Live data from Hacker News

Authy: Faster Two-Factor Authentication

authy.com

61–70 of 99 posts

Re: Authy: Faster Two-Factor Authentication

#61
post #35

Has anyone here used both Authy and Duo Mobile and would like to recommend one over the other?

We use Duo for various things around here. Love it. It's much more feature complete than Authy (which, unfortunately will not work for any of our use cases).

More importantly, the company is run by well know and respected security researchers (Dug Song and Jon Oberheide).

Re: Authy: Faster Two-Factor Authentication

#63

Hi, I'm Daniel, Authy Founder. We've worked almost 18 months on this product, it's surreal to finally see it out. Anyway, you can read more about why we did this here: http://blog.authy.com/thefuture

I'm having a tough time understanding all the moving parts involved. Could you post some drawings of what happens in different scenarios? 'cause I'm more of a visual learner.

From what I can tell, the user navigates to a site previously provisioned with Authy, they choose to authenticate via Authy, and then ??? happens resulting in their cell phone giving them a time-limited one-time passphrase.

Re: Authy: Faster Two-Factor Authentication

#64
post #48

Earlier quoted context omitted.

Cellphone numbers can very easily be abused to steal money (premium SMS), to steal my identity, to spam me in the middle of the night, to pull me out of the "zone" by calling me/messaging me during work hours, to track my location while roaming and probably a lot more stuff that's not currently apparent to me. Also, my phone number is known to some identity providers I trust. If they sent me an SMS asking me to click…

It is ridiculous to think that your number is private and even moreso to think that someone can steal money with just your cellphone number. Of course you could be phished or tricked by SMS but to expect your number to be private is to expect everyone ever who you give the number to go to extreme to keep it private as well. If you ever gave your number to someone who downloaded an app which has permission to contacts…

I think it's not so much "stealing money" as it is "I get charged per SMS and those bastards just texted me a dozen times and cost me three bucks."

Re: Authy: Faster Two-Factor Authentication

#65
I'm sorry. Authy is trying to push something that NEVER should have been a "startup". How the fuck is this a service ANYONE is going to pay for when it's trivial to set up an OTOP server and use the Google Auth app that everyone who uses TFA is already going to have installed.

This monkey patched TFA solution is not "the future" of logins, by a long shot. Not even in the short term. Things like Persona are going to beat Authy before Authy ever sees a non-negligible amount of revenue.

At least Coinbase doesn't FORCE me to use them anymore.

--

Also, since I forgot.

IF YOU SYNC MFA KEYS, YOU'RE ONLY COMPLETELY DEFEATING THE POINT.

Re: Authy: Faster Two-Factor Authentication

#67

Assuming an attacker has complete control over your computer, and your phone is within bluetooth range, can he make the phone generate a token without user interaction? I was assuming the user would have to click a button on the phone or something, but I couldn't see it in the video.

Assuming the attacker has complete control over your computer...

... the end user just lost, absent substantially more defense-in-depth on the provider side than just using TFA. TFA mostly helps you against "We lost credentials or a low-privilege session, let's prevent that from escalating to a high-privilege session." If your device is rooted, you'll eventually cough up a high-privilege session, either by passive monitoring or by something more clever like e.g. using your own computer as the MITM to ask you to provide a valid TFA to do something which really only requires a low-privilege session. Now the attacker has both factors. Game set match.

Re: Authy: Faster Two-Factor Authentication

#68
post #35

Has anyone here used both Authy and Duo Mobile and would like to recommend one over the other?

I highly recommend Duo Security, the guys behind have a solid track record in the industry. They started it first with phones. Prior to that everyone else was using expensive RSA like secureid tokens that take more to deploy. Read the man page for ssh and you see Dug's name in there. Jon has a solid track record on the mobile side. They just developed Rekey to fix the Android master key vulnerability issue about 2 weeks ago.
Post reply on HN