4 ms·
> Blockchain.info is a great service, but only when you enable 2-factor authentication (otherwise your encrypted wallet can be bruteforced offline) and make sur
by sehrope 13y ago
> Blockchain.info is a great service, but only when you enable 2-factor authentication (otherwise your encrypted wallet can be bruteforced offline) and make sure you get backups by email.
2-factor auth does not and cannot protect against offline bruteforcing, quite the contrary, it's only relevant for online authentication with a service provider.
In your example it would be for authenticating with blockchain.info so they could perform an action on your behalf. Assuming they use your actual password as a master key to unlock a wallet they store on your behalf, the 2-factor piece is just extra security they are providing for actions performed through their site. 2-factor auth does nothing to prevent someone from trying to brute force the private key or pass phrase for your wallet.
I'm all for using 2-factor auth (I personally have it enabled on every site/service that supports it) but it's only for securing online access to an external service.
- oleganza 13y agoIn case of Blockchain.info, wallet decryption happens in browser. The server sends you an encrypted wallet if you know user ID and provide 2-FA code. Without the code, anyone who knows your user ID will get the encrypted wallet and bruteforce it offline. With 2-FA they'd have to hack into your email or phone to get the code or hack into your email or computer to get your encrypted backup.
- sehrope 13y agoMy interpretation of offline is if someone had access to their stored data (ex: blockchain.info is hacked, database is leaked, etc). In that case then 2-FA is pointless. It's only valid when interacting with them as an online service.
- oleganza 13y agoUsually you send your password to a service, but in this case encrypted data is "leaked" to a person requesting it. 2-FA prevents from giving this data to strangers (and won't help if the service is hacked, yes)