Live data from Hacker News

When two-factor authentication is not enough

blog.fastmail.fm

11–20 of 57 posts

Re: When two-factor authentication is not enough

#11

It's interesting how there are people who think spending $100/year/domain is a lot of money - but when your entire company's business/value is on the line, I would think that spending $1,000/year/domain, to make absolutely sure nothing goes wrong, would be a bargain. It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything…

What I wonder is where I can get a domain with less human reviews. This wouldn't have happened if the humans at Gandi ignored the email with the fake documents and had just relied on the automated authentication systems.

The problem with their system is that it has the right amount of human intervention to be fallible to social engineering.

Re: When two-factor authentication is not enough

#12

It's interesting how there are people who think spending $100/year/domain is a lot of money - but when your entire company's business/value is on the line, I would think that spending $1,000/year/domain, to make absolutely sure nothing goes wrong, would be a bargain. It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything…

What I wonder is where I can get a domain with less human reviews. This wouldn't have happened if the humans at Gandi ignored the email with the fake documents and had just relied on the automated authentication systems. The problem with their system is that it has the right amount of human intervention to be fallible to social engineering.

You actually want both - you want all of the automatic safety checks to be first completed, and then, after all of them have been passed, you want an account manager to personally pick up the phone, and call their contact at the company making the change, and have a discussion as to what is trying to be done, and whether everything is kosher.

Re: When two-factor authentication is not enough

#13

Earlier quoted context omitted.

What I wonder is where I can get a domain with less human reviews. This wouldn't have happened if the humans at Gandi ignored the email with the fake documents and had just relied on the automated authentication systems. The problem with their system is that it has the right amount of human intervention to be fallible to social engineering.

You actually want both - you want all of the automatic safety checks to be first completed, and then, after all of them have been passed, you want an account manager to personally pick up the phone, and call their contact at the company making the change, and have a discussion as to what is trying to be done, and whether everything is kosher.

Sure, for a company, yeah. For my personal domains, I'd rather have cheap and human-free ;)

Re: When two-factor authentication is not enough

#14
post #3

This article really should have been called "Security hole in Gandi's processes". Why would they change the account email address if you didn't reply to a single email within 24 hours? Who thought that was a good solution?

A possible reason was called out in the article: "Gandi’s paper 'email reset' form makes a lot of sense in the world where most of their customers are individuals or small businesses with one or two domains, and using addresses that they may lose access to. With no other factors, if they lose access to the email address and forget their password, there needs to be a process to regain access." If a customer loses acce…

A better compromise is a 30 day lock down by default, with weekly, for three weeks, and then daily messages notifying of the change.

The alternative would be to go to a fastmail selected notary, and present appropriate identification material to them, and then pay a small fee to have an expedited (3 day) recovery process.

Re: When two-factor authentication is not enough

#16
I've been a fan of easyDNS for their security features and how they go to bat for their customers when it comes to things like transfers / takedown notices.

http://blog.easydns.org/2014/01/29/welcome-to-easydns-press-...

http://blog.easydns.org/2012/02/21/the-official-easydns-doma...

And has Gandi changed their terms recently to remove the bullshit? https://news.ycombinator.com/item?id=4970947

Re: When two-factor authentication is not enough

#17
post #3

This article really should have been called "Security hole in Gandi's processes". Why would they change the account email address if you didn't reply to a single email within 24 hours? Who thought that was a good solution?

A possible reason was called out in the article: "Gandi’s paper 'email reset' form makes a lot of sense in the world where most of their customers are individuals or small businesses with one or two domains, and using addresses that they may lose access to. With no other factors, if they lose access to the email address and forget their password, there needs to be a process to regain access." If a customer loses acce…

Shouldn't they send out a paper letter to the owner of the domain then? That might be a better way to verify identity. Or use an actual "real world" identity check?

In Germany you can do that with the German mail system - the postman will then check your id and confirm you are who you claim to be. Certainly not foolproof, but just accepting incoming letters at face value seems crazy.

Re: When two-factor authentication is not enough

#18
Although Gandi.net is a fantastic company, their security practices are nothing to write home about.

A few years ago, one of my clients lost access to her Gandi.net account. Unfortunately, she had the "disable password resets via email" option set in her account. That should have given her quite a headache, right?

Nope. I, an independent contractor who didn't even own the account, was able to convince Gandi support to disable that option so that she could reset her password via email. They didn't even ask for any documents to prove either my identity or my client's. It took several days, but the only reason it took so long was because their English support was very slow back then.

So I'm not surprised that Gandi let the attacker change the email on FastMail's account when presented with genuine-looking documents.

And this is not a problem that is specific to Gandi. Even with other online services, it's often quite easy to bypass automated security measures if you go through a human being, whether through the support system or through good ol' snail mail. In fact, I'm sure that snail mail is by far the most reliable way to take over someone else's account nowadays. So many of us in the tech industry have no idea how to verify the authenticity of a piece of paper, especially if it's from a different country.

Meanwhile, another favorite web host and registrar of mine, NearlyFreeSpeech.net, recently enabled two-factor authentication. But they did it differently. In addition to OATH TOTP, NearlyFreeSpeech allows you to select several other tests that you need to pass in order to recover your account. If you tell them to give you six different tests, which will probably take several weeks because some of the tests involve snail mail, they'll honor your preferences. Or you can choose to take four tests. Or three. Or two. It's your choice. That's multi-factor auth done right.

Re: When two-factor authentication is not enough

#19

It's interesting how there are people who think spending $100/year/domain is a lot of money - but when your entire company's business/value is on the line, I would think that spending $1,000/year/domain, to make absolutely sure nothing goes wrong, would be a bargain. It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything…

I've heard this claim made repeatedly on this site, but I've not heard any details as to what specifically MarkMonitor does to protect domains above and beyond other registrars. Anyone care to chime in?

FWIW I think Apple previously used MarkMonitor. In fact that's currently mentioned on Wiki. However, now Apple.com is controlled by something named "Corporation Service Company".

I think the idea behind these services is, they're not just a registrar. Broadly speaking, their business is "know your customer". They're boutiques. They protect large companies against the vagaries of DNS hacks, expired domain registrations, typosquatting, etc.

E.g. a (long) while ago Microsoft failed to renew hotmail.co.uk, just like they previously forgot to renew passport.com. But today, Microsoft can't forget to renew microsoft.com, because that's now MarkMonitor's job. Similarly, renewing passport.com is now the job of (according to whois '=passport.com'):

   Corporation Service Company(c) (CSC) 
   The Trusted Partner
   of More than 50% of the 100 Best Global Brands.
The bad part is if CSC screws up, quite a few companies could be in a world of hurt.

Re: When two-factor authentication is not enough

#20
post #3

This article really should have been called "Security hole in Gandi's processes". Why would they change the account email address if you didn't reply to a single email within 24 hours? Who thought that was a good solution?

Yeah, that's not something that should count as two-factor authentication. It's just single factor authentication with a warning.
Post reply on HN