockchain-based voting, we assumed that since people trust banking apps with their money, they should be able to trust a crypto wallet with their vote. But the biggest security flaw, it turns out, is systemic, not individual: people simply don’t care about securing their one measly vote as much as they care about securing $100,000 in their bank. So while people were motivated to secure large individual balances, they were not motivated to secure their votes. Which is why we have to force people to confirm their votes on another device, so that Apple or Google couldn’t theoretically steal the election by lying to you about who you voted for, let alone some random website like stackoverflow (which people trust in their moderator elections etc.) It turns out that this is also necessary for Web3 — the current state of security is dismal, the vast majority of people don’t actually check they are interfacing with the right contract or calling the right method or sending the right parameters before they hit “Submit” to sign the transaction. So even there, people have to be forced to double-check the details on another device, depending on the value of the transaction. For more info see my article from 2020: https://www.coindesk.com/tech/2020/03/12/in-defense-of-blockchain-voting/?outputType=amp https://www.coindesk.com/tech/2020/03/12/in-defense-of-block...
- chromanoid 3y agoI totally agree. But I also hate to add a password for each shitty website. I also don't want to connect an account via e.g. OIDC with any of my important accounts. I think there is a product or at least a new common mechanic somewhere in this mess.
- shortcake27 3y agoPasskeys solve exactly your complaints. They’re being pushed heavily by Apple and Google, so very soon you’ll be able to sign up for sites without having to set a password + MFA.
- chromanoid 3y agoBut won't this just use Google Sign In in the end. This will give the shitty website at least my OpenId data from Google and enables social engineering with my important account?
- plaguepilled 3y agoThis is the unfortunate truth about 2FA. While it significantly improves security, it is significantly less ergonomic than passwords (which are already sucky). It is also a problem when phones are, for whatever reason, not ideal for the work environment.
- zb3 3y agoI don't want to authenticate using something I have, because I won't be able to authenticate if I lose that thing. Phone number is something I legally own and this ownership can be enforced because I can get a new SIM card with the same number using my government ID - something I am rather than I (temporarily) have
- edf13 3y agoNot sure you legally own a phone number... isn't more of you legally have the right to use it whilst the telco allows it/and you pay your bill?
- red_trumpet 3y agoIsn't the telco contractually required to let me use it? Not sure about the US, but in Germany I think you even have the right to keep your phone number when changing telcos.
- easyThrowaway 3y agoI guess it depends on the jurisdiction, but in Europe (at least, France and Italy I'm certain of) the phone number is treated as personal sensitive data[1] and "owned" by the contract owner, not the telco. [1] https://commission.europa.eu/law/law-topic/data-protection/reform/rules-business-and-organisations/legal-grounds-processing-data/sensitive-data/what-personal-data-considered-sensitive_en https://commission.europa.eu/law/law-topic/data-protection/r...
- ThePowerOfFuet 3y agoNo, this is not ownership.
- world-set-free 3y agoJust to warn, social engineering attacks can get sims transfered without your involvement. There were some stories about it here somewhere a very long time ago.
- world-set-free 3y agoTwo factor authetication is dumb. It invites poor disipline with reusing passwords and with 500 pound gorilla corps, losing your second factor is losing your account permanently.
- oneeyedpigeon 3y agoYup — and the standard phone authenticator app pretty much guarantees you'll lose your second factor one day, unless you always upgrade your phone before it breaks.
- cuu508 3y agoConsider 3 scenarios: - Alice is currently reusing passwords, and does not use 2FA. Alice decides to set up 2FA, but keeps reusing passwords. Not ideal, but net improvement. - Bob is using a password manager, but does not use 2FA. Bob decides to set up 2FA, and sticks to using the password manager for storing password. All good! - Charlie is using a password manager, but does not use 2FA. Charlie decides to set up 2FA, and afterwards drops the password manager, and starts reusing passwords. Not good. My guess is the Alice and Bob cases would be the majority. Do you think the Charlie cases would also be common?
- CogitoCogito 3y agoWhile you're at it, you should also consider the scenario pointed out by the gp: > It invites poor disipline with reusing passwords and with 500 pound gorilla corps, losing your second factor is losing your account permanently. https://news.ycombinator.com/item?id=36416392 https://news.ycombinator.com/item?id=36416392
- cuu508 3y agoI take the argument that enabling 2FA increases the risk of getting locked out of the account with no recourse. But I doubt that many people with good password discipline will revert to bad password discipline after enabling 2FA (the Charlie example).
- 3y ago
- tempestn 3y ago"Another interesting question is "Is bad 2FA better than no 2FA?", and the answer to that is a resounding No!" Then goes on to explain why it is indeed better. Perhaps meant to write 'worse'?
- igetspam 3y agoHe addresses this in the comments and confirms that he got it wrong.
- theorangeone 3y agoWoops!
- httpz 3y agoMy company enforced 2FA on our GSuite accounts and discouraged using SMS for 2FA. Well, every year a new iPhone comes out, employees buy the new iPhone and factory reset their old phone. Now their 2FA codes are gone. Only recently Google Authenticator supported backing up to the cloud. Trying to do 2FA correctly is one thing and trying to make your whole company do it correctly is a whole other challenge...
- ThePowerOfFuet 3y agoThis is a poor choice of authenticator app. Bitwarden etc don't suffer from this.
- moralestapia 3y ago[flagged]
- mduggles 3y agoI’m not doing them wrong. They’re a user hostile design. The point of TOTP was just to say “here is an actually good password and a time element to it”. But expecting every user on the planet to carry their TOTP app around was wrong so immediately everyone put it in their password manager and it stopped being a check of whether I had the device. Then the most common TOTP app, Google Auth, didn’t backup your codes so that was pointless and user hostile. They fixed it but I mean damage done I guess. I’m not gonna buy a hardware security key and carry it around for casual usage. I absolutely will never ever do that. For work I will because I need to get paid, but for every login? Give me a break. Once again security cannot destroy the user experience. Here’s the actual right answer. Switch to passkeys and give up on all this poorly thought out junk.
- Encrypt-Keeper 3y agoI mean you still benefit from TOTP if it's in your password manager. That still means that if you're password is stolen, they can't get in without you being on an authorized device.
- rad_gruchalski 3y agoNice blanket statement. After reading the whole article my knee-jerk response is "you think I'm doing 2FA wrong". Good summary, though.
- vidanay 3y ago> Even once you were fully logged in, Facebook would show you a few photos of the same person, and ask you to identify them. Pretty sure this was FB training their facial recognition models.