Live data from Hacker News

That's not how 2FA works

shkspr.mobi

231–240 of 269 posts

Re: That's not how 2FA works

#231
Something people here are missing is that unless the phishing site uses your credentials right then and there within the existing session, they can't do much even if they do capture your 2nd factor.

But if the site just captures your credentials and puts them in a database of site/username/passwords, they are useless later, even if they also store your 2nd factor of the moment. The next time someone tries to authenticate with your stolen username and password, and the MFA challenge comes up, they will be stuck. The factor they captured phishing has long expired, and the site has no ability to provide the correct value for your 2nd factor at a later time.

So in other words, 2FA does provide additional protection in this scenario, unless the malicious party has programmed the system to also hijack your session.

I honestly can't say for sure how often the phishing sites use session hijacking vs. just collecting for later use. If the first scenario is most common then no, 2FA doesn't help much. If the second scenario is typical, then 2FA provides significant additional protection over just username/password.

Re: That's not how 2FA works

#232

So almost nothing can be done because > The top result on Google is invariably an advert for a scam site. No, use an adblocker. It's the modern antivirus and you should use one.

Except as others have noted this statement is an exaggeration at best.

Re: That's not how 2FA works

#233
post #20

Not sure why the author is so negative on Yubikey. His only reason is that an attacker can steal his laptop with the key plugged in. That’s a user error. I much rather have Yubikey over all other forms of security because it simply forces the attacker to be physically present. Why is that important? Because even if your laptop is stolen with your Yubikey at a local Starbucks, you’re more likely to catch that person v…

Author here. I did provide a few other reasons - mostly around usability of YubiKeys. Try observing a non-techie set one up and tell me if you think it is as easy as it could be. Realistically, you're probably not going to catch a mugger. Otherwise robberies like that wouldn't occur. Snatching a laptop with a key physically plugged in it is probably easier than snatching a laptop and a separate phone. Regardless of m…

[deleted]

Re: That's not how 2FA works

#234

Something people here are missing is that unless the phishing site uses your credentials right then and there within the existing session, they can't do much even if they do capture your 2nd factor. But if the site just captures your credentials and puts them in a database of site/username/passwords, they are useless later, even if they also store your 2nd factor of the moment. The next time someone tries to authenti…

This is true for all 2FA methods but not for FIDO security keys. With FIDO, the hostname of the site you're browsing is signed in the assertion, therefore the attacker -even with automation- can't reuse it on the target site.

This is why FIDO claims protection against phishing.

What the author says is that the attacker, when you're using a FIDO security key, can simply say it's not working and force the user to switch to a different 2FA method, therefore in the end phishing the user.

Re: That's not how 2FA works

#235

They author makes a few good points, but I find the author's critique of Yubikey weak: >Cost. The average YubiKey is £50... If that's too expensive for ensuring your internet security, then either you underestimate the risks, or undervalue your information. If a Yubikey cost 10 times more it would still be a bargain. >Usability. Buy a device, register it, install the app, configure it, find the setting in the website…

> YubiKeys have no password lock of their own I don't know if the author of the blog post means something else but if you're using 2FA tokens (i.e. Yubikey Authenticator) you can put password protection for additional security.

Yubikeys have PIN for FIDO2 passwordless auth, see `ykman fido set-pin` command (IIRC, there a GUI for this as well but I don't have a single passwordless login - to best of my awareness, no single website on the web that I use seem to support this).

This is different from typical U2F operations, though, where website asks for a password ("know") and a hardware token ("have"). For those, password is the secret part already.

If someone phished someone's password AND stole one's Yubikey - well, this is a very peculiar situation, where, indeed, the scenario fails. If someone steals a laptop with Yubikey plugged in - they (hopefully) don't have passwords. Unless someone had set it up to login and open their password manager with just a touch of the said Yubikey, without anything extra. Which is, again, quite a peculiar situation.

Re: That's not how 2FA works

#236
I think the negative aspects stated by the "hardware authentication device" is overkill. It's really easy to use and cost is relative (gets cheaper with use). May be real issue is that we're not using these new solutions and are still relying on unnecessarily complex passwords to save with master passwords. In some cases, 2FA can be a pain in the butt to manage when you have hundreds of them. A couple hardware keys and voila.

Re: That's not how 2FA works

#237
post #224

All the complaints made about yubikey and webauthn could be made about 2fa 5-10 years ago. Hardware tokens gated by software (ala yubikey + webauthn) are clearly the next step in auth. It’s an accident of circumstance you even need to buy a yubikey - your iPhone, iPad, laptop, android whatever can do everything a yubikey does. There just needs to be enough demand and time for OS and hardware vendors to come around to…

Why don't we just skip to 4fa, now. (though it might be tough for chimeras who have 2 sets of dna)

Maybe they can pioneer 5fa.

Re: That's not how 2FA works

#238

Something people here are missing is that unless the phishing site uses your credentials right then and there within the existing session, they can't do much even if they do capture your 2nd factor. But if the site just captures your credentials and puts them in a database of site/username/passwords, they are useless later, even if they also store your 2nd factor of the moment. The next time someone tries to authenti…

Session jacking can also allow disabling MFA unless sites are careful to re-verify the MFA before doing so. Or before changing the password or adding additional tokens / generating backup codes.

Security is hard. And features make it porous.

Re: That's not how 2FA works

#239
post #213

Earlier quoted context omitted.

So.... not a scam, in that you get exactly what you pay for. And certainly not phishing, which this article was talking about.

How is this not a scam? The company is just presenting their form to ask for the same information, relaying it to the government, and charging you $90 for the privilege.

To me a scam involves paying money and then not getting anything for it. You get exactly what you pay for.

These is just competing businesses / orgs vying for your custom, where one org (the govt) is charging $0, so you should totally use them, but won't if you're foolish.

Regardless, one tiny example of all google results (goverment form services) is... the vast minority of google search results. It is certainly not "invariably" a scam.

Re: That's not how 2FA works

#240
post #221

Earlier quoted context omitted.

The article's first and most prominent criticism is that it costs at least $30-$60, which might be a barrier to mass adoption but for most HN readers is not a serious reason not to use it.

I own two (one as a backup in my safe in case I lose this one. They all have the same TOTP stuff and setup in every service side by side where possible), to agree with you. Though it’ll be lovely when your iPhone can be a U2F key through their hardware security chips and some OS support, if I’m dreaming out loud.

Have I got good news for you: https://webkit.org/blog/11312/meet-face-id-and-touch-id-for-... - ICYMI WebAuthn is the successor to U2F.
Post reply on HN