5 ms·
unpopular thought perhaps, but with this many companies/teams mandating MFA (especially to technical people, who should already know how to create secure passwo
by superq 3y ago
unpopular thought perhaps, but with this many companies/teams mandating MFA (especially to technical people, who should already know how to create secure passwords, not use them on more than one site, not spread them around, etc):
The pressure of all of these MFA inputs, especially for products that expire them even on a trusted device/browser, is eventually going to push people into the arms of convenient "password managers".
This will effectively nullify the 'something you have' in MFA because it'll all be available on your one single device again.
Even worse, it'll present multiple high-value targets now, from the centralized server/sync side (ie lastpass) down to individual devices.
Put another way: if you're storing the passwords in the same place as the MFA secrets, then it's not actually MFA anymore.
It's not that PyPI is wrong to do this, it's that the weight of everyone mandating MFA will eventually either push people away or force them to work around draconian or onerous security requirements.
- mplewis 3y agoWhen someone stores their MFA credential in a password manager, that only means that in the worst case, they are as insecure as someone with no MFA – right? This doesn't seem like a big problem to me for two reasons: 1. if they're using a password manager, they are likely to be using a better password 2. it's much more likely that someone has intercepted a single static password for a single website than, say, your 1Password vault password AND username AND secret key
- saithound 3y ago> When someone stores their MFA credential in a password manager, that only means that in the worst case, they are as insecure as someone with no MFA – right? Even if this was right (which I don't think it is under the threat model described by the OP: they claim, rightpy or wrongly, that the attack surface somehow increases when everybody adopts MFA), consider the protocol where you have to enter your password and cut off a lock of hair to authenticate. In the worst case, this is as insecure as someone who just enters their password without any hair cutting, but doesn't mean that adopting it would not be a big problem, or even a good thing overall (at the very least it would massively inconvenience bald people; there are parallels, it's not like MFA does not inconvenience certain people).
- xavdid 3y ago> if you're storing the passwords in the same place as the MFA secrets, then it's not actually MFA anymore. I see this sentiment a lot and IMO it over-simplifies the security model pretty drastically. It's unlikely that a 1P vault is breached or leaked. For most people, the most likely threat vector for a random internet account is: 1. they re-use a password across sites 2. one site gets breached and that password is included in a hash dump (probably associated with their email) 3. one the hashes are broken, an attacker can try that password on another site In this situation, MFA stored in their password manager is still MFA because the TOTP secret wasn't leaked with the password (or it was and then it doesn't matter where you store it on your end). The only case in which storing MFA secrets with your passwords becomes an issue is if other people have access to your laptop (and password manager). Then you'd probably want passwords on the laptop and MFA on your phone (or something else kept on your person). Nobody questions leaving a yubikey in a laptop (which is also full of passwords). Even if doing so means anyone with your laptop can use your yubikey, it narrows your attack vector from "anyone who got your password" to "anyone with physical access to your laptop", which is a great reduction in scope (for most people).
- mschuster91 3y ago> The only case in which storing MFA secrets with your passwords becomes an issue is if other people have access to your laptop (and password manager). Then you'd probably want passwords on the laptop and MFA on your phone (or something else kept on your person). The problem is that a lot of the major package managers - at least nodejs npm/yarn, PHP composer, Apache Maven, Gradle - allow code execution of whatever packages were specified as part of the installation or build process. That means there are an equal lot of very juicy targets for a takeover - just look at the most popular build plugins... and a few minutes are enough to deploy a keepass and browser credential store stealer to a ton of people. Getting local code execution isn't that difficult if you manage to spray your payload over a huge enough area. Getting access to a target and their MFA device however is vastly more complicated.
- bombolo 3y agopypi doesn't require 2fa to upload. They use 2fa to login onto the website and make you create a token. After that you just save the token within your project and have a script to upload new versions.
- insanitybit 3y ago> Put another way: if you're storing the passwords in the same place as the MFA secrets, then it's not actually MFA anymore. Sure, but PyPI was also giving away yubikeys. Also, you're assuming that the compromise involves fully owning a device instead of the much more common case of phishing/password reuse.
- Tainnor 3y agoIMHO, there's a bit of confusion around terminology here. People aren't really mandating "MFA" unless they're requiring Yubikeys or something. But they are requiring TOTP, and adding TOTP to your login flow does mitigate certain kinds of attacks (though, of course not others). So maybe we should just be more honest about what we call things. "True" MFA is too inconvenient for most people - even banking apps are not only happy to let you log in from exactly the same device that they will send verification codes to, they usually make more secure workflows more of a pain too. But we're still gaining some additional security by having one-time codes that can't as easily be stolen without having access to the device.
- rightbyte 3y agoYe what happened to those designated code boxes the banks handed out? Seems like a almost fool proof device. Airgaped too.
- xmcqdpt2 3y agoYou mean like RSA SecurID? https://en.m.wikipedia.org/wiki/RSA_SecurID https://en.m.wikipedia.org/wiki/RSA_SecurID AFAIK they are still in common use in high security environments. I have one for work, but we are supposed to eventually migrate to phone-based token generators.
- tialaramex 3y agoDevices like this are basically TOTP reified. I mean, they aren't literally the TOTP protocol the technology is different, but it's a secret value (baked into the device) which is combined with a clock and a decent hash to produce predictable values over time. A kilt is a skirt, my sister isn't wearing a kilt but if you haven't seen any other skirts then "It's basically a kilt" is a pretty fair description. RSA is embarrassing because they kept the fucking secret values. As a result it was strictly worse than just getting whatever cheap knock off you can purchase. I believe their rationale was if they keep these values when a customer inevitably goes "Oh, oops, we lost the values" instead of "Too bad, now you own useless bricks, buy more" you can "Help" them by providing the secret values again. But that ought to be the very stupidest idea from a security company if only there weren't so many other embarrassing stories. In 2011 they suffered "an extremely sophisticated cyber attack" aka basic phishing, and bad guys are assumed to have stolen the complete database. So, that's not great.
- predictabl3 3y agoI'm sorry, no, I'm not remotely sorry. It's not hard to carry a Yubikey. Period, done.
- Caligatio 3y agoIt actually is hard to carry a Yubikey and, more importantly, use a Yubikey. Some employers don't allow personal USB-like devices in the building nor plugging them into company owned computers. I say this as someone that has several that are used at home but needs to use personal TOTP codes at work.
- jjgreen 3y agoHaving two single factors is obviously more secure than one, and three, ten, fifty, all the better. That's why the name was changed from 2FA to MFA.
- vladvasiliu 3y agoWhile I can see the merit in discussing the issue of where to store the second factor, what I see much less often discussed is the story on the "tooling" side. For example, on PyPI, to upload stuff, you need to generate a token. Now you have effectively a single factor, which requires as much care as a regular password.
- di 3y agoThis is why PyPI recommends using Trusted Publishing (https://docs.pypi.org/trusted-publishers/ https://docs.pypi.org/trusted-publishers/) which removes the need for long-lived tokens entirely.
- yodelshady 3y agoFor the vast majority of services, dump the passwords requirement then. Physically stealing a token from me is a much riskier, less scalable attack than slinging hashes from someone's hobby site into GPUs.
- tialaramex 3y agoAlso outside of Hollywood movies there's not a great intersection between people who are great at this sort of hands on crime (e.g. robbery, pick pocketing) and the high level strategy needed to want a specific person's MFA token. Tom Cruise would play a character who does that (and rides a motorcycle, obviously) but in the real world it's not a thing. Unlike car keys the tokens don't even know what they're for. You can walk around a car park with keys and match the car, these days it'll even remotely blip the lights - but if you have some random guy's Yubico Security Key, you don't even know if he uses Facebook, Google, PyPI, or what, let alone what the account's username/ email might be. Good luck.