3 ms·
> ... but the real-world value here is overstated. Malware can always just steal your tokens. Stealing a TOTP secret means being able to generate all the token
by TacticalCoder 2y ago
> ... but the real-world value here is overstated. Malware can always just steal your tokens.
Stealing a TOTP secret means being able to generate all the tokens. Which allows, for example, to take over an user account and lock the legitimate user out of his account. MITMing a single U2F/FIDO2 allows you to... log in? From one of the system uses to access his account (the one that's compromised).
I've got sites where the FIDO2 to log in and the one to change any security setting require two different security keys. And even when it only requires one security key, the procedure to take over an account requires several tap on the physical security key. A savvy user won't be tricked into tapping his security key for no reason.
Let's take, say, a brokerage account. There's a security key for withdrawals. Without that security key an attacker would be MITMing me by stealing one token could... Consult, what, see my balance and trade for me!? But he still wouldn't be able to steal a cent (and my account ain't big enough to move the market).
The real-world value of an HSM sitting on a device with a tiny attack surface has a lot of value.
The very reason they exist being that compromised computers are a thing. Compromised Yubikeys are not.
- FreakLegion 2y ago> MITMing a single U2F/FIDO2 allows you to... log in? You mean token theft? Most sites let you add factors without step-up auth once you're logged in [1]. That's what attackers prefer to do, vs. locking users out, which just gives away the game. To be clear, end-running around hardware keys with stolen tokens isn't hypothetical. See for example the fallout from the last Okta breach at Cloudflare: https://blog.cloudflare.com/thanksgiving-2023-security-incident https://blog.cloudflare.com/thanksgiving-2023-security-incid.... I make my team use YubiKeys, but there's no upside to being naive about what they are and aren't good for. Anyway the kinds of sites you're describing are vanishingly few. What people mostly have to deal with are sites like Fidelity's. If you want something other than SMS or push notifications, you have to call Fidelity on the phone, and then all you get is Symantec's bloated wrapper around TOTP. 1. It's even the default in some major identity providers, like Microsoft's (https://learn.microsoft.com/en-us/entra/identity/conditional-access/howto-conditional-access-policy-registration https://learn.microsoft.com/en-us/entra/identity/conditional...). Okta is better, but then their default session length is forever, so moot point.