Live data from Hacker News

Two-factor authentication is a mess

theverge.com

11–20 of 112 posts

Re: Two-factor authentication is a mess

#11
post #2

One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…

this is something that my bank is testing on its users now, whether I need to confirm the transaction or cancel my automatic deposit prolongation it asks me to make a photo and send it to them for confirmation, which takes them in average 5-10 minutes. Though it is not a ver comfortable way for an end-customer, I guess some kind of biometric authentication/confirmation will take place as soon as a user will tolerate that.

Re: Two-factor authentication is a mess

#12

I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…

To quote the AWS ManPage[0]: > We recommend that when you configure a virtual MFA device to use with AWS that you save a copy of the QR code or the secret key in a secure place. That way, if you lose the phone or have to reinstall the MFA software application for any reason, you can reconfigure the app to use the same virtual MFA. This avoids the need to create a new virtual MFA in AWS for the user or root user. That…

My standing recommendation is printing that QR code on paper and not keeping any digital copy of it, as it does function like "your second password" for all intents and purposes. You really don't want your 2FA tokens synced anywhere online, or stored on any device someone could potentially break into over the Internet.

That QR code paper can be secured the old fashioned way: I recommend a fireproof safe. The fact that you'd have to compromise your physical security (either the phone or your safe) and digital security (your password) at the same time provides reliable 2FA.

Re: Two-factor authentication is a mess

#13
post #5

> Avoid: SMS has been at the center of a lot of two-factor hacks, most recently as a way to hijack Telegram accounts in Iran. High-security accounts are already moving away from it, but a frightening number of services still keep it as an option, giving anyone who compromises your carrier account an easy way in. I feel like this is badly phrased. SMS 2FA is far worse than other types, but still better than no 2FA.

>> SMS 2FA is far worse than other types, but still better than no 2FA. It seems like every time I read about how SMS2FA was hacked it was done by some state level power that would've gotten in through some other method. I don't know if that's confirmation bias or actually true, but I think you're right, SMS is better than no 2FA. Just because the NSA etc... can easily break it doesn't mean it's useless right now. (m…

Every hack I've read about is based on social engineering and is enabled by weak policies and overly helpful customer service representatives at wireless companies.

Re: Two-factor authentication is a mess

#14
post #2

One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…

>> I'm surprised the cut-throat world of registrars don't compete on this. How many people go looking for that though? For most people my guess is people go shopping for CHEAP first, EASY second, maybe LOOKS GOOD third, and some where down that list is "much more secure". I hate to say, I rarely go looking for the more secure option of anything.

agree, we just made a small survey among our customers to learn whether they are looking for more secure way of authentifiction and data storage generally for their work/business (not only our product) and of course almost everybody replied with "yes, definitely, we need more security" and on the next questions about how much are they willing to spend on it, more than 80% replied with "depends on the price", which means security is indeed not in the top priority and is quite price elastic.

Re: Two-factor authentication is a mess

#15
post #5

> Avoid: SMS has been at the center of a lot of two-factor hacks, most recently as a way to hijack Telegram accounts in Iran. High-security accounts are already moving away from it, but a frightening number of services still keep it as an option, giving anyone who compromises your carrier account an easy way in. I feel like this is badly phrased. SMS 2FA is far worse than other types, but still better than no 2FA.

I think SMS 2FA is worse than no 2FA, given that you can often reset a password using SMS as verification. If your phone number is hijacked, you're owned completely. Without SMS 2FA, you have to reset your password via email, or resort to contacting the company directly.

Re: Two-factor authentication is a mess

#16

I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…

I only enable 2FA if it's TOTP or HOTP. In the case of TOTP I save the key (the data in the QR code) in my password manager (KeePass), in the case of HOTP my backup key is in my fireproof safe at home along with other important documents. That's admittedly a small portable box with a carry handle, so easy for a burglar to steal, but it's also easy to get to and I can take it with me if I ever have to evacuate or move…

I just made a couple of copies and stashed one in my house and the other at work. If the entire metro area burns down I'll be SOL, but for reasonable levels of disaster I should be able to manage.

Re: Two-factor authentication is a mess

#17

I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…

you should always have at least two keys (devices) just as you always have at least two sets of keys to your home or car. same for u2f tokens.

Re: Two-factor authentication is a mess

#18
post #5

> Avoid: SMS has been at the center of a lot of two-factor hacks, most recently as a way to hijack Telegram accounts in Iran. High-security accounts are already moving away from it, but a frightening number of services still keep it as an option, giving anyone who compromises your carrier account an easy way in. I feel like this is badly phrased. SMS 2FA is far worse than other types, but still better than no 2FA.

>> SMS 2FA is far worse than other types, but still better than no 2FA. It seems like every time I read about how SMS2FA was hacked it was done by some state level power that would've gotten in through some other method. I don't know if that's confirmation bias or actually true, but I think you're right, SMS is better than no 2FA. Just because the NSA etc... can easily break it doesn't mean it's useless right now. (m…

> It seems like every time I read about how SMS2FA was hacked it was done by some state level power...

It seems to be a lot more vulnerable than that. Perhaps the biggest problem is that the phone companies do not treat your phone number as being a component of a 2FA system (and, to be fair, that was never the intent). This is from the linked article by Cody Brown, "How to lose $8k worth of bitcoin in 15 minutes with Verizon and Coinbase.com":

"Of all the things that went down in the factors that lead to this hack, Verizon Wireless is what I was massively unprepared for. After talking at length with customer service reps, I learned that the hacker did not need to give them my pin number or my social security number and was able to get approval to takeover my cell phone number with simple billing information."

See also: https://krebsonsecurity.com/2016/09/the-limits-of-sms-for-2-...

Re: Two-factor authentication is a mess

#19
post #2

One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…

physical mail is not secure by _any_ stretch of the imagination

Re: Two-factor authentication is a mess

#20

I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…

Coincidentally I set up 2FA on Amazon yesterday. I am disappointed they do not give you backup codes, nor do they support FIDO U2F. I made sure to keep a copy of the secret token in case anything happens to my phone I can set it up again. The way I do it is to scan the barcode in a reader first, save the token, then scan it in an authenticator app to install it.
Post reply on HN