4 ms·
It's not so much that it's "more" in the sense of more of the same, like, e.g. requiring 2 different passwords. That's a waste of time. But 2FA makes the attack
by mindprism 3y ago
It's not so much that it's "more" in the sense of more of the same, like, e.g. requiring 2 different passwords. That's a waste of time. But 2FA makes the attackers job much more difficult. If someone steals my password or compromises a key, then they still need to hijack my SIM for SMS or steal my phone to get a code from my authenticator app. That's 2 completely different kinds of shenanigans that need to be successful.
- the_snooze 3y agoHow would a key compromise look like? A server-side key compromise just gives you public key material, which is useless. A client-side key compromise gives you an encrypted private key, but you've completely owned the client at that point so you've won already regardless of how weak or strong the authentication method is. Traditional server-side 2FA (e.g., "give me a password and a 1-time code") is superfluous in a passkey world, because it's ultimately just a hack to make up for the fact that password-only auth is weak. Key auth is incredibly strong, so a server-side 2FA challenge doesn't buy you much.