Highly misleading headline (EDIT: Title has now been changed). From the article: > including One Time Passwords (OTP)via SMS phone messages That "SMS" bit is critical. OTP over SMS sucks. OTP using the same app that already manages my passwords (1Password) is a breeze. Sure, if I had a U2F Security Key already plugged in, then it would probably be even faster, but the downside is I need to have a physical key plugged…
Keeping your password and your OTP generator in 1Password is not TWO-factor-authentication (2FA). Since you only need your master password to get both. https://blog.agilebits.com/2015/01/26/totp-for-1password-use... (See the "Second Factor? No." bit). In the case where you need true second factor authentication, it needs to be another factor (i.e. device). This is a good place to have a Fido U2F key. In my experience…
Google Determines that FIDO U2F Security Keys Improve Security
11–20 of 69 posts
Re: Google Determines that FIDO U2F Security Keys Improve Security
#12Updated the title to specify SMS OTP.
Re: Google Determines that FIDO U2F Security Keys Improve Security
#13Earlier quoted context omitted.
Given that NIST now explicitly says you shouldn't use SMS for 2FA, I'm not sure why we're even trying to compare U2F to SMS OTP. It's just not a useful comparison at all. Any company that is even considering supporting U2F should already be offering non-SMS-based OTP anyway.
For the vast majority of users who are not the targets of government attacks, SMS OTP is still a huge win for account security. Alex Stamos put it well: https://twitter.com/jonoberheide/status/804363754842554375 "Nothing https://twitter.com/alexstamos/status/804367695860744192 "Seems like the right ordering, but when deployment is 98% < 2% < .5% < .01% complaining about SMS security is pretty silly."
Re: Google Determines that FIDO U2F Security Keys Improve Security
#14Updated the title to specify SMS OTP.
We reverted the title from “Google: FIDO keys more secure, easier to use, and more affordable than SMS OTP” to that of the article, since it appears to be neither misleading nor clickbait. https://news.ycombinator.com/newsguidelines.html
Re: Google Determines that FIDO U2F Security Keys Improve Security
#15Earlier quoted context omitted.
Given that NIST now explicitly says you shouldn't use SMS for 2FA, I'm not sure why we're even trying to compare U2F to SMS OTP. It's just not a useful comparison at all. Any company that is even considering supporting U2F should already be offering non-SMS-based OTP anyway.
For the vast majority of users who are not the targets of government attacks, SMS OTP is still a huge win for account security. Alex Stamos put it well: https://twitter.com/jonoberheide/status/804363754842554375 "Nothing https://twitter.com/alexstamos/status/804367695860744192 "Seems like the right ordering, but when deployment is 98% < 2% < .5% < .01% complaining about SMS security is pretty silly."
Re: Google Determines that FIDO U2F Security Keys Improve Security
#16Highly misleading headline (EDIT: Title has now been changed). From the article: > including One Time Passwords (OTP)via SMS phone messages That "SMS" bit is critical. OTP over SMS sucks. OTP using the same app that already manages my passwords (1Password) is a breeze. Sure, if I had a U2F Security Key already plugged in, then it would probably be even faster, but the downside is I need to have a physical key plugged…
I have a Yubikey Nano in each of my computers, that are registered with everything that supports U2F (currently only Google and Github). I also have a Yubikey Neo that's on my keychain. Between all of these, I never have any U2F problems. Except my iPhone, which can't get OTP codes over NFC like Android phones can. So actually I have Google Authenticator for TOTP codes.
Re: Google Determines that FIDO U2F Security Keys Improve Security
#17Highly misleading headline (EDIT: Title has now been changed). From the article: > including One Time Passwords (OTP)via SMS phone messages That "SMS" bit is critical. OTP over SMS sucks. OTP using the same app that already manages my passwords (1Password) is a breeze. Sure, if I had a U2F Security Key already plugged in, then it would probably be even faster, but the downside is I need to have a physical key plugged…
Keeping your password and your OTP generator in 1Password is not TWO-factor-authentication (2FA). Since you only need your master password to get both. https://blog.agilebits.com/2015/01/26/totp-for-1password-use... (See the "Second Factor? No." bit). In the case where you need true second factor authentication, it needs to be another factor (i.e. device). This is a good place to have a Fido U2F key. In my experience…
So really it comes down to what your threat model is and what risk profile you're willing to accept for a given site. For me, all I really care about is TOTP and not having "real" 2FA. But of course if you're talking about something like an AWS account that controls access to your company's data, it's probably worth investing in a YubiKey or similar.
Re: Google Determines that FIDO U2F Security Keys Improve Security
#18Highly misleading headline (EDIT: Title has now been changed). From the article: > including One Time Passwords (OTP)via SMS phone messages That "SMS" bit is critical. OTP over SMS sucks. OTP using the same app that already manages my passwords (1Password) is a breeze. Sure, if I had a U2F Security Key already plugged in, then it would probably be even faster, but the downside is I need to have a physical key plugged…
Re: Google Determines that FIDO U2F Security Keys Improve Security
#19Earlier quoted context omitted.
Keeping your password and your OTP generator in 1Password is not TWO-factor-authentication (2FA). Since you only need your master password to get both. https://blog.agilebits.com/2015/01/26/totp-for-1password-use... (See the "Second Factor? No." bit). In the case where you need true second factor authentication, it needs to be another factor (i.e. device). This is a good place to have a Fido U2F key. In my experience…
With 1password you have to have both the password database (one factor) and the password to unlock it. (another) It's not traditional 2FA but it fits pretty close. (a thing you have and a thing you know)
Re: Google Determines that FIDO U2F Security Keys Improve Security
#20Highly misleading headline (EDIT: Title has now been changed). From the article: > including One Time Passwords (OTP)via SMS phone messages That "SMS" bit is critical. OTP over SMS sucks. OTP using the same app that already manages my passwords (1Password) is a breeze. Sure, if I had a U2F Security Key already plugged in, then it would probably be even faster, but the downside is I need to have a physical key plugged…
You quoted: including One Time Passwords (OTP)via SMS phone messages
The sentence that phrase is lifted from: U2F is an alternative to other forms of two factor authentication (2FA) including One Time Passwords (OTP)via SMS phone messages.
So you either deliberately or carelessly misquoted. What's more, I quote:
> Additionally, Google's research found that with OTP based authentication there was an average failure rate of three percent. In contrast, with the U2F Security Key approach, Google experienced zero authentication failures. The improved efficiency of using Security Keys instead of OTP is estimated by Google's support organization to have saved the company thousands of hours per year.
And further:
> "While any 2-SV mechanism is better than having only a password on your account, FIDO U2F provides strong authentication that's resistant to many forms of advanced phishing attacks that traditional 2-SV doesn't protect against," Brand said. "It also provides for a much better user experience."
So no. The headline is not misleading and in fact your hot take and comparison to 1Pass is a misunderstanding.
For people curious what these keys look like in the wild, by far the most famous brand name most people in our space would see is Yubico, which you can see here: https://www.yubico.com/products/yubikey-hardware/fido-u2f-se...
You _can_ integrate this approach into your product, into your AWS environment, into your Azure environment, or into your linux servers. And it works, and it can be self-hosted if that is a priority for you.
Oh, and if you'd like to try the best of ALL THREE WORLDs, LastPass directly supports Yubikey FIDO keys. And also lacks 30s of impromptu vault animations and supports touchid. They're working on facial recognition for Windows as a 3rd factor as well, I'm told. That'll be great.