32 ms·
MFA always feels like such a kludge... Do we really have no better ideas to solve this?
by RedShift1 3y ago
MFA always feels like such a kludge... Do we really have no better ideas to solve this?
- whizzter 3y agoThere's an RFC for a standard that I believe the Google Authenticator uses (and other authenticators also?). Basically (if I've understood it correctly), You get an random seed that you initiate the authenticator with, then for (each minute?) it combines the unix timestamp, the seed and calculate the time-based-one-time-password. So combining a user-specific password, the TOTP (whose seed is on an initiated device for the user) you have 2 factors that can be hard for an attacker to retrieve both of. https://datatracker.ietf.org/doc/html/rfc6238 https://datatracker.ietf.org/doc/html/rfc6238 (Kludgy? Maybe a bit but feels fairly secure in practice)
- oldbbsnickname 3y agoHOTP (one-time) and TOTP are typically used in conjunction with one another. HOTP provide backup codes should client or server time be out of sync. https://www.rfc-editor.org/rfc/rfc4226 https://www.rfc-editor.org/rfc/rfc4226 FIDO2 with a hardware key source provides a much stronger and more secure guarantee than a 6 digit hash and an unencrypted symmetric secret stored in an app. https://fidoalliance.org/fido2/ https://fidoalliance.org/fido2/ Any and all 2FA approaches demand backup codes (and backup code management with confidentiality and durability) to protect against 2FA loss or inability of the 2FA to function. For example, there are some apps that insist on performing FIDO2 on a non-NFC platform. While I can use a Lightning to USB-C adapter to workaround this limitation, it's possible that I might not have it and would need some other 2FA "sufficient" mechanism. By the way, there is "HSM"-like passkey functionality embedded in most modern Apple and Samsung devices that doesn't require a USB token. This has the downside of not being a dedicated hardware token, so it cannot be physically isolated offline and requires an additional piece of software to act as a FIDO2 authenticator.
- lll-o-lll 3y agoWhat sucks is that password’s don’t need to be so insecure. If you took WebAuthn and, instead of the private key, used one password, it’d be nearly as strong. Assuming that one password is sufficiently strong, and the password input could not be intercepted, and no one ever looked over your shoulder, or used a camera, and you never wrote it down somewhere others can find it, and you never typed it where someone had installed a key logger… Actually, let’s bring on the passkeys.
- oldbbsnickname 3y agoWell, your "feeling" is misleading. TOTP relies on correct time within a certain interval of grace period. The problem is the fault of Synology lacking a correct internal timekeeping source and the fault of paying money for other people's closed-source, faulty hardware. I have a Linux NAS running on a type-1 VM with passthrough to the actual disks. It also has TOTP when connecting over ssh but never has a problem because the hypervisor maintains the clock for all VMs and the on-board hardware clock is operable and has a battery.
- lazide 3y agopasskey theoretically. Passwords are so terrible with the way they're typically used and deployed (and now there is enough widespread value in compromising accounts at scale), that MFA went from a niche 'high security' edge case to, well, our current UX disaster. For high security needs, you'd still want MFA + passkey.
- lll-o-lll 3y agoPasskey is MFA isn’t it? Or at least, the site can demand it? You have to do the “fingerprint” or “pin” as the second factor when authenticating…
- lazide 3y agoNo. It’s an authentication method, any pin or whatever you enter is you unlocking your local auth store to allow the passkey to be used. That pin or whatever is not part of the actual authentication. Someone could have an auth flow with a password + passkey + say SMS mfa if they wanted to be a jerk. Or just use a passkey.
- lll-o-lll 3y agoWebAuthn has the concept of “User Verification” (optional demand). https://developers.yubico.com/WebAuthn/WebAuthn_Developer_Guide/User_Presence_vs_User_Verification.html https://developers.yubico.com/WebAuthn/WebAuthn_Developer_Gu... Looks like multi-factor to me.
- lazide 3y agoPasskey != webauthn Enjoy - https://teampassword.com/blog/passkey-vs-webauthn https://teampassword.com/blog/passkey-vs-webauthn
- lll-o-lll 3y agoOr as a counterpoint: https://support.apple.com/en-au/102195#:~:text=Credential%20security,which%20uses%20public%20key%20cryptography https://support.apple.com/en-au/102195#:~:text=Credential%20.... We are now literally arguing semantics.