Live data from Hacker News

Security Key for safer logins with a touch

facebook.com

41–50 of 105 posts

Re: Security Key for safer logins with a touch

#41

Looks like a logistical nightmare to me. You think forgetting a password is a pain in the ass, just wait until you loose your security key. It won't be one service you have to reset through an alternate verification route, but every single one you ever used! I also foresee potential issues with data corruption on keys, and multiple-keys getting out of sync (e.g. work vs home). And I have no doubt that clever hackers…

That's why you buy two keys. No, they don't have anything to "sync".

Re: Security Key for safer logins with a touch

#42

Looks like a logistical nightmare to me. You think forgetting a password is a pain in the ass, just wait until you loose your security key. It won't be one service you have to reset through an alternate verification route, but every single one you ever used! I also foresee potential issues with data corruption on keys, and multiple-keys getting out of sync (e.g. work vs home). And I have no doubt that clever hackers…

See also: https://news.ycombinator.com/item?id=13493100

Re: Security Key for safer logins with a touch

#43
post #3

Does it rely on SMS as backup, though?

I had SMS as my backup and in testing this morning, FB sends the SMS by default, even before you either tap the key or say you want to use another method (like SMS). That's a big flaw to me. It should only send the SMS if I specifically say, "Use my backup SMS method". I switched to use an authenticator app instead as a result.

I'm not sure I see the security advantage to opt-in SMS over opt-out SMS (both are bad). If the button exists to override the hardware token with a text message, the attacker will simply push the button after hijacking your phone number.

Re: Security Key for safer logins with a touch

#44
post #9
post #6

Earlier quoted context omitted.

That looks like a requirement, not a choice. So as usual, the U2F standard being adopted by companies these days is only as strong as SMS 2FA, because of this requirement. Can someone tell me what's the point then? Is it that they hope that in the end U2F will get popular enough that they'll remove that requirement? I would hope that's it. Otherwise, I don't see the point. I wish they at least allowed you to opt-out…

You can use a TOTP code generator (e.g. Authy) as your backup. No need to rely upon SMS.

You can, but is there a way to do it such that Facebook won't under any circumstances send an SMS message?

Re: Security Key for safer logins with a touch

#45

I've been a big fan of yubikeys for years, but I'd never use mine for something like Facebook. I work in computer security, so I know this sounds crazy. But my brain has been rewired to work in failure modes by the not-security domain I happen to do security stuff in. The obvious argument for TFA is to reduce the chances that my Facebook account is subject to the bad consequences of that come from a compromised Faceb…

I don't think I follow your reasoning of how increased security increases the severity of a compromise. Can you elaborate on that?

It doesn't increase severity in and of itself, it just changes the nature of the system. And people will adapt their decision making processes to the new properties of that system.

Facebook would feel more comfortable expanding their scope of features in a way that increases severity. -- For example, my primary objection to using my facebook account to log into unrelated websites isn't about privacy, it's that I think I can manage unique credentials for each one better than adding facebook as a shared point of failure and risking a cascade if my facebook account gets compromised.

Contacts would assume a higher degree of authenticity to actions done with my account.

It only sets the stage for the change, it doesn't implement it. I know the tech bubble likes to pretend speculation around obvious system effects is 100% unfounded if it might lead to even-the-slightest-bit-unflattering conclusions. But I don't play that game.

Re: Security Key for safer logins with a touch

#46
post #40

Earlier quoted context omitted.

This is really awful, for it to work well you would need to buy multiple keys and each time use them all to register (which precludes the option of storing the backup key somewhere safe). Straight from the yubico website: "It is recommended that users register at least two U2F devices with every service provider should a U2F device be misplaced" That's just a plain usability nightmare, and not to mention expensive. T…

Part of the point of hardware tokens is that you can't back up and restore their keys. If backup and restore is important to your userbase, you should stick with soft tokens.

The trezor only lets you backup the key during the initialization stage. After that the key can never be recovered. Also you can set a password so it's encrypted as well, so even if someone finds your paper backup it's not particularly useful.

Re: Security Key for safer logins with a touch

#47
post #40

Earlier quoted context omitted.

Part of the point of hardware tokens is that you can't back up and restore their keys. If backup and restore is important to your userbase, you should stick with soft tokens.

The trezor only lets you backup the key during the initialization stage. After that the key can never be recovered. Also you can set a password so it's encrypted as well, so even if someone finds your paper backup it's not particularly useful.

If there can at some point in time be two or more tokens with the same secrets in them, you're essentially parked in the same security place as soft tokens. Just use the soft tokens.

I'm not saying soft tokens are bad. They're not; they're great. When we get a workable U2F software token, that might be the best option for most people.

What I'm saying is don't spend money on a hardware solution that isn't buying you any meaningful additional security.

Re: Security Key for safer logins with a touch

#48
We started using these for internal services and Google accounts where I work. It's unfortunately a big pain in the butt- you can't use Safari, you can't use the Mac/iPhone calendar app to see your meetings. It's web apps in Chrome or nothing, more or less.

The one type of key supposedly uses Bluetooth, but that functionality isn't built yet or something, so you get to carry around a little 4-inch microUSB cord with you everywhere you go, and connect that every single time you hit a 2FA prompt. At least the Yubikeys have a USB connector built into them.

Re: Security Key for safer logins with a touch

#49

Looks like a logistical nightmare to me. You think forgetting a password is a pain in the ass, just wait until you loose your security key. It won't be one service you have to reset through an alternate verification route, but every single one you ever used! I also foresee potential issues with data corruption on keys, and multiple-keys getting out of sync (e.g. work vs home). And I have no doubt that clever hackers…

That's why you buy two keys. No, they don't have anything to "sync".

One issue with buying two keys is they internally have different keys, so you need to connect both to each new account which is a pain in the ass and stops you just keeping one somewhere very safe (i.e. safety deposit box, or a safe at a friends house)

Re: Security Key for safer logins with a touch

#50

Looks like a logistical nightmare to me. You think forgetting a password is a pain in the ass, just wait until you loose your security key. It won't be one service you have to reset through an alternate verification route, but every single one you ever used! I also foresee potential issues with data corruption on keys, and multiple-keys getting out of sync (e.g. work vs home). And I have no doubt that clever hackers…

Actually, the saddest part is what a pain it is when it's all working correctly.
Post reply on HN