3 ms·
Beware when using TOTP (Google Authenticator)
- akerl_ 12y agoThe title is quite linkbaity. I mostly agree with the main premise, which is "If you're passing your first factor via the same device that has your 2nd factor's secret key, you only have 1 factor", but that doesn't mean we should "beware" TOTP.
- webhat 12y agoIt's not just that, many of the custom implementations of Google Authenticator keep the seed in plaintext.
- akerl_ 12y agoThat doesn't bother me terribly much. Passcode or not, I pretty much consider everything on my phone to be unencrypted, and treat it as such. Sandboxing the app from other apps matters much more. If somebody gets access to my phone, either by rooting it over the network or physically, I'm gonna consider that token burned and generate a new one.
- webhat 12y agoIt didn't bother me either, I'm the one he had the conversation with, until I realized that the phone isn't the problem. It's people using implementations like this: http://gauth.apps.gbraad.nl/ http://gauth.apps.gbraad.nl/
- adrianusw 12y agoHi, I am the author... I do not see anywhere saying to beware of TOTP, but when using TOTP. And that is only in the title ;)
- akerl_ 12y agoAs an end user, bewaring an idea and bewaring using the idea are pretty much the same. And putting it in the title is why I called the title linkbait.
- adrianusw 12y agoHmm, I do not agree, but that may be just me being rigorous in wording as a habit. End users being a moving target, I may have been out of touch with them for some time; my target audience is rather people in security for which I try to write up some ways to stock up on some verbal ammo for those fantastic corporate meetings. But it is not intended as such (linkbait) and since it is my blog I can gripe in any way I see fit :)
- webhat 12y agoThe title might more aptly by "Beware when using third-party TOTP implementations (Google Authenticator)"