Live data from Hacker News

The bleak picture of two-factor authentication adoption in the wild

elie.net

41–50 of 96 posts

Re: The bleak picture of two-factor authentication adoption in the wild

#41

For those among us who can handle our passwords and general security, 2FA is just a penalty we have to pay for those who can't. As far as possible, I ditch any company that wants to force it upon me. I've done my homework, I don't want to consult my telephone, my mailbox, or even worse, some pesky dongle to complicate my life and add to my expenses.

Until a zero day exploit takes your browser, your VM you run your browser in (with confidence like yours you'd better run Qubes OS style) and just sniffs everything.

The "I know what I'm doing" doesn't hold up very well, statistically.

Re: The bleak picture of two-factor authentication adoption in the wild

#42
post #5

Earlier quoted context omitted.

The thing that is nutty is.. they PAY MONEY for the SMS method! I do not understand why more sites don't support TOTP like Google Authenticator.

Google authentication is great, until it's time to get a new phone.

1Password can store 2FA and will auto-fill them on desktop and mobile.

Re: The bleak picture of two-factor authentication adoption in the wild

#43
post #25

Earlier quoted context omitted.

Check out Authenticator Plus - its another TOTP app that lets you backup your (encypted) 2FA secrets and optionally syncs them across devices. Thankfully Google Authenticator is just TOTP, so you can use whatever client you want.

Also, check out andOTP on F-Droid: https://f-droid.org/en/packages/org.shadowice.flocke.andotp/ Open source and supports backups.

andOTP is amazing, I thoroughly recommend it.

Re: The bleak picture of two-factor authentication adoption in the wild

#44
The failure mode of TOTP, SMS is that the user needs to be sure to be connected to the correct site.

The hidden assumption is that the use is able to distinguish the fake from the correct site.

For any authentication system to work in the face of adversaries trying to confuse a user, the system needs to be robust against that.

https://eccentric-authentication.nl/blog/2014/11/30/spot-the...

https://eccentric-authentication.nl/blog/2016/11/18/on-the-i...

Re: The bleak picture of two-factor authentication adoption in the wild

#45
post #19
post #2

I was having an argument over 1password's 2fa support not being a second factor. (I don't think it is.) However, it is so much safer than not using 2fa. In similar terms U2F is amazing and keeps you from being phished and has a great challenge/response protocol, if that was implemented in 1password (or browsers themselves thank you!) we'd all be a lot safer than not using it at all. In 2018 I'm using an app to take s…

> (I don't think it is.) If your master password is someone exposed, then nothing really protects you.

This is not true. 1Password could have a breach which exposes your master password. A hacker would then have access to your passwords, but not your 2fa. Even if you do not keep these items physically separated like a hardware token, it makes complete sense to have them be in different applications. For example, passwords in 1Password and tokens stored in Authy.

Re: The bleak picture of two-factor authentication adoption in the wild

#46
post #25

Earlier quoted context omitted.

Also, check out andOTP on F-Droid: https://f-droid.org/en/packages/org.shadowice.flocke.andotp/ Open source and supports backups.

andOTP is amazing, I thoroughly recommend it.

Had no idea about this. I liked Google's Auth since it was simple but it missed the crucial backup feature. Authy is nice but you're putting trust in a 3rd party that doesn't have a channel for donations, though it seems they're making money through SMS (Twilio).

andOTP is just what I was looking for since it's FOSS and had backup! This would have been a lifesaver when I lost my phone but glad to have run into it now.

Re: The bleak picture of two-factor authentication adoption in the wild

#47
post #2

I was having an argument over 1password's 2fa support not being a second factor. (I don't think it is.) However, it is so much safer than not using 2fa. In similar terms U2F is amazing and keeps you from being phished and has a great challenge/response protocol, if that was implemented in 1password (or browsers themselves thank you!) we'd all be a lot safer than not using it at all. In 2018 I'm using an app to take s…

Afaiu 2fa primarily protects from password leaks on the part of the service and coincidentally some other kinds of leaks such as keylogging. Not so much from data theft on the user's side.

A different question, though, is whether a password keeper web service could leak passwords like any other service.

Re: The bleak picture of two-factor authentication adoption in the wild

#48

For those among us who can handle our passwords and general security, 2FA is just a penalty we have to pay for those who can't. As far as possible, I ditch any company that wants to force it upon me. I've done my homework, I don't want to consult my telephone, my mailbox, or even worse, some pesky dongle to complicate my life and add to my expenses.

So you trust all the services you use to never leak your password. Good luck with that.

Re: The bleak picture of two-factor authentication adoption in the wild

#49

Earlier quoted context omitted.

Google authentication is great, until it's time to get a new phone.

1Password can store 2FA and will auto-fill them on desktop and mobile.

I do this too. I guess it sort of undermines the idea of a second factor but the only way someone could get at it would be to break into my 1Password account, which seems unlikely.

Re: The bleak picture of two-factor authentication adoption in the wild

#50
post #48

For those among us who can handle our passwords and general security, 2FA is just a penalty we have to pay for those who can't. As far as possible, I ditch any company that wants to force it upon me. I've done my homework, I don't want to consult my telephone, my mailbox, or even worse, some pesky dongle to complicate my life and add to my expenses.

So you trust all the services you use to never leak your password. Good luck with that.

Whatever gives you that idea?
Post reply on HN