5 ms·
I used to think that TOTP was the way to go too but it can be improved. I really like having a public/private key pair vs a static shared secret. It's just obje
by sehrope 13y ago
I used to think that TOTP was the way to go too but it can be improved. I really like having a public/private key pair vs a static shared secret. It's just objectively better. With this setup a rogue agent working at company X can't leak your 2FA secret. Data breaches don't compromise 2FA (this is really important).
The main advantage I see with TOTP is that it's standardized. I can use any TOTP client with any TOTP server. I can implement TOTP 2FA to my app and it'll work on any compliant TOTP client. A standardized 2FA approach using public/private key pairs would be superior though. You'd get a common approach but with all the advantages I list out in the first paragraph.
- jlgaddis 13y agoOh I would love to have a single SSL certificate for the client-side that I could use to authenticate everywhere I want to... but until we move towards some sort of global ID system (which, of course, has its own ramifications) I don't see that happening.
- hayksaakian 13y agoyou CAN have multiple IDs, and the ID does not need to be associated with any personal information.
- jlgaddis 13y agoYes, you're absolutely correct. I'm also capable of managing several different client SSL clients (I do it everyday). Can the average user keep track of just a few different SSL certificates and remember which one to use for which site? No, they can't, and that's why having "multiple IDs" won't work and we'll need some single centralized issuer of certificates in order for it to work "at scale".
- harshreality 13y agoWhat is the advantage of public key crypto for 2FA, other than that someone who hacks the site's 2FA database can't then impersonate you to that site later, so the site doesn't need to do a 2FA token reset on all accounts if there's a compromise? With TOTP, 2FA secrets are unique per site, so a rogue agent at company X doesn't gain very much by leaking your, or everyone's, 2FA secrets. Does TOTP vs public key 2FA have to have a winner? It seems to me like both are fine if properly implemented, and if a public key 2FA system turns into a standard I'm okay with having both. They have trade-offs but for most people and most sites either one is fine. TOTP wins for now because it's a standard and nobody else uses Twitter's system. I don't want an authentication app that only works for one site.
- voyou 13y agoThe disadvantage of Twitter's approach, though, is that it requires the thing that holds the private key to connect to the internet to verify the request. This increases the attack surface (and is potentially a pain if your phone doesn't have internet access, for example if you have no mobile reception but want to use the Twitter web site on a PC with a wired connection). I've been wondering if it's possible to have an offline system like TOTP that uses a private key rather than a shared secret. EDIT: Also it's a pain when Twitter's main web site is working but the bit that handles responding to approvals from the mobile client isn't, like, erm, right now.