It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…
I thought Authy was TOTP?
Two-factor authentication is a mess
91–100 of 112 posts
Re: Two-factor authentication is a mess
#92Earlier quoted context omitted.
So instead of hacking 1 email/account they would just hack 2 or 3? I don't think that is adding any real security as those accounts would still just be protected by regular passwords. It makes it a tad bit harder for a hacker but not prohibitively so, because if they got the credentials to your first account then the others are probably not too much harder. The real power of 2FA is having the code generated by you, t…
> So instead of hacking 1 email/account they would just hack 2 or 3? I don't think that is adding any real security as those accounts would still just be protected by regular passwords. It makes it a tad bit harder for a hacker but not prohibitively so, because if they got the credentials to your first account then the others are probably not too much harder. That's certainly one of the thoughts that I had originally…
You can't add N factors to multi factor authentication by adding more accounts. That's just lightly strengthening the first factor (something you know which is a few different accounts) with a splattering of the second factor (those accounts rely on something you have such as your phone). The third factor of something you are doesn't even come into play in this solution.
Having 2FA set up for the account in question makes it reasonably secure. Relying on a second account that also has 2FA enabled does not make it twice as secure. It might make it slightly more secure but not by a lot. It's even likely that the second account is using the same device for the second factor as the first account which negates any added security.
The best you can do in a scheme like this is shift the trust based security to second entity. It's the same level of security but just handled by something you might trust more. (Google/Facebook vs some random website I had to make an account for).
Re: Two-factor authentication is a mess
#93Please critique this wild-ass idea of mine: When the user makes their first purchase, print out five identical business cards and send it to them by snail-mail. (If you're selling physical products then obviously ship it with the product). The front of the card is a regular business card; the back says "Use this code for a 10% discount on your next checkout: correct-horse-battery-staple-OTOP-backup-code" and a OTOP Q…
Re: Two-factor authentication is a mess
#94Earlier quoted context omitted.
>> I'm surprised the cut-throat world of registrars don't compete on this. How many people go looking for that though? For most people my guess is people go shopping for CHEAP first, EASY second, maybe LOOKS GOOD third, and some where down that list is "much more secure". I hate to say, I rarely go looking for the more secure option of anything.
It's why I started doing more of my business with Hover.com. I wanted a reliable looking company with 2FA. That was important to me.
Re: Two-factor authentication is a mess
#95Earlier quoted context omitted.
A quick question for someone who knows little about 2FA. If I were to use my Google Voice account as the SMS number does that make it any more secure since it's not tied to a SIM card?
It still goes through a bunch of providers, including Google, so it would not be as secure as TOTP. If the provider doesn't use it as a replacement for the password (ie you can't change your password using it), it may be more secure than just the password alone, but I don't trust it.
Re: Two-factor authentication is a mess
#96Please critique this wild-ass idea of mine: When the user makes their first purchase, print out five identical business cards and send it to them by snail-mail. (If you're selling physical products then obviously ship it with the product). The front of the card is a regular business card; the back says "Use this code for a 10% discount on your next checkout: correct-horse-battery-staple-OTOP-backup-code" and a OTOP Q…
I throw out every business card I get with a package. I never scan the QR codes. I can only imagine the nightmare of recovering 2FA for someone who was tricked into setting it up without really understanding it. Just getting my relatively technically savvy mom on a passowrd manager took some work.
The user can either:
1. Throw it away. Then nothing happens; no 2FA is set up.
2. Type in the code in for a 10% discount. Again, no 2FA is set up so the user's security is never worst off than before.
3. Type in the code and setup 2FA. This is case the user is tech-savvy enough to properly setup 2FA and successfully authenticate with it (in order to claim the 20% discount) so they (hopefully) realize the importance and convenience of the pre-printed physical backup codes and will (hopefully) stash them away somewhere safe.
Re: Two-factor authentication is a mess
#97Re: Two-factor authentication is a mess
#98Earlier quoted context omitted.
> So instead of hacking 1 email/account they would just hack 2 or 3? I don't think that is adding any real security as those accounts would still just be protected by regular passwords. It makes it a tad bit harder for a hacker but not prohibitively so, because if they got the credentials to your first account then the others are probably not too much harder. That's certainly one of the thoughts that I had originally…
This really does just seem like 2FA with extra steps. You can't add N factors to multi factor authentication by adding more accounts. That's just lightly strengthening the first factor (something you know which is a few different accounts) with a splattering of the second factor (those accounts rely on something you have such as your phone). The third factor of something you are doesn't even come into play in this so…
This is an absurd statement that I didn't imply, but perhaps you inferred?
> The third factor of something you are doesn't even come into play in this solution.
As I've said, the point is to allow for additional claims to be given. "Something you are", i.e. biometrics, is certainly "in play" in this solution. It is yet another claim to add to establish an identity. The point is that the identification is extensible, and that it's left to the end user to make the opinions that you're depicting rather insouciantly as some kind of "absolute truth", when what we're actually talking about is trade-offs with security vs. convenience, as well as defense-in-depth.
> It's even likely that the second account is using the same device for the second factor as the first account which negates any added security.
You're assuming that the attack vector is only at the end device. Of course diversification of hardware like a keyfob or smart card is an added layer of defense. But that doesn't mean that there is no value in multiple identities from the same device. It all depends on the specifics of how your device is compromised, or even if it's your device that is compromised in the first place. As I said, what if you have a single email address hacked or a single email (or oauth, or sms, or whoever) has a data breach?
> The best you can do in a scheme like this is shift the trust based security to second entity.
Creating your own user/pass scheme, or your own oauth server is certainly one of the options we have, so again this is not "shifting to a second entity".
I'm wondering if this is just trolling at this point? You're making simply outlandish remarks with numerous assumptions and with little regard to what I'm actually saying.
Re: Two-factor authentication is a mess
#99Earlier quoted context omitted.
I throw out every business card I get with a package. I never scan the QR codes. I can only imagine the nightmare of recovering 2FA for someone who was tricked into setting it up without really understanding it. Just getting my relatively technically savvy mom on a passowrd manager took some work.
It's fine if the user throws it out. The whole scheme is optional and the code is never activated until the user types it in first. The user can either: 1. Throw it away. Then nothing happens; no 2FA is set up. 2. Type in the code in for a 10% discount. Again, no 2FA is set up so the user's security is never worst off than before. 3. Type in the code and setup 2FA. This is case the user is tech-savvy enough to proper…
Re: Two-factor authentication is a mess
#100It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…
I just consider them as not supporting 2FA. I'm looking at you, Namecheap. My domain registrar not having two-factor authentication in 2017 is preposterous.