Live data from Hacker News

Show HN: Faktor – The missing 2FA code autocomplete for Chrome

getfaktor.com

41–50 of 56 posts

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#41

Earlier quoted context omitted.

I just went round and round with my bank about needing my phone number so they can text me a TOTP. You know, for security. They just can't quite seem to wrap their head around how having the same device running their banking app that also receives the text is not secure when the device is no longer in your possession.

Sounds like one factor auth with 2 passwords

Its called two step verification. Prevents someone from “guessing” the password but doesn’t stop someone who has physical access to the device with the password stored. Same as with e-mail or SMS codes, basically. I don’t think i recall any websites that detect i am using my phone and rely on a true “second factor” aside from enterprise applications where i got a hardware yubi key.

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#42

Earlier quoted context omitted.

1Password already has support for this. Some would argue that you're defeating the purpose of 2FA if it's stored in the same way as your password, but it is pleasant.

Does 1Password do SMS based 2FA code filling? I use it for sites where they let me use any compliant auth app, but I've not seen a way to get it to work for SMS codes.

No, only passkeys or TOTP stored in 1Password.

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#44

Why not bitwarden?

I use both Bitwarden (Personal, recommended by a friend, paid for a year in advance) and 1Pass (Paid by my company).

The level of friction Bitwarden adds as compared to 1Pass is staggering.

Also, their Firefox extension eats resources like a new baby (I had to disable it because just a handful of tabs [1] were killing my machine).

[1] May be a little more than a handful, but having to disable an extension so that your machine behaves normally is telling.

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#45

Earlier quoted context omitted.

My view is that totp/2FA prevents someone with only your password from logging in. Having the totp seed inside a password manager doesn't break this goal, so I'm fine with it. Of course it means if my password manager gets hacked, there's everything to log in inside, but I'm more concerned about services leaking password hashes that get broken, or accidentally getting phished (and giving up a password + totp combo th…

I just went round and round with my bank about needing my phone number so they can text me a TOTP. You know, for security. They just can't quite seem to wrap their head around how having the same device running their banking app that also receives the text is not secure when the device is no longer in your possession.

Doesn't the attacker still need to know the password to the banking account, or the master password to the password manager? That'd be the second factor.

Besides being able to unlock the phone in the first place obviously.

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#46

If your 2FA code is as autocompletable as your password, is it really a second factor?

Yes — because 2FA is commonly stored on a separate device (phone), people are very quick to conclude that it is pointless otherwise without thinking further. Even if it is stored in your password manager, it is still useful. Consider the case where your network or website is compromised: the password is compromised and can be reused, but the totp 2fa that is in your password manager still prevents login by anyone who…

But what if it is an app on the phone that is asking for that 2FA which then receives that 2FA via text?

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#47
post #45

Earlier quoted context omitted.

I just went round and round with my bank about needing my phone number so they can text me a TOTP. You know, for security. They just can't quite seem to wrap their head around how having the same device running their banking app that also receives the text is not secure when the device is no longer in your possession.

Doesn't the attacker still need to know the password to the banking account, or the master password to the password manager? That'd be the second factor. Besides being able to unlock the phone in the first place obviously.

I only switched to a device with FaceID recently, so I haven't seen how often false positives are in the wild. I still have devices with ThumbID, and I can get into my tablet with rubber gloves without any issues. As far as just a password, if you're using a password manager also located on the phone... There's also people that just don't enable any of that kind of thing on their apps. So we're still fighting those fights. I'm the type that wishes every single app required authentication though.

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#48
post #10

I'm glad to see someone making this for Chrome. I really like how Safari does it. It can check mail and messages, then delete the message after verifying. One of the reasons why I am finding it difficult to switch from safari.

Broken websites aren't enough of a reason to switch?

Never seen a broken website on safari. Like others mentioned anything specific?

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#49
post #42

Earlier quoted context omitted.

Does 1Password do SMS based 2FA code filling? I use it for sites where they let me use any compliant auth app, but I've not seen a way to get it to work for SMS codes.

No, only passkeys or TOTP stored in 1Password.

[deleted]

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#50

Earlier quoted context omitted.

My view is that totp/2FA prevents someone with only your password from logging in. Having the totp seed inside a password manager doesn't break this goal, so I'm fine with it. Of course it means if my password manager gets hacked, there's everything to log in inside, but I'm more concerned about services leaking password hashes that get broken, or accidentally getting phished (and giving up a password + totp combo th…

I just went round and round with my bank about needing my phone number so they can text me a TOTP. You know, for security. They just can't quite seem to wrap their head around how having the same device running their banking app that also receives the text is not secure when the device is no longer in your possession.

If they're texting you it, it's almost certainly not TOTP.
Post reply on HN