Live data from Hacker News

That's not how 2FA works

shkspr.mobi

61–70 of 269 posts

Re: That's not how 2FA works

#61
for one, html email is vicious, terminal email clients can help to not fool you with visual alignment.

I like the feature `From: via ` in the view, maybe this tipped her off - "palette.cloud" is an unlikely envelope-sender for github mail. Reactivating an old gmail account, I can't see how to enable the feature.

In a muttrc, you can get context with showing you more headers.

  ignore *
  unignore from: to: cc: date: subject: user-agent: x-mailer: return-path: authentication-results:
  hdr_order date: from: return-path: to: subject: user-agent: x-mailer: authentication-results:
A client could by default show "unverified" and use spf+dkim to get to verified. The "unverified" could be signal enough to enable spidey sense

Re: That's not how 2FA works

#62
post #30

Earlier quoted context omitted.

I have helped literally hundreds of people setup Yubikeys across several companies. Your take is just not my experience at all. Tapping a blinking light it is much easier than fussing with a 2FA app and works when someone's phone is dead. Yubikeys in particular are near indestructible. They even work after you soak them in acetone overnight and melt the plastic off. I tried. When it says "plug in your device" you plu…

If my Yubikey gets stolen, how do I log in into my accounts? Serious question; never understood how that works.

The last time I've used the configurators on Windows and Linux they provide the private key material for one to backup.

Re: That's not how 2FA works

#63
post #30

Earlier quoted context omitted.

I have helped literally hundreds of people setup Yubikeys across several companies. Your take is just not my experience at all. Tapping a blinking light it is much easier than fussing with a 2FA app and works when someone's phone is dead. Yubikeys in particular are near indestructible. They even work after you soak them in acetone overnight and melt the plastic off. I tried. When it says "plug in your device" you plu…

If my Yubikey gets stolen, how do I log in into my accounts? Serious question; never understood how that works.

That’s how 2FA works. It’s a physical token.

You either have other 2FA devices or backup codes.

Re: That's not how 2FA works

#64
post #20

Earlier quoted context omitted.

Author here. I did provide a few other reasons - mostly around usability of YubiKeys. Try observing a non-techie set one up and tell me if you think it is as easy as it could be. Realistically, you're probably not going to catch a mugger. Otherwise robberies like that wouldn't occur. Snatching a laptop with a key physically plugged in it is probably easier than snatching a laptop and a separate phone. Regardless of m…

I agree on the idea around usability of YubiKeys. I have them also and believe they are great, but I never seem to have them when I need them. Of course, maybe its on another floor or another room and I am being lazy not walking over there, but it is an added inconvenience on a process that needs to be balanced between security and convenience.

Adding a rotating 2FA to a password database, for one.

Re: That's not how 2FA works

#65
post #14

Earlier quoted context omitted.

Try browsing the web without an ad blocker. The top results on Google search are always adverts. And, quite often, they link to scam sites. There are loads of copycat websites which appear in the top slot - especially for government site. https://www.which.co.uk/consumer-rights/advice/how-to-spot-a... It's particularly prevalent in the UK, where you see companies proxying legitimate services and charging premium rate…

How can this pass through Google 's quality controls that scam sites can get advertising?

...quality controls? They're paying customers, Google has no incentive to prevent scam sites, which is why the results and adverts are infested with them, and have been for decades.

Re: That's not how 2FA works

#66
post #50
post #16

Mostly agree with a lot of this, but it's a little unfortunate to lump all WebAuthn authenticators together. WebAuthn keys--physical dongles you plug into the USB port--are indeed problematic for the reasons the author notes. (A small--but user-visible--cost; the requirement for a spare USB port of the right form factor; loss.) However, authenticators that are built into the client device (e.g. Apple's support for a…

I use Krypton [0] as a virtual YubiKey, I like it a lot but they got acquired by Akamai and the GitHub accounts have gone worryingly quiet. [0] https://krypt.co

That's cool. Either I haven't seen this before or I've forgotten. :)

I do think (as I said elsewhere here) that ultimately people will adopt WebAuthn via their browser/OS vendor. Support is widespread! But for relying parties, there are still challenges to solve.

Re: That's not how 2FA works

#67
post #19

The Yubikey/WebAuthn comments are really ignorant and discouraging people from the best defense against this sort of attack that exists. First of all you can get WebAuthn devices for as little as $10 now. Second, there is no app to configure. You plug it in when it says register and tap it. Done. Third, if the WebAuthn device gets stolen the attacker presumably lacks a password. You can't use the device by itself. Al…

For the reasons listed in the article and more, Yubikeys and similar devices aren’t likely to ever be popular. To give future security devices along the same vain a better chance at gaining popularity and being widely adopted (which will hopefully bringing us a more stable, less stressful society), the designs of these new devices must solve or workaround the issues the author describes. It’s really annoying when ind…

I use a Yubikey daily and the OP is greatly exaggerating the issues in my opinion. Vanguard for example it took less than a minute to set up. I don't have an "application" installed locally for the Yubikey, it was plug & play. No special software needed.

I honestly think Yubikey type devices' largest problems are - 1. Marketing. People simply do not know they exist or how they work (simple or not). 2. Support - Many websites do not support Webauthn yet. We really need developers and businesses to consider this a priority.

I have bought some keys for my family members and they love them once I demonstrate how they work.

Re: That's not how 2FA works

#68
post #14

Earlier quoted context omitted.

Try browsing the web without an ad blocker. The top results on Google search are always adverts. And, quite often, they link to scam sites. There are loads of copycat websites which appear in the top slot - especially for government site. https://www.which.co.uk/consumer-rights/advice/how-to-spot-a... It's particularly prevalent in the UK, where you see companies proxying legitimate services and charging premium rate…

Can you give me an actual example of this with a google search right now?

I just did an ingonito search for "!g ETA",

I got 3 results on the screen

CanadianTravel - ETA Ad·www.canadaonlineapplication.org/

CanadianTravel - ETA Ad·www.canadatravelvisa.com/

CanadaETA - for UK citiziens - canadian-etavisas.com Ad·www.canadian-etavisas.com/

Which all look the same, and seem to charge $99 for the 'service' of filling in a form the Canadian government charges $7 for.

After that there is a wikipage for the Spanish terrorist group, two more wiki pages, then finally

The official site: Electronic Travel Authorization (eTA): How to apply - Canada.ca

Searching google for "Canada ETA" gives the above 3 adverts and also a link to https://www.etatocanada.com/ which charges £69 for the service.

Re: That's not how 2FA works

#69
> Risk. YubiKeys have no password lock of their own. At least my crumby Android has a fingerprint lock to prevent people getting my 2FA tokens. But if you’ve stolen my laptop and the YubiKey is plugged in, then you’ve got the keys to my kingdom.

The key is only the second factor. You need to lose the key *and* have your password stolen in order to have your accounts compromised. At that point, think about what you're doing wrong as a user.

Re: That's not how 2FA works

#70

Earlier quoted context omitted.

For the reasons listed in the article and more, Yubikeys and similar devices aren’t likely to ever be popular. To give future security devices along the same vain a better chance at gaining popularity and being widely adopted (which will hopefully bringing us a more stable, less stressful society), the designs of these new devices must solve or workaround the issues the author describes. It’s really annoying when ind…

I think Yubikey (and similar physical solutions) will eventually gain popularity. Carrying a key is pretty much a standard practice across the globe and benefit is more than negligible because it forces physical attack versus remote/virtual.

Instead of a hardware authenticator to be carried on a keyring, they should be put into rings, i.e., the things meant to be worn on your fingers, i.e., the things that most people use for providing input to their computing devices, whether they sit on a desk or are held in one's hands.
Post reply on HN