Live data from Hacker News

That's not how 2FA works

shkspr.mobi

191–200 of 269 posts

Re: That's not how 2FA works

#191

Earlier quoted context omitted.

Yes. You must have at least two keys registered. However it’s worth noting that most services do not offer priority. Meaning you can use either one. I think it makes sense to designate back up keys and only to be used when user reports lost/stolen primary key.

But what is the story there? You have a backup key, hopefully stored "off site", now you want to enroll in another website. You have to get that backup key before you do that? Or bookkeep which sites you have on the backup key and which you don't?

Actually, this is one area where pgp's use in pass works really well. You use your public key to encrypt passwords. So, adding a new one doesn't need the physical key.

Re: That's not how 2FA works

#192
post #109
post #104

The linked article is correct, but uncharitable. It correctly states the behavior of two-factor auth systems but incorrectly understands their value . Yes, 2FA won't protect you from being phished by a site if you aren't careful. 2FA absolutely will protect you from a phishing site using the password it stole. So no, when someone says "Use 2FA if you might be phished" you shouldn't be replying "That's not how 2FA wor…

The attacker could proxy the 2FA request from the real site using the password you enter and therefore you wouldn't be protected.

Right, they could have access to your account, but not full access. A good website will ask for 2FA again if a user tries to do something destructive (like change password, email, or disable 2FA). They wouldn’t be able to do those things.

Re: That's not how 2FA works

#193
post #96

Earlier quoted context omitted.

Some other responders have given you the answer as it currently exists. They are all either inconvenient, weaken security, or both. For that reason, I would only suggest using a security key for a small number of critical services, where it's worth the extra effort to deal with the backup mechanisms. However, a good solution for this issue is finally in the works: https://www.yubico.com/blog/yubico-proposes-webauthn-…

Having two keys, one of which you keep in a secure place, seems pretty simple and intuitive to me.

What does your workflow look like when you set up new credentials?

Re: That's not how 2FA works

#194
post #109

Earlier quoted context omitted.

The attacker could proxy the 2FA request from the real site using the password you enter and therefore you wouldn't be protected.

Right, they could have access to your account, but not full access. A good website will ask for 2FA again if a user tries to do something destructive (like change password, email, or disable 2FA). They wouldn’t be able to do those things.

[deleted]

Re: That's not how 2FA works

#195
You don't need a $50 Yubikey token to do U2F, there are ones in the $10-15 range.

Most sites that support U2F support enrolling multiple tokens, so just have one in each machine.

Theft of a machine still needs your password to access the accounts, so it's not "keys to the kingdom" as the article suggests.

I feel that this article is... wrong.

Re: That's not how 2FA works

#196

They author makes a few good points, but I find the author's critique of Yubikey weak: >Cost. The average YubiKey is £50... If that's too expensive for ensuring your internet security, then either you underestimate the risks, or undervalue your information. If a Yubikey cost 10 times more it would still be a bargain. >Usability. Buy a device, register it, install the app, configure it, find the setting in the website…

Just because it’s a website problem , it doesn’t stop being a problem. Usability is important if you want adoption outside of the HN crowd.

It is a problem anyway, I agree. It's incorrect to attribute the problem specifically to Yubikeys.

Re: That's not how 2FA works

#197
post #91

Earlier quoted context omitted.

If my Yubikey gets stolen, how do I log in into my accounts? Serious question; never understood how that works.

I have a backup U2F device. You can register multiple with any account. If I somehow manage to lose both, I assume I’ll have to talk to a customer support rep or something.

This depends on the service supporting it though, and not all of them do (e.g. AWS).

Re: That's not how 2FA works

#198
post #188

Earlier quoted context omitted.

> may I suggest spending a couple of days volunteering for a local Victim Support charity. Please try being less condescending. Losing the keys, due to whatever reason, means losing one factor. If the user loses the key, the "mugger" still needs to get the users' passwords. 2FA = something you know + something you own. Having one factor compromised should not compromise your accounts if the service you are using is c…

What’s the second factor with yubikey? The site seems to say it’s passwordless.

A yubikey doesn't replace a password.

Re: That's not how 2FA works

#199
post #30

Earlier quoted context omitted.

I have helped literally hundreds of people setup Yubikeys across several companies. Your take is just not my experience at all. Tapping a blinking light it is much easier than fussing with a 2FA app and works when someone's phone is dead. Yubikeys in particular are near indestructible. They even work after you soak them in acetone overnight and melt the plastic off. I tried. When it says "plug in your device" you plu…

If my Yubikey gets stolen, how do I log in into my accounts? Serious question; never understood how that works.

Second yubikey ;)
Post reply on HN