4 ms·
That sounded scary, but after reading into the Retool breach (thanks for pointing it out), it doesn't sound like Google Authenticator is completely to blame. R
by ckcheng 3y ago
That sounded scary, but after reading into the Retool breach (thanks for pointing it out), it doesn't sound like Google Authenticator is completely to blame.
Retool points out the "attacker was able to navigate through multiple layers of security" [0], i.e.:
1. "through a SMS-based phishing attack" on "Several employees"
2. "one employee logged into the [SMS phishing] link", "logging into the fake portal"
3. "attacker called the [phished] employee" "and deepfaked our [IT team] employee’s actual voice"
4. "the [phished] employee grew more and more suspicious, but unfortunately did provide the attacker one ... (MFA) code" (over the call)
5. "The additional OTP token shared over the call was critical, because it allowed the attacker to add their own personal device to the employee’s Okta account, which allowed them to produce their own Okta MFA from that point forward."
6. "This enabled them to have an active GSuite session on that device." With "Google Authenticator synchronization feature that syncs MFA codes to the cloud", "if your Google account is compromised, so now are your MFA codes".
By #5, I'm thinking GA sync is about as blameworthy as Okta for allowing a device to be added with just a single additional OTP token shared over a phone call?
Here's a different perspective (tptacek) [1]:
>> We use OTPs extensively at Retool: it’s how we authenticate into [Google, Okta, internal VPN and Retool]
> They should stop using OTPs. OTPs are obsolete. For the past decade, the industry has been migrating from OTPs to phishing-proof authenticators: U2F, then WebAuthn, and now Passkeys†. The entire motivation for these new 2FA schemes is that OTPs are susceptible to phishing, and it is practically impossible to prevent phishing attacks with real user populations
> TOTP is dead. SMS is whatever "past dead" is. Whatever your system of record is for authentication (Okta, Google, what have you), it needs to require phishing-resistant authentication.
> My only concern is the present tense in this post about OTPs, and the diagnosis of the problem this post reached. The problem here isn't software custody of secrets. It's authenticators that only authenticate one way, from the user to the service.
[0] https://retool.com/blog/mfa-isnt-mfa https://retool.com/blog/mfa-isnt-mfa
[1] https://news.ycombinator.com/item?id=37503551 https://news.ycombinator.com/item?id=37503551
- lxgr 3y ago> it doesn't sound like Google Authenticator is completely to blame. I don't think anyone would seriously claim that, but I think it's fair to call it an unfortunate additional hole in the swiss cheese.
- ckcheng 3y agoI only started reading into the Retool case because there was the claim above that sounded serious and scary: > Google Authenticator started syncing secrets to the cloud[0] which means that those secrets can now be accessed in new ways outside of the user's control[1], which resulted in a huge breach at a startup called Retool[2].