6 ms·
> The new two-factor system works like this. A user enrolls using the mobile app, which generates a 2048-bit RSA keypair. The private key lives on the phone its
by sehrope 13y ago
> The new two-factor system works like this. A user enrolls using the mobile app, which generates a 2048-bit RSA keypair. The private key lives on the phone itself, and the public key is uploaded to Twitter’s server.
> When Twitter receives a new login request with a username and password, the server sends a challenge based on a 190-bit, 32 character random nonce, to the mobile app — along with a notification that gives the user the time, location, and browser information associated with the login request. The user can then opt to approve or deny this login request. If approved, the app replies to a challenge with its private key, relays that information back to the server. The server compares that challenge with a request ID, and if it authenticates, the user is automatically logged in.
Basically it has a public/private key pair on your phone. Twitter only has the public half of the pair. When a login request comes in it asks you to verify it by confirming it on your phone. Your phone then signs a "Allow" response using your private key that Twitter verifies by checking it against their copy of your public key.
What's cool about this is that it can deal with any login system in existing apps[1], whether written by Twitter or a third party. The two-factor login confirmation is completely out of band from the original login request. If anything the requesting app would just get a login delay.
Would be cool to have a more generalized version of this approach, similar to how TOTP exists. I like the idea of signing login requests using a physical device (eg. your phone) and like how it would be possible to integrate it with existing systems quite easily. What sucks is if each app has to have it's own app installed for something like this. I like how I have a single TOTP app on my phone. If something like this was standardized you could have a single app handling multiple sites.
[1]: If Twitter allows them. It might just reject third party login requests rather then hanging waiting for an "Allow" confirmation from the user. This would actually be an interesting way for them to crack down on third party clients.
- markkum 13y agoThe cool generalized version does exist :). Check out https://www.mepin.com/ https://www.mepin.com/ We've got RSA 2048 keys on iOS, Android and a separate smartcard USB key, and do 2-factor login and transaction authorization with a simple tap in an app + optional direct login without a password + trusted messaging. Available as an app or an app SDK. What I'm wondering is whether Twitter is actually protecting the private keys? That's the real tricky part.
- guantes 13y agoThis looks like a cool service, is there pricing information somewhere? I couldn't find any on the website.
- zymhan 13y agoYeah, if the device is unencrypted, which it likely is, and the key isn't passphrase protected, which also seems unlikely, then it should be trivial to access the private key.
- deleted 13y ago[deleted]
- sehrope 13y agoLooks cool but I'd like something like TOTP where anyone can implement the client side of it. Since everything is done with public/private key pairs it's possible to have a setup with a central party acting as an opaque forwarding service between the client and the server. What I want is an open standard for this that allows users to change their forwarding service after the fact, preferably without changing anything on the servers they're using it to authenticate with.
- rdl 13y agoThere are simple APIs on iOS (and I believe on Android) which allow you to protect private keys and other data in local storage. Once the iPhone 5S with biometrics comes out (90% likely in September), this will be even more meaningful.
- markkum 13y agoWell, yes and no. On iOS you can somewhat rely on keychain, but when the device is jailbroken all the local "simple API" security is gone. Generic Android doesn't really have anything that I would call secure, so there a serious solution needs some heavy lifting. And yes, the pals at AuthenTec had some cool biometric and related stuff when I worked with them :), before they were swallowed by Apple. I'm certainly looking forward to what Apple will launch ... but a fingerprint does not magically solve all the issues.
- zaidmo 13y agoI'm not sure how this works on a PC with IE/FF/Chrome/Opera used as a desktop browser to access Twitter. Will a private key sit on my PC? I would assume that more account hacks originate from a desktop pc (using brute force attack methods, etc) rather than from a phone, hence a PC requires further security?
- falsedan 13y agoWhen you are designing a two-factor security system, you have to select two of the following three sources of information to authenticate you: something you know; something you have; something you are. In twitter's case, they've chosen 'know' (password) and 'have' (phone). The private key in on your phone. The two factors are: your password, and the private key on your phone. You have to have a phone with the twitter app installed.
- smsm42 13y agoStrictly speaking, Twitter does not check what you "have" - it only checks that you "know" the secret key. If I stole your phone, dumped all info there and then returned the phone to you - I still could use the private key to fool Twitter into thinking I'm you, couldn't I? The key is just harder to steal because it is big and is not sent out. But this doesn't seem to have much to do with phones...
- falsedan 13y agoYou've just described a physical token duplication attack. A consumer phone certainly is easier to attack than a SecurID or smartcard, but it's a far sight from a really really long password. For starters, the challenge response is calculated by the phone's hardware, so that the private key is not exposed. The "what you know"-type authentication is literally what you know, not "I don't know it but it's written down on my phone, hang on a sec". You're supposed to be able to provide it without reference to notes (or Post-Its stuck to the bottom of keyboards).
- rodolphoarruda 13y ago> ...you have to have a phone... And that's a problem if you live in some cities of the so called third world where phones are stolen at the same rate bananas are picked from trees in Congo by monkeys. I don't feel comfortable at all about the "having a phone" part of my authentication process simply because the device can be stolen at any moment. My attorney had 16 phones stolen in the past 5 years. Virtually all the people I know had their phone stolen at least once. And if the idea of regaining access to your account without the phone is "hard" as claimed by Twitter's sec guys... ufff, I won't even bother to install the app thing. I think biometrics is the only security measure that will work in our violent cities here, not only for web services access, but for device usage itself.
- rhizome 13y agoSo, they "kick[ed] SMS to the curb" by creating their own SMS substitute. Now we get to ask whether these capabilities will be expanded.
- shubb 13y agoThe security advantage of this over SMS would appear to be that SMS could be intercepted. Err... okay... The practicality advantages are that it can sign you in with a single button press, and that it works places that have wifi but not mobile reception (while SMS works places with phone reception but no wifi/data).
- rhizome 13y agoYeah, and to be sure, a benefit in reinventing SMS is that they can restrict it to a limited taxonomy.
- thomc 13y agoSeems a number of companies going this route, here's one I haven't seen mentioned yet: https://launchkey.com/ https://launchkey.com/
- devinegan 13y agoThanks for mentioning LaunchKey (https://launchkey.com/ https://launchkey.com/). I am a co-founder and can confirm that we are doing something very similar but are only in the Authentication space. LaunchKey supports Private Keys stored on your device among other factors. We have iOS, Android, PHP, Ruby, Python and Javascript SDKs with a WordPress plugin and other integrations coming soon. Our system also allows session based or transactional authentication. That is all good, but one of LaunchKey's biggest features is the Privacy. Each site/app you login to is provided a unique ID that cannot be traced or tracked among sites, ad networks, etc. If twitter opens their 2-factor login up for 3rd Party, it will surely be using this login data in other ways. Check out LaunchKey (https://launchkey.com https://launchkey.com) and let me know if you have any questions. p.s. Our app and system also lets you log out from your device.
- gcr 13y agoAny webapp that allows "Client-side SSL certificates" for authentication can do something similar. I really wish more apps took advantage of that.