3 ms·
This was an easy choice for us when we setup two-factor auth for our app. We chose TOTP. The only real con (if you can call it that) is requiring the user to in
by sehrope 13y ago
This was an easy choice for us when we setup two-factor auth for our app. We chose TOTP. The only real con (if you can call it that) is requiring the user to install a TOTP app (eg. Google Authenticator) but given our target userbase that was a non-issue.
Here's a quick summary of pros/cons:
TOTP pros:
* Assuming the initial secret is delivered securely (eg. HTTPS) no MITM vulnerability
* Free as in beer
* Simple to implement
* Instantaneous
* No additional personal information asked of user[1]
TOTP Cons:
* Requires user's to install an app or have a physical TOTP device
* Clocks must be kept in sync[2]
Phone SMS pros:
* Nothing to install assuming your user has a phone
Phone/SMS cons:
* Not free as in beer
* Could be MITM by telco or anyone with access to telco data (wireless scanner)
* Requires asking for the user's phone number
* SMS is *not* instant, could be minutes or more to receive a message
[1]: I don't like giving out my phone number and I assume most other people are like that as well. Less is more when it comes to sharing personal info.
[2]: Clock sync is really important. If you're going to do a TOTP implemenation make sure you run ntpd/ntpdate to keep your clock in sync.
- arn 13y agoWhat about losing your device? How is that handled with something like Google Authenticator? Don't you then have to fall back to some sort of manual verification? If you lose your SMS authenticated Phone, you can get a new one and transfer your number to it.
- sehrope 13y agoIf you lose your device then you restore it from a backup. For Google apps's 2FA setup they also have one time use codes. It s a special list of 10 codes that you're supposed to save somewhere safe offline (eg. wallet, deposit box, trusted neighbor, ...). If you lose your device you can use one of the codes to login and configure (or disable) 2FA.
- arn 13y agoI've had backup restore to a new device not work for google authenticator (I assumed that was by design), which is what has made me wary of it. But for your app, I assume you use manual re-authentication if someone loses their device?
- sehrope 13y agoI've upgraded my phone 3 times so far (3G -> 4 -> 4S -> 5) and no issues with migrating Google Authenticator settings. I do have the habit of wiping out all my music but that's because I never bothered to setup iTunes properly (plus my desktop is Linux so I run it in a Windows VM). I'm not too worried about the restore not working as I have the single use codes securely saved as well (and tested). If I lost my phone or bricked it during an upgrade I can just use those to set things up again in ~15 minutes. I consider that process superior to waiting to get a new phone. More importantly on a day to day basis (eg the normal case where you don't lose your phone) it's more secure as it can't be MITM without getting the TOTP secret either from my phone or from the system I'm authenticating against.