Live data from Hacker News

Gitlab Support is no longer processing MFA resets for free users

about.gitlab.com

111–120 of 228 posts

Re: Gitlab Support is no longer processing MFA resets for free users

#111

Earlier quoted context omitted.

Isn't there Authy?

Authy's SMS convenience/reliance undermines the whole thing. Avoid.

Authy supports symmetrically encrypting your OTP codes with a password which is fine IMO: https://authy.com/blog/how-the-authy-two-factor-backups-work...

Re: Gitlab Support is no longer processing MFA resets for free users

#113

Good - 2FA is the responsibility of the user and resetting it kind of invalidates the security it helps bring. I think the bigger issue is that people's 2fa codes are still tied to their phone. You can lose your phone at any moment, which is why i've always disliked apps like Google Authenticator which don't let you export 2fa keys (for good reason). I personally use 1password, but there's definitely room for a cloud…

I use AndOTP which allows you to encrypt, export and import the OTP database.

Re: Gitlab Support is no longer processing MFA resets for free users

#114

Good - 2FA is the responsibility of the user and resetting it kind of invalidates the security it helps bring. I think the bigger issue is that people's 2fa codes are still tied to their phone. You can lose your phone at any moment, which is why i've always disliked apps like Google Authenticator which don't let you export 2fa keys (for good reason). I personally use 1password, but there's definitely room for a cloud…

> Good - 2FA is the responsibility of the user and resetting it kind of invalidates the security it helps bring.

Actually, no. This is a terrible idea.

Think about the psychology of what you are telling people: "You have two choices - one is normal security, which you use on 80%+ of the rest of the internet, and one is 2fa which you only use on the annoying services that badger you into it. On the first one, if you lose your password you can do a password reset. On the second one, if your laptop and phone get fried in a rainstorm / car crash / act of children, you lose access to everything forever, no recourse and no recovery. And by the way, we totally encourage you to choose the second one... "

Yes, online services that store credentials and backup passwords mitigate this somewhat, but they also add an attack vector via keyloggers, or make you dependent on the third party's security measures.

And I probably don't need to point out to the HN crowd just how badly internet services are moving towards no-recourse solutions to petty problems to save money. Yet another one doing this is not a good thing.

Re: Gitlab Support is no longer processing MFA resets for free users

#115
post #84

Earlier quoted context omitted.

As someone who travels frequently and has moved to different countries, SMS is the absolute worst. If a service asks me to verify my number after crossing a border, the chances of me ever being able to log into that account ever again are basically zero. Then there's Google. Google doesn't have a phone number on file for me, but they sometimes demand that I input a phone number and enter a verification code to access…

This is a very niche case. Why can't you recieve sms abroad? Do you leave your phone behind when you travel? Why can't you give Google your current phone number?

> Why can't you recieve sms abroad?

Because my SIM card is useless the minute I'm outside of its recognized area.

> Why can't you give Google your current phone number?

Because my phone number is useless the minute I'm outside of its recognized area.

My old bank accounts have my old phone number on record. It hasn't been my phone number in 6 years and they don't accept phone numbers from my current country.

I'm not going to give Google my current phone number, because if it changes again, I'll be locked out of those accounts forever should I move or change numbers again. As it is, I can still login while having someone lend me a phone and making my account completely insecure.

Re: Gitlab Support is no longer processing MFA resets for free users

#116
post #100

Earlier quoted context omitted.

Google Authenticator now allows you to export your keys to another phone. I keep my keys in analog form - I print QR code for every service. We know how to handle valuables stored on paper.

Would you be willing to describe the process you use to do this?

I have only two copies - one stored in home for quick access if needed, second in bank storage locker with all other my documents.

Re: Gitlab Support is no longer processing MFA resets for free users

#117
post #105
post #100

Earlier quoted context omitted.

Would you be willing to describe the process you use to do this?

Screenshot the QR Code and print it? Put it in a vault or store somewhere safe. It’s a standard practice for securing enterprise accounts (AWS root acc. for example)

You can't screenshot it.

The app puts a no screenshot request, so you have to scan the qr code from another phone.

Re: Gitlab Support is no longer processing MFA resets for free users

#118
post #110
post #89

Earlier quoted context omitted.

I'm currently using andOTP. Just to throw some more news of good OSS MFA apps out there.

Also, Aegis: https://github.com/beemdevelopment/Aegis

Icons Pack/logos for the sites stored in Aegis.

https://github.com/krisu5/aegis-icons

Just extract the zip, and you can input any photo to the Aegis app

Re: Gitlab Support is no longer processing MFA resets for free users

#119

Is it just me, or does this make my MFA-protected account safer? I wish conpanies offered this as a feature, in the sense I'm much more worried about someone SEing their way into my account rather than me losing access to all my MFA methods and backup codes or whatever.

It makes your MFA-protected account safer from takeover, but also creates a new risk of completely losing access to your account and username forever.

Github has the same policy, and it deterred me from using MFA for a long time, and when I finally did, I added a large number of alternatives, including the not-so-secure SMS.

I think the fear of being temporarily unable to access your account is already a major reason why people don't use MFA. Turning the threat into a permanent loss will make people even more reluctant to do it.

Dealing with some of the backup methods (e.g. off-site copies of backup codes) is tedious, and I wouldn't be willing to do it for less important sites. If I had 2FA on Gitlab, I'd probably turn it off now. (Actually, just saw they don't have an option to add a phone number - I'd definitely turn it off.)

Re: Gitlab Support is no longer processing MFA resets for free users

#120
post #108

Good - 2FA is the responsibility of the user and resetting it kind of invalidates the security it helps bring. I think the bigger issue is that people's 2fa codes are still tied to their phone. You can lose your phone at any moment, which is why i've always disliked apps like Google Authenticator which don't let you export 2fa keys (for good reason). I personally use 1password, but there's definitely room for a cloud…

The problem with storing the 2FA keys in 1Password is that you're practically downgrading your account to 1FA because once 1Password is compromised, the second factor lost all of its value, though that compromise is much harder to achieve than a compromised shared machine I'm typing my password in on (which you probably also should never do). I'm saying this as I'm looking at my 1Password database which also contains…

Yes, in 1Password's 2FA announcement its head of security mentions that using 2FA in 1PW does not give you true 2FA:

> If you would like to turn a site’s offering of TOTP into true two-factor security, you should not store your TOTP secret in 1Password (or in anything that will synchronize across systems).

They mention multiple times that if you want true 2FA the second factor needs to be on a different device or a physical key like a YubiKey.

Then they say that “two-step” security offered by 1PW + 2FA is probably enough for most use cases, and that 2FA in 1PW still has additional value because (a) some sites require 2FA and (b) one-time passwords offer protection against sniffing passwords over insecure networks.

https://blog.1password.com/totp-for-1password-users/

The fact that 1PW even auto-copies the code to your clipboard after auto-filling a password so that you can paste it in when prompted raised my eyebrows when I first used the feature, though. It's very convenient but it's obvious at that point that you're throwing away the protection that storing the key on a second device would offer, even if 1PW requires you to authenticate before the app will open.

Post reply on HN