3 ms·
While defense in depth is never wrong, please be aware that even moderately advanced trojans will simply capture the contents of any form fields in most browser
by phlo 12y ago
While defense in depth is never wrong, please be aware that even moderately advanced trojans will simply capture the contents of any form fields in most browsers. Neither your "skipping" technique, nor (partially) using an on-screen-keyboard will help against that.
Using a second factor for authentication provides some extra security, but a well-configured trojan might intercept your logout request, display a fake logout confirmation and store your session data for their botmaster to peruse.
If you need to regularly use untrusted machines (and have access to usb ports or a cd drive), you could bring a hardened browser with you. That should defeat most "Man-in-the-Browser" tricks. Or, even better, a live CD or USB drive. At this point, you should still assume your keyboard and screen to be compromised, but the OS should be safe enough to cautiously use.
- onnoonno 12y agoIn this scenario, if I login to my own server, if I control the login on the remote end, I set it up to support one time passwords. It would be nice if this would be something that can be set up by default for credentials. Maybe this should be a feature request to the web-app devs.?
- peterwwillis 12y ago2FA with one-time codes is basically a one-time credential. Use this site to support web apps with 2FA, or request 2FA for unsupported sites: http://twofactorauth.org/ http://twofactorauth.org/
- nmcveity 12y agoSome services like Gmail allow you to sign out all other sessions from a session. So in the case of logging out from a unsecured computer, you logout as normal and then immediately sign out all sessions from your mobile device - it's a bit like a two factor logout to go with your two factor authentication.