One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…
Two-factor authentication is a mess
11–20 of 112 posts
Re: Two-factor authentication is a mess
#12I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…
To quote the AWS ManPage[0]: > We recommend that when you configure a virtual MFA device to use with AWS that you save a copy of the QR code or the secret key in a secure place. That way, if you lose the phone or have to reinstall the MFA software application for any reason, you can reconfigure the app to use the same virtual MFA. This avoids the need to create a new virtual MFA in AWS for the user or root user. That…
That QR code paper can be secured the old fashioned way: I recommend a fireproof safe. The fact that you'd have to compromise your physical security (either the phone or your safe) and digital security (your password) at the same time provides reliable 2FA.
Re: Two-factor authentication is a mess
#13> Avoid: SMS has been at the center of a lot of two-factor hacks, most recently as a way to hijack Telegram accounts in Iran. High-security accounts are already moving away from it, but a frightening number of services still keep it as an option, giving anyone who compromises your carrier account an easy way in. I feel like this is badly phrased. SMS 2FA is far worse than other types, but still better than no 2FA.
>> SMS 2FA is far worse than other types, but still better than no 2FA. It seems like every time I read about how SMS2FA was hacked it was done by some state level power that would've gotten in through some other method. I don't know if that's confirmation bias or actually true, but I think you're right, SMS is better than no 2FA. Just because the NSA etc... can easily break it doesn't mean it's useless right now. (m…
Re: Two-factor authentication is a mess
#14One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…
>> I'm surprised the cut-throat world of registrars don't compete on this. How many people go looking for that though? For most people my guess is people go shopping for CHEAP first, EASY second, maybe LOOKS GOOD third, and some where down that list is "much more secure". I hate to say, I rarely go looking for the more secure option of anything.
Re: Two-factor authentication is a mess
#15> Avoid: SMS has been at the center of a lot of two-factor hacks, most recently as a way to hijack Telegram accounts in Iran. High-security accounts are already moving away from it, but a frightening number of services still keep it as an option, giving anyone who compromises your carrier account an easy way in. I feel like this is badly phrased. SMS 2FA is far worse than other types, but still better than no 2FA.
Re: Two-factor authentication is a mess
#16I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…
I only enable 2FA if it's TOTP or HOTP. In the case of TOTP I save the key (the data in the QR code) in my password manager (KeePass), in the case of HOTP my backup key is in my fireproof safe at home along with other important documents. That's admittedly a small portable box with a carry handle, so easy for a burglar to steal, but it's also easy to get to and I can take it with me if I ever have to evacuate or move…
Re: Two-factor authentication is a mess
#17I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…
Re: Two-factor authentication is a mess
#18> Avoid: SMS has been at the center of a lot of two-factor hacks, most recently as a way to hijack Telegram accounts in Iran. High-security accounts are already moving away from it, but a frightening number of services still keep it as an option, giving anyone who compromises your carrier account an easy way in. I feel like this is badly phrased. SMS 2FA is far worse than other types, but still better than no 2FA.
>> SMS 2FA is far worse than other types, but still better than no 2FA. It seems like every time I read about how SMS2FA was hacked it was done by some state level power that would've gotten in through some other method. I don't know if that's confirmation bias or actually true, but I think you're right, SMS is better than no 2FA. Just because the NSA etc... can easily break it doesn't mean it's useless right now. (m…
It seems to be a lot more vulnerable than that. Perhaps the biggest problem is that the phone companies do not treat your phone number as being a component of a 2FA system (and, to be fair, that was never the intent). This is from the linked article by Cody Brown, "How to lose $8k worth of bitcoin in 15 minutes with Verizon and Coinbase.com":
"Of all the things that went down in the factors that lead to this hack, Verizon Wireless is what I was massively unprepared for. After talking at length with customer service reps, I learned that the hacker did not need to give them my pin number or my social security number and was able to get approval to takeover my cell phone number with simple billing information."
See also: https://krebsonsecurity.com/2016/09/the-limits-of-sms-for-2-...
Re: Two-factor authentication is a mess
#19One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…
Re: Two-factor authentication is a mess
#20I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…