Live data from Hacker News

That's not how 2FA works

shkspr.mobi

71–80 of 269 posts

Re: That's not how 2FA works

#71
post #14

Earlier quoted context omitted.

Try browsing the web without an ad blocker. The top results on Google search are always adverts. And, quite often, they link to scam sites. There are loads of copycat websites which appear in the top slot - especially for government site. https://www.which.co.uk/consumer-rights/advice/how-to-spot-a... It's particularly prevalent in the UK, where you see companies proxying legitimate services and charging premium rate…

Can you give me an actual example of this with a google search right now?

In the UK there was a problem of commercial companies setting up look-alike websites and charging a fee to do stuff that is free to do via the correct gov website. It's not as common now, partly because UK orgs put pressure on Google to fix it.

Here's an example:

[change name deed poll]

https://www.google.co.uk/search?sxsrf=ALeKk00J9KQR_SH1ZlvHgi...

For me the top four links are clearly marked ads. (Although some people may miss that [ad] marker). After the ads there are two links to the proper gov.uk website. Then there's a link to a commercial site called "Deed Poll Office", who charge for a services that's free.

In the past that TheDeedPollOffice link ranked higher.

Similar things used to happen for passports and tax self assessment.

Re: That's not how 2FA works

#72

Earlier quoted context omitted.

How can this pass through Google 's quality controls that scam sites can get advertising?

...quality controls? They're paying customers, Google has no incentive to prevent scam sites, which is why the results and adverts are infested with them, and have been for decades.

It seems to be against AdSense's rules, however.

Apparently they aren't so enforced.

Good thing that Google is still going after you if your website has nudity on it it, however. — 'tis very important.

Re: That's not how 2FA works

#73
post #30

Earlier quoted context omitted.

I have helped literally hundreds of people setup Yubikeys across several companies. Your take is just not my experience at all. Tapping a blinking light it is much easier than fussing with a 2FA app and works when someone's phone is dead. Yubikeys in particular are near indestructible. They even work after you soak them in acetone overnight and melt the plastic off. I tried. When it says "plug in your device" you plu…

If my Yubikey gets stolen, how do I log in into my accounts? Serious question; never understood how that works.

Depends. Some have a bunch of magic numbers you can use as alternative "second factor", basically another password for the special purpose of bypassing a real 2nd factor. That's of course stupid and dangerous.

Then there are those where you can register another 2nd factor, e.g. another Fido-Key, SMS-Codes or recovery email. Those might be better or might be worse, depending on the method and circumstances. E.g. SMS is vulnerable to all kinds of SIM-Cloning and redirection stuff, email is vulnerable to whatever your email might be vulnerable to.

The only thing I would accept as really idiot-proof and secure is "go someplace, show a government-issued hard-to-fake ID" (like a passport, not your drivers license...) like banks do. But that only works with physically present businesses and accounts that are strictly tied to one person. And even there, "Joe Smith" might impersonate "Joe Smith"...

Re: That's not how 2FA works

#74
post #70

Earlier quoted context omitted.

I think Yubikey (and similar physical solutions) will eventually gain popularity. Carrying a key is pretty much a standard practice across the globe and benefit is more than negligible because it forces physical attack versus remote/virtual.

Instead of a hardware authenticator to be carried on a keyring, they should be put into rings, i.e., the things meant to be worn on your fingers, i.e., the things that most people use for providing input to their computing devices, whether they sit on a desk or are held in one's hands.

This is actually brilliant.

Re: That's not how 2FA works

#75

https://www.amazon.in/Auto-ePass-2003-FIPS-Token/dp/B00S7LUL... does anyone know if its posible to reuse these fips pki tokens? they are cheap enough.....

It's essentially a smartcard (certificate storage) in a more convenient form factor for most users, so you could use them to store your RSA keys - though personally I would not trust them - but they are not FIDO/FIDO2 so they are almost useless in the context of the article.

Re: That's not how 2FA works

#76
post #20

Not sure why the author is so negative on Yubikey. His only reason is that an attacker can steal his laptop with the key plugged in. That’s a user error. I much rather have Yubikey over all other forms of security because it simply forces the attacker to be physically present. Why is that important? Because even if your laptop is stolen with your Yubikey at a local Starbucks, you’re more likely to catch that person v…

Author here. I did provide a few other reasons - mostly around usability of YubiKeys. Try observing a non-techie set one up and tell me if you think it is as easy as it could be. Realistically, you're probably not going to catch a mugger. Otherwise robberies like that wouldn't occur. Snatching a laptop with a key physically plugged in it is probably easier than snatching a laptop and a separate phone. Regardless of m…

> may I suggest spending a couple of days volunteering for a local Victim Support charity.

Please try being less condescending.

Losing the keys, due to whatever reason, means losing one factor. If the user loses the key, the "mugger" still needs to get the users' passwords.

2FA = something you know + something you own. Having one factor compromised should not compromise your accounts if the service you are using is configured correctly.

Re: That's not how 2FA works

#77
post #38

Not sure why the author is so negative on Yubikey. His only reason is that an attacker can steal his laptop with the key plugged in. That’s a user error. I much rather have Yubikey over all other forms of security because it simply forces the attacker to be physically present. Why is that important? Because even if your laptop is stolen with your Yubikey at a local Starbucks, you’re more likely to catch that person v…

Another issue not mentioned by the author is what happens if the Yubikey is lost or breaks. The story around this type of event is sort of ignored and not understood properly. AFAIK it's not possible to duplicate a key (by design), meaning that the user will have to update all their websites' 2FA (hopefully there is a recovery method available).

While it's not possible to duplicate an existing key, it is possible to create duplicate keys in the first place - you can't get the secrets out, but you can write identical secrets to two or more keys if you want to.

This adds some convenience, though it also does add some risks e.g. in case of breach you can't tell which token was misused, you can't invalidate a lost key without invalidating others at the same time.

Re: That's not how 2FA works

#79
post #50
post #16

Mostly agree with a lot of this, but it's a little unfortunate to lump all WebAuthn authenticators together. WebAuthn keys--physical dongles you plug into the USB port--are indeed problematic for the reasons the author notes. (A small--but user-visible--cost; the requirement for a spare USB port of the right form factor; loss.) However, authenticators that are built into the client device (e.g. Apple's support for a…

I use Krypton [0] as a virtual YubiKey, I like it a lot but they got acquired by Akamai and the GitHub accounts have gone worryingly quiet. [0] https://krypt.co

> Krypton is built on top of an end-to-end verified and encrypted architecture. This means zero trust. We, Krypt.co, cannot access your keys or see where you're authenticating. The keys only live in the Krypton app on your phone.

Sounds great, except one of the "ends" is likely the Secure Enclave (iOS) or Keystore (Android), over which the user has basically no control. So while the architecture might require "zero trust" of Krypt.co, it still requires complete trust of Apple or Google.

Perhaps completely trusting one of those companies is already the reality for nearly everyone, in terms of using a mobile device to access online data, but hopefully WebAuthn-supporting sites don't put extra restrictions on the devices you can use, via the "feature" of attestation:

https://www.imperialviolet.org/2019/01/01/zkattestation.html

Re: That's not how 2FA works

#80
post #78

This is a weird post. Yubikeys are absolutley the solution here, also a password manager. A decent password manager will check the URL for you.

There are many legitimate situations in which a login domain is changed and a password manager no longer works. So then you manually open the password manager, look for the password, copy+paste, and save the new entry.

How can you be completely confident that this isn't an attacker?

Post reply on HN