Live data from Hacker News

TOTP tokens on my wrist with the smartest dumb watch

blog.singleton.io

11–20 of 131 posts

Re: TOTP tokens on my wrist with the smartest dumb watch

#11
post #9
post #5

Earlier quoted context omitted.

Can you recommend any cheap USB security keys? I've looked in the past and cost has been prohibitive.

Have you looked into these? https://solokeys.com

I was a backer of the V2 and I think my order is now a year overdue. I don't really back things on kickstarter because I don't like to gamble, but this seemed like a sure bet. Turns out it wasn't.

Re: TOTP tokens on my wrist with the smartest dumb watch

#12
post #8
post #2

Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…

> TOTP is not much better than SMS-based 2FA. It's still vulnerable to phishing, local device malware (that attacks your TOTP in your password manager), etc. It's best to use hardware tokens everywhere that support them, and both Google and GitHub do. (And Google supports a special hardware token only mode which I wish more sites would adopt.) Since this device doesn't actually have network connectivity he might have…

TOTP is really vulnerable to phishing. Hardware keys are the solution.

Re: TOTP tokens on my wrist with the smartest dumb watch

#15

How accurate does the time have to be for TOTP to work? If the watch drifts a bit, will it no longer work? Compared to your phone which is synced with an NTP server.

The key lifetime may be other than the default 30 seconds, and IIRC the validator side may be configured to accept keys from N previous generations.

Re: TOTP tokens on my wrist with the smartest dumb watch

#16
post #8

Earlier quoted context omitted.

> TOTP is not much better than SMS-based 2FA. It's still vulnerable to phishing, local device malware (that attacks your TOTP in your password manager), etc. It's best to use hardware tokens everywhere that support them, and both Google and GitHub do. (And Google supports a special hardware token only mode which I wish more sites would adopt.) Since this device doesn't actually have network connectivity he might have…

TOTP is really vulnerable to phishing. Hardware keys are the solution.

Yeah, sure, but then again a watch on your wrist is harder to take away than a hardware key on your physical keychain that you don't pay attention to.

EDIT: yes, lol, thank you for explaining what phishing is jgrahamc. We didn't know. I get that a lot of Americans and some Germans guard their car keys like an internal organ, but for a lot of people in the world a keychain is something you toss in an insecure place most of the time of the day.

Re: TOTP tokens on my wrist with the smartest dumb watch

#17

Earlier quoted context omitted.

TOTP is really vulnerable to phishing. Hardware keys are the solution.

Yeah, sure, but then again a watch on your wrist is harder to take away than a hardware key on your physical keychain that you don't pay attention to. EDIT: yes, lol, thank you for explaining what phishing is jgrahamc. We didn't know. I get that a lot of Americans and some Germans guard their car keys like an internal organ, but for a lot of people in the world a keychain is something you toss in an insecure place mo…

It may be easier to steal, but it should have some kind of minimal protection. It should lock out after a low number of failed pins, for example. The YubiKeys do this.

Re: TOTP tokens on my wrist with the smartest dumb watch

#18
post #9

Earlier quoted context omitted.

Have you looked into these? https://solokeys.com

I was a backer of the V2 and I think my order is now a year overdue. I don't really back things on kickstarter because I don't like to gamble, but this seemed like a sure bet. Turns out it wasn't.

I got my solokeys v2. A bummer that they did not ship to some folks.

Re: TOTP tokens on my wrist with the smartest dumb watch

#19
post #5
post #2

Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…

Can you recommend any cheap USB security keys? I've looked in the past and cost has been prohibitive.

I have a $50 yubikey nano plugged into each of my multiple-thousand-dollar computers, protecting my accounts containing/accessing client data worth millions.

If anything under $100 is too much to secure your account, just use SMS 2FA, or disable 2FA entirely.

Re: TOTP tokens on my wrist with the smartest dumb watch

#20
post #5
post #2

Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…

Can you recommend any cheap USB security keys? I've looked in the past and cost has been prohibitive.

Fwiw big players regularly give free keys to e.g. OSS maintainers. Dunno if it’s still active but Pypy has a program for maintainers of crates flagged as sensitive (or something like that), you can get two Titan keys courtesy of google.

I also have a pair of github-branded yubikeys from a long time ago but I don’t remember what that program was.

> cost has been prohibitive.

A titan is 35 or so, hardly prohibitive. And if you have access to anything important your company ought be glad to get you one or two, or yubis.

Post reply on HN