Live data from Hacker News

TOTP tokens on my wrist with the smartest dumb watch

blog.singleton.io

21–30 of 131 posts

Re: TOTP tokens on my wrist with the smartest dumb watch

#21
post #5
post #2

Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…

Can you recommend any cheap USB security keys? I've looked in the past and cost has been prohibitive.

Cloudflare and Yubico are in partnership to provide YubiKeys at a discount:

https://www.cloudflare.com/products/zero-trust/phishing-resi...

Related thread: https://news.ycombinator.com/item?id=33020078

Re: TOTP tokens on my wrist with the smartest dumb watch

#22
If you are not that a hacker but already own a Smartwatch such as the Apple Watch, Authy[1] is a pretty rock solid option. I use Authy for a few key credentials, and I have used my watch for the keys.

FYI, Authy was bought and is now owned by Twilio

1. https://authy.com

Re: TOTP tokens on my wrist with the smartest dumb watch

#23
post #2

Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…

While I agree with your points regarding the security of TOTP / SMS, and I do push for hardware keys at work, I think a case could be made for a mixed use for "regular people".

Maintaining two hardware keys is an absolute PITA, especially if you go down the route of storing one off-site, hence not having it with you to enroll when you get a new account.

What I do, is use the hardware token as the "main" factor and use the TOTP if for some reason I don't have the token (I may sometimes forget it at home when I'm at my parents' house).

The point is that, since I usually have my key, if I'm presented with a Google or whatever prompt for a TOTP, I know something's fishy. I don't normally use that, so I'll investigate why that happens and won't just go ahead and type my code in there.

Re: TOTP tokens on my wrist with the smartest dumb watch

#24

Earlier quoted context omitted.

TOTP is really vulnerable to phishing. Hardware keys are the solution.

Yeah, sure, but then again a watch on your wrist is harder to take away than a hardware key on your physical keychain that you don't pay attention to. EDIT: yes, lol, thank you for explaining what phishing is jgrahamc. We didn't know. I get that a lot of Americans and some Germans guard their car keys like an internal organ, but for a lot of people in the world a keychain is something you toss in an insecure place mo…

Phishing doesn't require stealing the watch. It just requires me to type in a TOTP token on a phishing website. Very different threat model than physical access.

Re: TOTP tokens on my wrist with the smartest dumb watch

#25
post #9

Earlier quoted context omitted.

Have you looked into these? https://solokeys.com

I was a backer of the V2 and I think my order is now a year overdue. I don't really back things on kickstarter because I don't like to gamble, but this seemed like a sure bet. Turns out it wasn't.

Not them but I have stopped backing projects on Kickstarter, because I have been burned to the tune of $2,000+ (2016-17-ish currency conversion).

Re: TOTP tokens on my wrist with the smartest dumb watch

#26

If you are not that a hacker but already own a Smartwatch such as the Apple Watch, Authy[1] is a pretty rock solid option. I use Authy for a few key credentials, and I have used my watch for the keys. FYI, Authy was bought and is now owned by Twilio 1. https://authy.com

I use Duo Mobile [1] with my Apple Watch.

Authy gets recommended often here but got turned off of them because they require a phone number to set up the app on iOS. There's no phone number requirement for TOTP implementations so I eventually found Duo Mobile. This was before they got bought by Cisco.

1: https://apps.apple.com/us/app/duo-mobile/id422663827

Re: TOTP tokens on my wrist with the smartest dumb watch

#27
post #8
post #2

Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…

> TOTP is not much better than SMS-based 2FA. It's still vulnerable to phishing, local device malware (that attacks your TOTP in your password manager), etc. It's best to use hardware tokens everywhere that support them, and both Google and GitHub do. (And Google supports a special hardware token only mode which I wish more sites would adopt.) Since this device doesn't actually have network connectivity he might have…

Well if you want to look at specific attack vectors this one may have remote access issues based on what and where you store the source code. I'd guess OP knows what he's doing, but someone trying this with an accidentally open repo or comprised machine are possibly bigger risks here then with most other TOTP solutions.

Equally it has the hardware key flaw of being able to be physically stolen, but with no option of an additional lock, and more likely then most systems that you might leave the totp running so a camera exploit is a little easier then with an app maybe.

Not to say I think any of this is likely, and with the exception of a public repo mistake, it's probably a lot harder then an SMS exploit.

Re: TOTP tokens on my wrist with the smartest dumb watch

#28
post #2

Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…

[deleted]

Re: TOTP tokens on my wrist with the smartest dumb watch

#29
post #2

Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…

I like the yubico key that even has a pin code so if lost or stolen protects your TOTP codes

Re: TOTP tokens on my wrist with the smartest dumb watch

#30
post #21
post #5

Earlier quoted context omitted.

Can you recommend any cheap USB security keys? I've looked in the past and cost has been prohibitive.

Cloudflare and Yubico are in partnership to provide YubiKeys at a discount: https://www.cloudflare.com/products/zero-trust/phishing-resi... Related thread: https://news.ycombinator.com/item?id=33020078

US Google One users on a >=2TB plan should currently also have an offer for a free Titan key at https://one.google.com/benefits
Post reply on HN