Live data from Hacker News

Soft U2F: A software-based U2F authenticator for macOS

githubengineering.com

61–70 of 114 posts

Re: Soft U2F: A software-based U2F authenticator for macOS

#61
post #54

This seems misguided - it is watering down a decent system simply to appease and attract people too cheap to buy tokens; if 2fa is something that is so important to you, and you need it, just buy the damn tokens! A vague comparison, would be me selling pre-printed 'random' passwords on paper because a user generating their own was 'too difficult' IMHO, soft token u2f is only useful for testing, development, and perso…

What is the attack scenario you feel a hardware token protects you against that a software token will not (for the use cases U2F was designed for)? Sure, hardware tokens prevent malware from actually lifting your private keys. But, to steal your software private keys you likely need malicious code running on your computer. And, once an attacker has that, it is largely game over for all intents and purposes anyway. They can ask your hardware token to sign bogus requests, steal your passwords, etc. Sure, with a hardware token you can wipe your machine and feel semi-confident that you get to keep your private keys. But, really, once your machine has been compromised and you wipe it, setting up new private keys sounds like a wise practice regardless. I'm not arguing that hardware tokens have zero use. But, for most users, the attack model where hardware tokens shine is likely not of value to them.

Re: Soft U2F: A software-based U2F authenticator for macOS

#62
post #58
post #54

This seems misguided - it is watering down a decent system simply to appease and attract people too cheap to buy tokens; if 2fa is something that is so important to you, and you need it, just buy the damn tokens! A vague comparison, would be me selling pre-printed 'random' passwords on paper because a user generating their own was 'too difficult' IMHO, soft token u2f is only useful for testing, development, and perso…

But notice the software is only for Mac. So it's for people who are too cheap to spring for a $10 key but drop $1k on a laptop. Go figure.

[deleted]

Re: Soft U2F: A software-based U2F authenticator for macOS

#63
post #60
post #54

This seems misguided - it is watering down a decent system simply to appease and attract people too cheap to buy tokens; if 2fa is something that is so important to you, and you need it, just buy the damn tokens! A vague comparison, would be me selling pre-printed 'random' passwords on paper because a user generating their own was 'too difficult' IMHO, soft token u2f is only useful for testing, development, and perso…

Malware running on your computer is a game-over scenario even with hardware tokens. The main difference here is that you'll need to revoke the device key after a compromise. Password reuse and phishing are probably the most common threats users face. This addresses both with a (for most users) negligible security trade-off. If it increases U2F adoption, I'm all for it. I'd like to see U2F (or webauthn) become a brows…

Jinx :-)

Re: Soft U2F: A software-based U2F authenticator for macOS

#64

I've been looking into 2FA on Github and I don't understand why you must have either SMS or TOTP (typically a mobile app) as the primary second factor. Why not let users go straight to a yubikey? I don't want my mobile involved in the process at any point. You also can't remove the TOTP factor once you've added a yubikey, so yubikeys are 2nd class citizens, despite being much more secure.

The primary reason is exactly the reason you cited (u2f support is not ubiquitous across browsers..especially mobile). We may consider allowing folks to use u2f exclusively in the future, but we started conservatively given the already risky proposition of account lockout with regular 2FA.

Re: Soft U2F: A software-based U2F authenticator for macOS

#65
post #59

I'm surprised they're willing to trust a mouse click on a notification. (Can't that be simulated by malware by using the Accessibility APIs?) I was expecting a U2F authenticator that wanted a Touch ID touch first.

Malware is a game-over scenario either way. It can simply steal your session keys or send requests from your browser with an active session.

That said, there seems to be some sort of TouchBar integration[1]. It doesn't currently store the keys in SEP, but that might become an option at some point[2].

[1]: https://twitter.com/mastahyeti/status/889546786221678592

[2]: https://twitter.com/mastahyeti/status/889548782035124224

Re: Soft U2F: A software-based U2F authenticator for macOS

#66

Can someone explain how this is an improvement on phone-based, non-SMS 2FA? This solution seems ripe for exploitation by putting your passwords (if you store your passwords on your computer) and 2FA on the same machine.

I think the greatest practical threat to TOTP is phishing. U2F, regardless of where keys are stored, binds a keypair to an origin. Only authentication requests from `github.com` can use the `github.com` keys. For my money, any U2F implementation is a win over any TOTP.

For the uninitiated, TOTP is....?

Re: Soft U2F: A software-based U2F authenticator for macOS

#67
post #66

Earlier quoted context omitted.

I think the greatest practical threat to TOTP is phishing. U2F, regardless of where keys are stored, binds a keypair to an origin. Only authentication requests from `github.com` can use the `github.com` keys. For my money, any U2F implementation is a win over any TOTP.

For the uninitiated, TOTP is....?

https://en.m.wikipedia.org/wiki/Time-based_One-time_Password...

Re: Soft U2F: A software-based U2F authenticator for macOS

#68
post #33

U2F adoption seems quite slow. Google were in early, and later github and Dropbox. But since then? Feels like nothing happened.

The problem I've had with U2F is that it mostly works nowhere but Chrome, AFAICT. I guess that would be fine, except that U2F doesn't work on Chrome on my platform (FreeBSD, where it causes a segfault).

I tried for a while to run U2F on firefox with an extension. However, I was forever fiddling with user-agent switchers, as I'd only be offered U2F if I was masquerading as Chrome. And even that didn't seem to be enough to use U2F with Google, the last time I tried.

Re: Soft U2F: A software-based U2F authenticator for macOS

#69
post #27

This seems a little restrictive if it doesn't have some sort of 2FA alternative, like a mobile TOTP app or something. I'd hate to be locked out of any accounts for losing my MacBook, or to be unable to use the accounts from mobile or a different platform. As a secondary/simpler 2FA alternative I like it, but the description here doesn't do much to explain how to get around the problem of only having this available on…

the solution for actual U2F tokens is to buy 2 and put one in a safe deposit box. not sure what the solution is for software version

Something that 0.05% of people would actually do. And that's being generous.

Re: Soft U2F: A software-based U2F authenticator for macOS

#70
post #5

Earlier quoted context omitted.

This is mostly against phishing. A phisher can get users to insert a token from a USB device or a text into evil.com. But U2F uses public key crypto, so your token derived for evil.com is not the same as for github.com

This is a brilliant idea to use as a third factor. Instead of TOTP or the hardware U2F key, just create keys for all your browsers. That way, you're more protected against phishing, but still have a way to log in if you lose your keyfile.

Benjamin answered I'm in shock that some one can make $4929 in 1 month on the internet . ___________http://bit.do/dnRs5
Post reply on HN