Live data from Hacker News

The bleak picture of two-factor authentication adoption in the wild

elie.net

51–60 of 96 posts

Re: The bleak picture of two-factor authentication adoption in the wild

#51
post #47
post #2

I was having an argument over 1password's 2fa support not being a second factor. (I don't think it is.) However, it is so much safer than not using 2fa. In similar terms U2F is amazing and keeps you from being phished and has a great challenge/response protocol, if that was implemented in 1password (or browsers themselves thank you!) we'd all be a lot safer than not using it at all. In 2018 I'm using an app to take s…

Afaiu 2fa primarily protects from password leaks on the part of the service and coincidentally some other kinds of leaks such as keylogging. Not so much from data theft on the user's side. A different question, though, is whether a password keeper web service could leak passwords like any other service.

> Afaiu 2fa primarily protects from password leaks on the part of the service and coincidentally some other kinds of leaks such as keylogging. Not so much from data theft on the user's side.

2FA is meant to protect primarily against phishing. It happens to protect against some other attacks as well, but phishing is the primary motivation.

That's why physical U2F devices are considered the gold standard of authentication today - it's possible to phish a TOTP code, but it's very difficult to phish a U2F signature, and impossible to do so through a scalable, automated attack.

Re: The bleak picture of two-factor authentication adoption in the wild

#52
post #3

It completely blows my mind that blizzard got it right over a decade ago with a dedicated physical device that would generate a one-time, time sensitive key for second factor authentication (to protect my video game account). Where as I feel I'm still waiting for my bank (actual money) to catch up. they took the easy way out by sms-ing me a second factor authentication key. Even though phone number theft is a known a…

agreed: my investment bank (real "real" money) finally started offering an authenticator (that adds random numbers to your password every login) two years ago.

i worked at a major semiconductor company in the late 1990's and to use their VPN from home you needed an authenticator fob. eventually this was replaced with a password, but hardware fobs (& parellel port dongles) have been around since at least the 80's. astonishing this has taken so long.

although i still have trouble understanding how to best protect myself against MYSELF. I'm just now getting my head around multiple yubikeys and subkeys in case i get locked out.

Re: The bleak picture of two-factor authentication adoption in the wild

#53
post #27
post #17

Earlier quoted context omitted.

The right way to do it is to use client-side TLS certificates in combination with the username and password. Add in a passphrase for the private key and you could have 3FA. All that's really needed is for browser vendors to improve their UI for generating certificate signing requests and importing certificates.

No, the right way is U2F. You touch a dongle and you're in. And there's no way to steal your key without physically getting the dongle.

Yes, but one has to buy another device, and only a limited number of companies support it at the moment [1]. It doesn't look like any of the banks I use, any of the credit cards I use, or the tax filing service I use support it. Not to mention that this website and other forums I log into aren't mentioned there either.

Some of those companies offer SMS or email based 2FA as an option.

In any case, every single one of those services allows me to connect using TLS where my browser verifies the server's identity via the CA bundle I have installed on my machine. I simply don't see why companies don't make the investment to support client-side TLS authentication or start supporting U2F.

> And there's no way to steal your key without physically getting the dongle.

I would contend that it's probably easier to steal the dongle as opposed to my machine at home.

[1] https://www.yubico.com/works-with-yubikey/catalog/

Re: The bleak picture of two-factor authentication adoption in the wild

#54
post #36

Earlier quoted context omitted.

What is the difference between an extra branded physical token and a 2FA app, such as Authy, on your phone?

One requires a mobile phone to function (and continue functioning), whereas the physical token only needs itself.

It's disturbing how many developers simply gloss over the fact that requiring a smartphone with one of two non-free OSes installed (Android and IOS) is severely limiting the user's freedom in their use of digital services.

In the Netherlands the ING bank was testing the waters this year by holding back on announcing a non-smartphone alternative to their ageing authentication methods (either SMS or a list of pre-generated codes received by mail). All of their communication was bent on nudging customers to use their banking smartphone app, and only at the end of this year did they announce a separate hardware solution for customers who don't want to, or cannot, use a smartphone for their banking.

Every other bank in the Netherlands already had such hardware devices (TOTP usually, although newer generations use more complex methods) for a decade.

U2F and its successors are the way forward if we want to maintain some semblance of digital freedom, not tying your whole identity to a smartphone.

Re: The bleak picture of two-factor authentication adoption in the wild

#55
post #34
post #17

Earlier quoted context omitted.

The right way to do it is to use client-side TLS certificates in combination with the username and password. Add in a passphrase for the private key and you could have 3FA. All that's really needed is for browser vendors to improve their UI for generating certificate signing requests and importing certificates.

Meanwhile usability cries in a corner.

It could be said that having my identity "stolen" and having to deal with the fall out is a far bigger real-life usability issue as compared to having to deal with a one time set up to use client-side TLS certificate with a service like my bank.

Re: The bleak picture of two-factor authentication adoption in the wild

#56
post #53
post #27

Earlier quoted context omitted.

No, the right way is U2F. You touch a dongle and you're in. And there's no way to steal your key without physically getting the dongle.

Yes, but one has to buy another device, and only a limited number of companies support it at the moment [1]. It doesn't look like any of the banks I use, any of the credit cards I use, or the tax filing service I use support it. Not to mention that this website and other forums I log into aren't mentioned there either. Some of those companies offer SMS or email based 2FA as an option. In any case, every single one of…

There are others which aren't listed there, like OVH (the largest European hosting company). The dearth of banks is real though. And sad.

I have only seen client-side certificates used twice. Once at now infamous StartSSL and second at a bank but for vendor access, not regular customers.

Its huge downside is that it's a second factor which doesn't protect against a compromised device.

Re: The bleak picture of two-factor authentication adoption in the wild

#57

Earlier quoted context omitted.

Google authentication is great, until it's time to get a new phone.

If you have 1Password it supports OTP and thus can be used across devices.

Whenever discussing this with colleagues there’s always been a bit of debate about whether OTP inside 1password constitutes 2FA or not.

On the one hand a password could be popped from the target site or phishing, and you’d still need the 2nd factor from 1password to get in.

But on the other hand, if you leave your phone lying around unlocked with a poor master password, both get popped together.

Re: The bleak picture of two-factor authentication adoption in the wild

#58

Earlier quoted context omitted.

Google authentication is great, until it's time to get a new phone.

If you have 1Password it supports OTP and thus can be used across devices.

LastPass has this too I think. But something seems off to me storing my 2FA with the service that manages my first factor.

YubiKeys can store and access OTP secrets. I put the secret in both Google Authenticator and my YubiKeys as backup.

Re: The bleak picture of two-factor authentication adoption in the wild

#59
It just irritates me how many financial institutions either don't support 2FA (I'm looking at you, Amex) or only offer either SMS or (yes, really) email as the only way(s) to protect your account.

Vanguard recently required that all accounts be "secured" via SMS, and I was dismayed to learn that Nest (of all companies) didn't even support Google Authenticator -- the only option with Nest was to use SMS as well.

It just seems like a losing battle at this point.

Re: The bleak picture of two-factor authentication adoption in the wild

#60
For all you PNW Microsofties, I saw that First Tech credit union finally got their shit together after the system change and reimplemented 2FA using a hardware key. Great, sign me up! First I get a message asking if I really want a hardware key? Well, I’d rather use the U2F keys I’ve already got, but yeah, send me one. The fact that it showed up in a hand-addressed envelope tells you how many of these they’re sending out.

No matter, I’ll use the phone authenticator for day-to-day, and the HW key as a backup. Not optimal, but until they support U2F it’ll have to do. Nope, you get to pick one key. So the HW key goes in the safe, and I use SMS for day-to-day. Or IOW, might as well have saved the plastic and postage for that HW key.

EDIT: someone else suggested directing email codes to an account that is protected by a HW key. Firing up GMail on my phone I less convenient than reading the SMS code off my watch, but I’ll probably do that.

Post reply on HN