The linked article is correct, but uncharitable. It correctly states the behavior of two-factor auth systems but incorrectly understands their value . Yes, 2FA won't protect you from being phished by a site if you aren't careful. 2FA absolutely will protect you from a phishing site using the password it stole. So no, when someone says "Use 2FA if you might be phished" you shouldn't be replying "That's not how 2FA wor…
2FA absolutely will protect you from a phishing site using the password it stole. Not if it also steals the 2nd factor. My response would be more like "2FA is good but not for this problem." This problem is about going to the wrong site. The solution is to go only to the right site.
That's not how 2FA works
241–250 of 269 posts
Re: That's not how 2FA works
#242Earlier quoted context omitted.
Also, I'm a big fan of U2F keys including Yubikeys. I don't use SMS, deprecated it 10 years ago in favor of e-mail, and would never use SMS for 2FA. I still have a virtual SMS number that forwards to my e-mail for the idiot sites that still insist on it. For most people, SMS is hackable, tied to a single battery-powered device, easy to steal (after which for most people in the default phone configuration the SMS veri…
> I still have a virtual SMS number that forwards to my e-mail for the idiot sites that still insist on it. Really? How? Last time I tried to do this it turned out that apps/sites would not send to these virtual SMS numbers.
B. Find a different virtual SMS number. Try other countries as well. Sometimes it costs a small monthly fee but I don't want to give in to their idiotic game.
Re: That's not how 2FA works
#243Earlier quoted context omitted.
Also, I'm a big fan of U2F keys including Yubikeys. I don't use SMS, deprecated it 10 years ago in favor of e-mail, and would never use SMS for 2FA. I still have a virtual SMS number that forwards to my e-mail for the idiot sites that still insist on it. For most people, SMS is hackable, tied to a single battery-powered device, easy to steal (after which for most people in the default phone configuration the SMS veri…
I would love to be a fan of Yubikeys, in fact most people would say I _am_ a fan of Yubikeys, I think I have like 10 of them (due to product evolution and always buying a few when I buy one). Unfortunately most of the sites I use do not have anything to do with them.
Re: That's not how 2FA works
#244Earlier quoted context omitted.
I would love to be a fan of Yubikeys, in fact most people would say I _am_ a fan of Yubikeys, I think I have like 10 of them (due to product evolution and always buying a few when I buy one). Unfortunately most of the sites I use do not have anything to do with them.
Have you tried using the Yubico Authenticator? It usually solves the problem for the sites that don't support U2F, such as PayPal, Coinbase, Gusto, and others.
Re: That's not how 2FA works
#245Earlier quoted context omitted.
I use Krypton [0] as a virtual YubiKey, I like it a lot but they got acquired by Akamai and the GitHub accounts have gone worryingly quiet. [0] https://krypt.co
> Krypton is built on top of an end-to-end verified and encrypted architecture. This means zero trust. We, Krypt.co, cannot access your keys or see where you're authenticating. The keys only live in the Krypton app on your phone. Sounds great, except one of the "ends" is likely the Secure Enclave (iOS) or Keystore (Android), over which the user has basically no control. So while the architecture might require "zero t…
Vanguard, for example, only trusts Yubico keys, and it's a pain in the ass.
That said, your complaint about Secure Enclave/Keystore trust doesn't make sense to me. Is there an architecture with on-device authenticators where you don't have to trust the device manufacturer? The use of SE/Keystore is a red herring here, no?
Re: That's not how 2FA works
#246It is tied to the site keys and not the address nor even the CAs.
It forces you to check and think before doing your thing.
And It is easier to use than 2FA, since it is one factor, open your key one time, the key auths you as long as you want.
Re: That's not how 2FA works
#247A password manager won't offer to auto-complete if the protocol/domain does not match with what you've saved. This is an immediate red-flag that something fishy is up.
Re: That's not how 2FA works
#248Earlier quoted context omitted.
> Not all 2nd Factor solutions allow stealing the 2nd factor. The second half of the article goes into detail about the shortcomings of U2F (using "Yubikeys" as it's terminology)
The article's first and most prominent criticism is that it costs at least $30-$60, which might be a barrier to mass adoption but for most HN readers is not a serious reason not to use it.
So that leaves ease of setup and support. Since setup only has to be done once per site, and I only bother with important sites, that’s not a major deal for me either.
Re: That's not how 2FA works
#249Earlier quoted context omitted.
2FA absolutely will protect you from a phishing site using the password it stole. Not if it also steals the 2nd factor. My response would be more like "2FA is good but not for this problem." This problem is about going to the wrong site. The solution is to go only to the right site.
Not all 2nd Factor solutions allow stealing the 2nd factor. Mainly U2F incorporates the domain and (should) only work if an TLS connection with a valid certificate for given domain is used. Furthermore it uses a key exchange. This means: - The attacker needs a valid certificate for the applications login domain, which wrt. web security is normally assumed to not be possible but tbh. might be possible in case of an st…
For either of those methods, stealing two SMS/TOTP codes isn't that much harder than stealing the first one - you just display a fake error saying that it failed, and try again.
For all but the most attentive folks - getting a "Whoops, try again" error when authenticating is probably going to be a semi-regular occurrence anyhow, so adding a fake one in there probably won't trigger any mental alarms.
Re: That's not how 2FA works
#250Earlier quoted context omitted.
I don't think the kickstarter is relevant now. You just buy them from solokeys.com. There's been Somu since that, and Solo2 is in the offing, with plenty of storage, apparently. I bought Somu partly for convenience, and partly for the promise of PGP support, which unfortunately hasn't been added yet (though there is a development version). In answer to the expense question, two Solo keys appear to set you back 38 qui…
I can confirm what you and _wldu are saying and yes, the latest project is https://solokeys.com/v2 and is launching end of this month. From an economic perspective, unfortunately, it's really hard to focus on reducing the cost, there's simply no incentive. First, consider that the biggest cost in the customer getting a security key is basically shipping + packaging. Imagine a key that costs Next, it's features. To st…
Integrated in to the laptop it would be great, like an Apple Watch allows https://support.apple.com/guide/imac/unlock-and-approve-with...
* https://solokeys.com/collections/all/products/somu-tiny-secu...