3 ms·
I wonder if “true multi factor” security requires exclusivity between each factor. So, you cannot “know” anything about the “thing you have”. It should be more
by sixstringtheory 3y ago
I wonder if “true multi factor” security requires exclusivity between each factor. So, you cannot “know” anything about the “thing you have”. It should be more like a yubikey that you plug into your computer and which is secure enough that you cannot get the information out of it to “know” it. That’s a little harder to do for the “thing you are” factor because we can’t design a system to use a feature we can’t understand. And maybe we shouldn’t really “have” the thing we know, as in, it shouldn’t be recorded in something we have. Of course that makes it easier to forget. But then again, I don’t have my 1Password master password recorded anywhere. If I forget it, I’m pretty fucked.
I’ve often considered moving that master password to the frontier of email access and just never recording a password and using password reset for every login session.
Regarding API keys vs passwords, a difference is that API keys are something that are used on your behalf by automated systems, whereas passwords IME are always something you manually input at the time you need it.
- crote 3y ago100%. Storing your "2FA" TOTP tokens in your password manager is asking for trouble, in my opinion. Why put all your bags in one basket? The moment your PC gets owned your are pretty much permanently locked out of all your accounts.
- quectophoton 3y agoI agree, but I'd point out one thing just in case you're using "PC" in a restrictive sense. There's no difference between using a big Personal Computer (PC) like a desktop computer, or a small Personal Computer (PC) like a smartphone. Both are something you have. The problem is not that a bigger computer that never leaves your home is more insecure and that the small computer with a touch screen that actually leaves your home is more secure. The problem is also not storing TOTP in a password manager. Because a password manager can also be used from a smartphone and a TOTP authenticator can also be used from a desktop computer. The problem is using the same device ("factor", if we're being fancy) for storing and reading both secrets, because that means if the device is compromised it'll be able to read both types of secrets. So using a desktop computer for passwords and a smartphone for TOTP, should be just as fine as using a laptop 1 for passwords and a laptop 2 for TOTP.
- kortex 3y agoI'm way more at risk of locking myself out than someone getting onto my system, getting into my password store, exporting secrets, and using them to ruin my life. Honestly it would probably make national news if someone physically burgled their digital identity.