3 ms·
If you have a hardware second factor that does not require user interaction (or that has a low-security tier that does not require user interaction), couldn't t
by usrusr 3y ago
If you have a hardware second factor that does not require user interaction (or that has a low-security tier that does not require user interaction), couldn't that be used to transparently re-validate existing sessions with zero inconvenience cost? Keep challenging that factor with the existing session and a nonce. Am I missing something?
And even if you don't have that, when authentication is your core business you might want to harden your sessions against transmission contents getting in the wrong hands by setting up an additional factor in the browser's local storage that gets challenged without putting the key on the wire. Sure, that local storage is no secrets vault, but you don't write some existing secret there, you set up an additional key that would protect e.g. from a .HAR playback. That's the nature of multi-factor tiered defense, protection from just one angle is protection nonetheless, perfect must not be the enemy of good.
- insanitybit 3y agoThat's actually what GSuite's Context Aware Access does if the downstream service supports it (GSuite does, ofc). It will rechallenge your client on every request (client can cache). Exfil of the token won't work if that challenge includes hardware verification.