Live data from Hacker News

Two-factor authentication is a mess

theverge.com

41–50 of 112 posts

Re: Two-factor authentication is a mess

#41
post #38

Earlier quoted context omitted.

I just consider them as not supporting 2FA. I'm looking at you, Namecheap. My domain registrar not having two-factor authentication in 2017 is preposterous.

Namecheap does have 2fa... https://www.namecheap.com/support/knowledgebase/article.aspx... Do you mean because they only support SMS based 2fa? Considering they have a drop down menu it's possible they just have not had time to develop the other options?

As of January, 2014 Namecheap said[1]: "Currently, we only accept SMS authentication but Google Authenticator, Authy, and TOTP authentication are planned."

More than three years seems to me a long development cycle to add TOTP support. Am I being disingenuous to think they just don't care?

[1] https://blog.namecheap.com/account-security/

Re: Two-factor authentication is a mess

#42
post #36
post #29

It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…

What annoys me most about using SMS for 2FA is that it's useless if you ever travel to another country and don't have global roaming enabled.

SMS receiving is free everywhere, it has nothing to do with data roaming and generic roaming - available on the network - has been free since I had a mobile phone (~17 years).

Doesn't make it a the best option though.

Re: Two-factor authentication is a mess

#43
post #29

It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…

but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. Cloudflare supports Authy and Google Authenticator (or any TOTP-compliant app): https://blog.cloudflare.com/you-can-now-use-google-authentic...

Thank you, I didn't know this, and it was something I was judging against CF for years. It makes me a little uncomfortable though that there aren't any offline recovery codes in the event the TOTP device is lost/stolen/etc

EDIT: as pointed out below, there is one briefly on the QR dialog, it's not a separate sheet you generate/download like GitHub/Google/etc

Re: Two-factor authentication is a mess

#45
people's phones have their passwords from their google/firefox accounts, their email, and tend to be their 2FA device for google authenticator... not really 2FA anymore

to be fair if you are running the latest android or have an iphone that's probably better than having it all on your exploit ridden PC, but it's still 1FA

Re: Two-factor authentication is a mess

#46
post #38

Earlier quoted context omitted.

I just consider them as not supporting 2FA. I'm looking at you, Namecheap. My domain registrar not having two-factor authentication in 2017 is preposterous.

Namecheap does have 2fa... https://www.namecheap.com/support/knowledgebase/article.aspx... Do you mean because they only support SMS based 2fa? Considering they have a drop down menu it's possible they just have not had time to develop the other options?

Yep, SMS 2FA just makes my account less secure, therefore it doesn't count as 2FA.

Re: Two-factor authentication is a mess

#47
post #42
post #36

Earlier quoted context omitted.

What annoys me most about using SMS for 2FA is that it's useless if you ever travel to another country and don't have global roaming enabled.

SMS receiving is free everywhere, it has nothing to do with data roaming and generic roaming - available on the network - has been free since I had a mobile phone (~17 years). Doesn't make it a the best option though.

Don't know where you are from, but with the company and pre-paid plan I use, I can't receive an Australian SMS from my Australian phone when I'm not in Australia.

Re: Two-factor authentication is a mess

#48

I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…

To quote the AWS ManPage[0]: > We recommend that when you configure a virtual MFA device to use with AWS that you save a copy of the QR code or the secret key in a secure place. That way, if you lose the phone or have to reinstall the MFA software application for any reason, you can reconfigure the app to use the same virtual MFA. This avoids the need to create a new virtual MFA in AWS for the user or root user. That…

The nice part about AWS MFA is that there's usually multiple people with IAM access. So rather than use backup codes, we rely on co-workers to help us resynchronize. It may not work for 1-man shops, but how many AWS accounts only have 1 admin?

Re: Two-factor authentication is a mess

#50

Earlier quoted context omitted.

>> SMS 2FA is far worse than other types, but still better than no 2FA. It seems like every time I read about how SMS2FA was hacked it was done by some state level power that would've gotten in through some other method. I don't know if that's confirmation bias or actually true, but I think you're right, SMS is better than no 2FA. Just because the NSA etc... can easily break it doesn't mean it's useless right now. (m…

Every hack I've read about is based on social engineering and is enabled by weak policies and overly helpful customer service representatives at wireless companies.

Yes, to the point where YouTubers get their accounts hijacked so often that it's best practice among them to use a secret burner phone for 2FA
Post reply on HN