5 ms·
> When I tell people I work on authentication software, I nearly always hear some version of the same story: I hate multifactor authentication. No, really. Peop
by seplox 1y ago
> When I tell people I work on authentication software, I nearly always hear some version of the same story: I hate multifactor authentication. No, really. People hate this stuff.
I hate all of the half-cooked non-TOTP MFA methods that I'm forced to use. Just let me use my freaking authenticator app. If you believe that your users prefer (or maybe it's just you?) more databroker-friendly methods, then fine, but please at least provide TOTP as an option.
- cosmic_cheese 1y agoI wish that banks would offer TOTP. SMS is famously insecure and poorly suited for something that’s a load-bearing pillar in most of our lives, and TOTP is probably the most reasonable replacement. Unfortunately only a tiny handful of US banks offer non-SMS 2FA of any kind, and to my knowledge the one that does (Scwhab I think?) requires the use of a hardware gadget even though it’s standard TOTP (which people have written python scripts to extract the necessary bits of info from).
- toomuchtodo 1y agoFidelity offers TOTP standard support, works with the native Apple Password app/keychain.
- cpburns2009 1y agoOnly recently. They used to require Symantec's authenticator.
- hinkley 1y agoTo this day I'm just amazed that World of Warcraft tried to mandate security tokens in a time when E*Trade barely supported them. Why is a video game embarrassing fintech?
- abdullahkhalids 1y agoWorld of Warcraft was supporting tens of thousands poor teenagers in developing countries, who would farm high value items in the game and then sell the account /items to rich people who didn't want to put in the hard work. There was (maybe still is) lots of money to be made by hacking accounts and selling them. WoW was fintech!
- FirmwareBurner 1y ago>WoW was fintech! WOW was teaching kids how free market capitalism works early on.
- deleted 1y ago[deleted]
- tn1 1y agoSchwab supports Symantec VIP but there's a python package to emulate it, which will give you a regular TOTP setup code.
- riedel 1y agoAt least in Germany all the SMS 2FA has been shut off, but replaced with tons of custom 2FA apps. The security argument is certainly that they can check for 'insecure' devices. But I wonder what the empirical evidence here is and how often (compared to phishing/social engineering) a TOTP token was actually stolen. Worst thing is IMHO Microsoft now which seem to have also shut off the TOTP option and use some other propriatary 2FA scheme now. IMHO banks should simply use FIDO2 HW tokens, but with all that passkey bullshit it becomes unlikely...
- 7bit 1y agoNo it hasn't. How can you make a statement so confident, when obviously you couldn't objectively know?
- nh2 1y agoEvidence to the contrary? For my German banks, this is true. Stupid custom apps and proprietary reader hardware that read coloured moving QR codes everywhere.
- 7bit 1y agoIt's your responsibility to provide evidence for your claims, not everyone else's to prove yours wrong...
- nh2 1y agoYou say "no" to the poster saying "in Germany all the SMS 2FA has been shut off". It makes sense to ask you for evicence: You'd just have to name a bank that provides SMS 2FA.
- GoblinSlayer 1y agoA failure scenario I found is when mitm antivirus decrypts traffic (or something similar), so a proprietary 2fa scheme doesn't work, because it can't get through network.
- esseph 1y agoA passkey is far better than TOTP for security to the point that TOTP should probably be deprecated already.
- lanfeust6 1y agoTOTP still seems good enough for most things
- esseph 1y agoIt's like picking WEP for your wifi https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf https://www.cisa.gov/sites/default/files/publications/fact-s...
- ongy 1y agoAt best WPA2. WEP is broken in ways that don't need human fault. The only downside of TOTP to FIDO and friends (from a security perspective) is phishing resistance
- bigDinosaur 1y agoThat's a pretty major downside to OTP's and certainly not one that can be offhandedly dismissed.
- lanfeust6 1y agoIt is for general population. I don't think HN users for instance are particularly concerned about phishing sites.
- esseph 1y agoZero days exist, and something like tapjacking can be used to obscure and capture those TOTPs. Don't use TOTPs if you have an option to use Passkeys/WebAuthN Short video example: https://taptrap.click/ https://taptrap.click/
- EatFlamingDeath 1y agoYes, for the love of god and all that is holy, just let me use TOTP for MFA. I absolutely HATE that some banks use SMS as a method of MFA. Sometimes it's a mix of 8 character numeric password with SMS as MFA.
- arccy 1y agototp is still terrible, still phishable, more annoying to enter or use. it's only tolerable because it's better than the other methods you might see (email, sms, custom app), but imo it also falls into the half baked category behind things like passkeys.