11 ms·
Auth0 OSS alternative Ory Kratos now with passwordless and SMS support
- DaiPlusPlus 3y ago> SMS support I thought it was well-established that SMS text messages should not be used for authentication purposes? Here's the original feature-request: https://github.com/ory/kratos/issues/1570 https://github.com/ory/kratos/issues/1570 - user @zepatrik raised concerns about this and everyone else just ignored him. Yikes.
- konha 3y agoRight. But for validation they can still be useful if you need a way to prevent (or at least hinder) users to create lots of accounts.
- scaglio 3y agoYes, exactly. SMS should be an option because it is obsolete, and therefore unsecure.
- YetAnotherNick 3y agoEveryone says this here, but no one has shown any concrete proof that SMS could be hacked more easily than say TOTP.
- computerfriend 3y agoSMS is better than nothing, but I personally know several people who had their accounts compromised because their SMS 2FA codes were intercepted. It's not possible to do this with TOTP.
- mooreds 3y agoHow were they intercepted? Was it a sim takeover, where the attacker took over the phone number? Or intercepting the code over the air, since SMS has no encryption?
- computerfriend 3y agoThe latter.
- YetAnotherNick 3y agoHow can I someone see other's messages? Surely someone has step by step guide if it is that easy. Are you sure it was interception without SIM takeover?
- TheNewsIsHere 3y agoIt's not that you can do this just from any old device by flipping a built-in switch, but it's not that different from observing plaintext traffic over an Ethernet network with the right software. There are various ways to nab an SMS. Some are similar to SIM swap attacks in that they rely on social engineering or human or process fallibility to execute [1] [2], and others can grab messages right right out of the air, so to speak [3] [4]. This is in part because one of the foundational protocols that underlie modern cellular networks was never designed with modern security in mind. It's called SS7, and it's been extensively documented as a concern to the security of cellular based communications [5] [6] [7] [8]. Lot's of references because this is an area that has long fascinated me, and I have many bookmarks. There are also some recent papers on this behind paywalls (e.g., [9]). In between the lines and lightly touched on in some reporting is a nuanced point that I think plays a larger part - one issue is that overhauling these older foundational technologies isn't just a matter of commercial and standards changes but also moving the goal posts on where lawful interception happens in the stack, how it happens, and the technologies that support that. For example in the U.S., law enforcement agencies can acquire devices that impersonate cellular infrastructure in order to force communications to go through law enforcement controlled equipment (called IMSI catchers). If we were to revamp cellular networks with a view toward security in the way we probably should, it's reasonable that devices like that wouldn't be feasible without being operated by the telephone companies that own the networks, and that would probably become some amount of red tape that law enforcement doesn't like. [1] https://arstechnica.com/information-technology/2021/03/16-attack-let-hacker-intercept-a-t-mobile-users-text-messages/ https://arstechnica.com/information-technology/2021/03/16-at... [2] https://krebsonsecurity.com/2021/03/can-we-stop-pretending-sms-is-secure-now/ https://krebsonsecurity.com/2021/03/can-we-stop-pretending-s... [3] https://www.firstpoint-mg.com/blog/ss7-attack-guide/ https://www.firstpoint-mg.com/blog/ss7-attack-guide/ [4] https://www.youtube.com/watch?v=RXBvO8TWGsw https://www.youtube.com/watch?v=RXBvO8TWGsw [5] https://www.theguardian.com/technology/2016/apr/19/ss7-hack-explained-mobile-phone-vulnerability-snooping-texts-calls https://www.theguardian.com/technology/2016/apr/19/ss7-hack-... [6] https://arstechnica.com/information-technology/2018/05/nefarious-actors-may-have-abused-routing-protocol-to-spy-on-us-phone-users/ https://arstechnica.com/information-technology/2018/05/nefar... [7] https://arstechnica.com/features/2019/04/fully-compromised-comms-how-industry-influence-at-the-fcc-risks-our-digital-security/ https://arstechnica.com/features/2019/04/fully-compromised-c... [8] https://www.zdnet.com/article/5g-networks-could-be-vulnerable-to-exploit-due-to-mishmash-of-old-technologies/ https://www.zdnet.com/article/5g-networks-could-be-vulnerabl... [9] https://link.springer.com/article/10.1007/s11235-023-01018-0 https://link.springer.com/article/10.1007/s11235-023-01018-0 edit: formatting
- achandlerwhite 3y agoSo they had weak passwords? Or were their accounts recovered/reset via SMS which is prevalent but not 2nd factor login.
- vmfunction 3y agothere are tons of articles here in HN that have shown that SIM swamp (at least in US) is much easier then trying to brute force (or using quantum computer) to break TOTP encryption. One of main reason for SMS is also meta data collection of your number.
- YetAnotherNick 3y agoGive some examples then. I can't find any article.
- rad_gruchalski 3y agoYou haven’t looked for any proof: search for sim cloning.
- YetAnotherNick 3y agoIn the first link: > In SIM cloning attack, the fraudster gains access to the victims physical SIM card and.. Same thing could be done with TOTP.
- rad_gruchalski 3y agoIt’s not the same. The explanation you quote is wrong. This is the correct one: > SIM cloning is the procedure through which a genuine SIM card is reproduced. When the cloning is accomplished, the cloned SIM card’s classifying information is transported onto a separate, secondary SIM card. The secondary card can then be used in a different phone while consuming all the calls and related charges credited to the original SIM card. https://fraud.net/d/sim-cloning/ https://fraud.net/d/sim-cloning/ There is no need to have physical access.
- vbezhenar 3y agoYou can use social engineering (or corrupted workers) to issue SIM card for other people and receive SMS. This method is widely used to steal money from bank accounts in my country. Telegram accounts also known to be stolen this way. Of course you should be located in the same country. But it's a risk nonetheless.
- Hamuko 3y agohttps://www.theverge.com/2019/8/31/20841448/jack-dorsey-twitter-hacked-account-sim-swapping https://www.theverge.com/2019/8/31/20841448/jack-dorsey-twit... https://www.axios.com/2024/01/22/sec-hack-twitter-x-sim-swap https://www.axios.com/2024/01/22/sec-hack-twitter-x-sim-swap
- Terretta 3y ago> no one has shown any concrete proof that SMS could be hacked more easily On the contrary, here is an empirical study demonstrating 100% of the 5 major carriers in US used insecure authentication challenges that can easily be subverted by attackers: https://www.issms2fasecure.com https://www.issms2fasecure.com
- arekkas 3y agoYes, this is definitely true. However, there are use cases and companies who rely on SMS based two-factor: - Using SMS for phone verification - Using SMS for mobile login (think dating apps for example) - Using SMS for two-factor where other factors are not available / convenient (often in emerging markets) SIM Swap Attack, SIM Port Hacking are all real, but as always in security it comes down to your threat model to decide what's acceptable risk and what isn't. Hope this makes sense (maintainer here).
- asdaq1312512 3y ago> - Using SMS for mobile login (think dating apps for example) Dating apps in particular seem to be a problematic example to me. In some regions, phone numbers change owners quite easily (e.g., no possibility to port a phone number to a new contract, and quick re-cycling of the phone number when a contract is terminated).
- zinekeller 3y agoTo be fair, it really depends on the region you're operating. Some regions (like most places in Asia) use this as the primary identifier (instead of email), so despite the very obvious security flaws you might be simply be forced to offer it.
- jhugo 3y agoRight, by this point the global norm is to rarely, if ever, use email (or a computer larger than a smartphone) unless you work in an office (and in some places not even then). The phone number is the primary identifier for mass-market apps in most countries.
- ravenstine 3y agoPlus you have to consider the amount of support you inherit when using something less universal (and generally fool-proof) than SMS. "The one-time code won't work!" "The authenticator app doesn't work!" "The email takes forever to arrive!" "I never got the email!" Most of that sort of thing goes away with SMS. It's not that SMS never fails, but every mobile device takes it, it's relatively simple, and very reliable. An alternative approach may be more secure, but require more hand holding, and not every organization wants to do that. In a similar vein, it's not necessarily prudent to do everything that infosec experts espouse. For an analogy, businesses should consult lawyers, but if they follow every bit of advice from a zealous lawyer, they might never take necessary risks that allow the business to achieve excellence; as well, they may need to dedicate substantially more time and effort on compliance.
- OJFord 3y agoYes, but if you want large enterprise customers such as regulated financial institutions where lots of money's at stake, you will need to support SMS as a second factor, mothers' maiden names, and bypassing all that when the user has forgotten.
- andix 3y agoInteresting, in the European Union SMS token are mostly illegal for financial services, because they are not considered safe enough.
- TheNewsIsHere 3y agoIt would be lovely to have that in the U.S., but I doubt it will go anywhere anytime soon. I'm sympathetic to the reasons. The U.S. has a massive population of people who for various reasons will not or cannot adopt methods other than SMS, if that. Meanwhile you can call up some of our largest financial institutions and impersonate someone with public-record knowledge. Many organizations will allow you to skip any kind of over-the-phone SMS challenge by asking for -more- publicly available knowledge to "better"/further authenticate the caller. And of course all our Social Security Numbers are effectively all out there, and those are still the de-factor identifier where a phone number is not. I used to do business with Vanguard. Several years ago they rolled out U2F-then-WebAuthn support so you could use a Yubikey or other FIDO2 compliant token as your MFA method. They allowed you to disable SMS MFA if you did that. I happily enabled that. Within two years, they re-introduced a requirement to enroll a number for SMS MFA on the grounds that their mobile app only supported codes delivered by SMS, and there was no opt-out. If you didn't enroll a number you'd be locked out and have to call customer service to add a number and reset your password.
- andix 3y agoStill funny to hear that everyone in the US has a social security number, although there is no public healthcare for everybody. And I always thought it's the land of unlimited freedom, doesn't seem to apply to privacy. I have a social security number too, but I need it to get free (actually less expensive) healthcare. Not for opening a bank account. I think in my country nobody except health care is allowed to process social security numbers, because it's considered private information. They are not allowed to store them. If they get them by accident they need to delete them ;)
- mooreds 3y agoSMS has problems, it's true. But every MFA method for consumers has issues, and for some applications it is a viable solution. I wrote more about that here: https://ciamweekly.substack.com/p/ciam-mfa https://ciamweekly.substack.com/p/ciam-mfa
- achandlerwhite 3y agoI think it’s biggest problem is when used for account recovery and password reset, not login 2nd factor.
- lucideer 3y ago> I thought it was well-established that SMS text messages should not be used for authentication purposes? Using SMS text messages for 2FA is barely better than 1FA, but it is better. There's a lot of value in discouraging what many see as the easy option, especially when the alternatives are getting users to install extra apps (or even buy hardware keys of some sort), so the scaremongering around SMS is warranted, but it's still absolutely better than nothing.
- andix 3y agoIt depends. Using SMS as a second (!) factor is fine. There are better options, but SMS is much better than no second factor at all. What you absolutely shouldn't do is allowing password reset only via SMS token, because it's often not that hard to get access to SMS codes via social engineering (convincing a store clerk to issue a new SIM card, or stealing a phone and getting the code displayed on the lock screen) Having SMS as second factor requires the attacker to know the password AND do some social engineering. It's a significant security improvement over password only. SMS might even be safer than password less passkey login, if the user's passkey implementation is unsafe. It's possible to store passkeys in password managers, and people regularly manage to get their vaults compromised. This might only require a keylogger on a PC where the user logs in to the password manager.
- achandlerwhite 3y agoThis. I wish this distinction was recognized more.
- andix 3y agoSadly people are like sheep. They hear SMS and shout unsafe.
- Rodeoclash 3y agoThis is a massive release, well done! I run Kratos and Oathkeeper self hosted on ECS for our onboarding app (Xero only in Australia for now I'm afraid, xonboard.com.au). Works like a dream for the most part. One thing which was very painful was adapting the custom UI. I started with an existing example project and adapted it but it was a confusing mix of server code and CSS in JS which made it very difficult to "get at" some of the HTML / CSS. Any movement on that front with the project?
- arekkas 3y agoOur roadmap for this year has a revamped Ory Elements v2, which will make this a lot less painful!
- doctorpangloss 3y ago> One thing which was very painful was adapting the custom UI. I started with an existing example project and adapted it but it was a confusing mix of server code and CSS in JS which made it very difficult to "get at" some of the HTML / CSS. I cannot wrap my mind around why the vendors don't separate the UI and backend application; and then in the UI project, author it in something ubiquitous like React.
- PlutoIsAPlanet 3y agoIs this comparable to Authentik?
- rad_gruchalski 3y agoIt’s not really an alternative to Auth0. It’s certainly a component of an alternative to Auth0.
- yladiz 3y agoThis isn’t very substantive, can you go into more detail about what’s missing?
- vinckr 3y agoOry Kratos is an identity management solution with MFA, passwordless, WebAuthn and so on, so I would argue for most use cases it alone is comparable. But there are two more Ory services; one for permissions / authZ and an OAuth2 server. You can make use of those to cover the full range of authN/authZ use cases.
- v3ss0n 3y agoOry Kratos is so complicated .Authentik is much simpler and easier.
- arekkas 3y agoWe have worked quite a lot on making Ory Kratos easier to consume. In the release notes you find ~4 CLI commands you can use to get a fully working Ory Kratos up and running, with all UIs and configuration management :) You should give it another try!
- v3ss0n 3y agoI will give a try. Back in 2023 it's very complicated to build own web application backend and frontend with it so we ended up choosing Authentik.
- aidos 3y agoSeems like a good place to ask: Does anyone have advice on good solutions for B2B SAAS apps? Just our app that needs logging in to and would like to allow the usual things (password, social etc) but also allow customising the rules per email domain. For example, if someone enters someone@example.com in to the login form they'll be shuffled off to this Azure connection for authentication. Or maybe they use our login pages, but MFA is enforced. Things that I've tried (eg Authentik and FusionAuth) weren't well suited for per organisation controls.
- arekkas 3y agoWe have this feature and it is called B2B SSO: https://www.ory.sh/docs/kratos/organizations https://www.ory.sh/docs/kratos/organizations
- aidos 3y agoInteresting. Any more details available on what’s configurable? How does it work out pricing wise?
- arekkas 3y agoThe flow is essentially what you see in the small video on the docs page and can be set up in the Ory Network Console with a few clicks. I agree though that the docs here are a bit thin. Pricing wise this is available on the Scale tier currently dubbed as "Enterprise SSO" although "B2B Organizations" probably would be more correct: https://www.ory.sh/pricing/ https://www.ory.sh/pricing/ There are no limits to how many organizations you can have. Regarding MFA - the MFA enforcement typically is the responsibility of the IDP the company owns. So for example dean@companyA.com use Okta and they enforce 2FA for their users. anna@companyB.com use OneLogin and they do not enforce MFA.
- aidos 3y agoThanks. In terms of other enforcement, I meant more wrt to an organisation that _didn't_ use another IDP but still wanted to apply PW policies (for example) on their domain. Could you create an Ory project (sorry, don't know all your terminology) to forward on to? Something like: Our app -> Ory -> split by domain -> Ory for specific domain -> Policies.
- notorandit 3y agoSMS? Really?
- buro9 3y agopasswordless via email is the single thing that I've been waiting for, once I integrate this I can disable Auth0 and still support the OSS SaaS forum platform — this previously required an Auth0 account, and has sent Auth0 at least 10 medium sized customers.
- fuomag9 3y agoUnfortunately this is not comparable to authentik for me, it looks like it’s only for applications you’re developing and not already implemented solutions
- mooreds 3y agoWhat do you mean? I think it supports oidc endpoints? https://www.ory.sh/docs/oauth2-oidc/authorization-code-flow https://www.ory.sh/docs/oauth2-oidc/authorization-code-flow indicates this.
- mooreds 3y agoCongratulations, this is a big release. Some great features in there. Love the phone number as a first class citizen, something we've been considering for a while. (I work for a competitor, FusionAuth.) I noticed account linking, between social accounts and existing accounts, based on email matching, was a new feature. It's documented here: https://www.ory.sh/docs/kratos/social-signin/link-multiple-provider-account https://www.ory.sh/docs/kratos/social-signin/link-multiple-p... I believe. The document walks through the "linking an existing account with a password to social account" scenario. I was wondering if there was also the ability to go the other way, from an existing social account to adding a password? How do you handle the case where Alice signs up with a username of alice@example.com but later wants to link alice@gmail.com? I also wonder if you can block account linking on a per user basis or if it is enabled for everyone in a system. We've had account linking for a few years (documentation here: https://fusionauth.io/docs/lifecycle/authenticate-users/identity-providers/#linking-strategies https://fusionauth.io/docs/lifecycle/authenticate-users/iden... ) and have had customers bring up some edge cases like this.
- Sytten 3y agoMy experience is that in general edge cases are not kratos strong suit. Works very well for the base case but anything fancy you are generally on your own. But I don't mind since it is OSS and someone can contribute/fork if they it.
- esafak 3y agoWhat edge cases did you run into?
- arekkas 3y agoWe do have all edge cases brought to us solved in terms of account linking and the recent changes further improve the user experience in these scenarios. There are many credential types around these days from passkeys to OTP codes to passwords and OIDC. The biggest challenge is always ensuring the flows are secure which is the hardest part in our view. ps: I find it a tad frustrating that on every Ory post FusionAuth is shilling in the comments, even if the comment is tangential but clearly intended (through links and name dropping) to draw attention away. It would be much better if FusionAuth focused on releasing open source themselves and truly contributed back to the security community instead.
- mariusor 3y agoI always wanted to use Kratos for my own open-source projects, but I never got far enough into the researching how support for adding different storage options is. My project supports multiple storage back-ends (mostly around document storage) and I would like to get Kratos to query the same ones, even if it requires dev work on my side to add support.
- Sytten 3y agoBeen using it in production for a bit less than 2y now. It has improved a lot, the configuration is still kinda hard (jsonnet is really ugly IMO) and there are a lot of weird decisions (like you can change the password without knowing the current password if you have login within the last X minutes even coming from a social provider) but overall it is a solid contender in the space now.
- sneak 3y agoNote that this software unethically phones home with your usage data without your consent. Such opt-out, on-by-default spyware exfiltrates your data silently. They claim it’s anonymous, but that’s false as it includes your client IP address, which frequently maps directly to physical location. You have to patch it out, because even if you try to turn it off, it still phones home in violation of your expressed wishes: https://www.ory.sh/docs/ecosystem/sqa https://www.ory.sh/docs/ecosystem/sqa > Disabling telemetry doesn't have any downsides, except for us not being able to improve the project. Note that Ory always sends minimal ping with version information once on start up. Why do people feel entitled to spy on users of the software they gave away? I would never, ever even consider using their SaaS, or that of any other company these founders ever run. https://github.com/ory/x/blame/master/metricsx/metrics.go https://github.com/ory/x/blame/master/metricsx/metrics.go Kevin Goslar, formerly of Google (per his GitHub profile), is the one that committed this code (per the history publicly available on GitHub). It is somewhat unsurprising that free software at his new startup follows the same ethical framework regarding nonconsensual surveillance as the world’s largest advertising surveillance company where he used to work. The trend of open source spyware is increasing. We need to be more vigilant both about the presence of spyware in open source software, as well as being mindful of the people who engage in such unethical practices. (For instance, Mattermost is another offender in this category.)
- vinckr 3y agoIf you look in the source code for this software which is provided for everyone to see you will realize that Kevin Goslar is entirely innocent of this heinous crime. He merely added the copyright headers to each file. You misunderstand the purpose of the SQA telemetry. There are some reasons for SQA telemetry listed in the doc you posted: - Be able to say how many production deployments exist. - Understand which features are used and how. - Understand how much throughput deployments handle. - Evaluate how frequently specific features are used. - Detect issues introduced by new features (such as a buggy releases). - Identify problems at scale (such as slow endpoints). - Understand which versions are deployed. If you have concerns about privacy as you rightly noted you can turn it off with a simple flag (--sqa-opt-out) and if you don't like the version ping you can block in your network. Hundreds of users are running Ory Kratos without any telemetry sent without any extra work. So if this is a plot to produce open source spyware it's not the best.
- jillesvangurp 3y agohttps://securityboulevard.com/2021/12/why-using-sms-authentication-for-2fa-is-not-secure/ https://securityboulevard.com/2021/12/why-using-sms-authenti... SMS is an anti feature at this point. This just moves the problem. Arguably email is actually better than SMS and that's not saying much. It's the difference between getting stabbed and shot. What's the most common thing that people have stolen: wallets and phones. Lots of people have cheap phones, pre-paid sims, or worse. Tying your identity to some phone number that should be treated as temporary only to get locked out of your account some years later is just not great. Here's a list of reasons people change phone numbers: - they have a prepaid number and they switch to a different provider - they travel and use a different sim while traveling - they change job and lose access to their employer provided phone - they change operator and the operator declines to take over the old number (happened to me in Germany) - their phone number ends up on some list of scammers and to get out of the non stop spam by simply getting another number
- manishsharan 3y agoI discovered another reason to avoid SMS OTP: I am currently visiting India and I have put my phone in Airplane mode because my Canadian phone company , Rogers,charges $15 per day for roaming and it is simply cheaper to buy an Indian SIM card and use it on an old phone to act as a wifi hotspot for my actual phone. So while my phone is in Airplane mode, I am unable to use my RBC Visa or MasterCard for any online purchases in India as there is no way for me to get the SMS OTP without paying Rogers the CA$15 .
- moi2388 3y agoMagic links to email and sms, which are unencrypted, for signup and login, account linking and then converting the session cookies to valid jwt? I smell a CVE within a year.
- toomuchtodo 3y agoAll password resets lead back to email.
- js4ever 3y agoOry Kratos is using 7 docker containers to run, seems super heavy compare to Keycloak that will run with just 2 containers. What is justifying the bloat?
- belthesar 3y agoI looked at using the Ory stack when they were much younger, and had some chats with their team. Ory builds everything with the expectation that you're a large enterprise, where service classes and systems are expected to be scaled. They're also pretty big k8s adopters, so they all but expect that you want to run your workloads in a large environment. Great for folks that are bringing Auth* home from Auth0/Okta, etc, as scaling for each app class is right there, but also a much more complex stack to begin with. That said, where are you seeing 7 containers? I haven't grabbed the repo to run it, but their quickstart instructions use config overlays to manage specific configs, and none of the examples looked like more than 5 containers, 4+ your database, with 1 of them being a dev mail endpoint. Separating tasks out to 3 different services, frontend, backend, and DB migration, doesn't seem super big to me.
- hsluoyz 3y agoCasdoor has SMS support long ago: https://casdoor.org/docs/category/sms https://casdoor.org/docs/category/sms Casdoor is much more way powerful than Kratos: https://casdoor.org/ https://casdoor.org/