Live data from Hacker News

Thoughts on Twitter's new Two-Factor Authentication

blog.authy.com

31–35 of 35 posts

Re: Thoughts on Twitter's new Two-Factor Authentication

#31
post #24

I know Twitter did this (primarily) in response to the AP hacking, but I fail to see how this change is going to help organizations (say...news) with multiple people sharing an account for business purposes. We want to secure with 2 factor here in our offices, but it involves giving 10 people the app and possibly getting spammed every time someone logs in. I realize they went for this approach rather than have your a…

It is astounding to me how many companies who clearly want, welcome, and benefit from organizational users, fail to provide admin experience that works for organizations.

Why doesn't Twitter (and YouTube, also a terrible offender), simply allow multiple accounts to manage a corporate channel? Like Facebook does with Pages, or Google Analytics with profiles?

Instead we have to either share a single password among multiple people (not secure) or use third party apps like HootSuite (and now your security totally depends on that app, not Twitter).

Re: Thoughts on Twitter's new Two-Factor Authentication

#32
post #23

Not a tremendously compelling argument, and I think the company may come to regret the know-it-all tone of the post. Hubris is not what you want in a security platform company. The author cites two "flaws": 1. Your phone is offline sometimes. Twitter has a backup code mechanism that covers this case. They talk about it, right in the post. 2. An attacker can send verification requests that look exactly like yours. The…

While I agree that Twitter's mechanism addresses the vast majority of potential attacks against a person's Twitter account (which would almost always be remote), it's not hard to imagine a scenario like Authy describes.

Imagine you're at work, logging in to a two-factor system. Now imagine your attacker is sitting 15 feet away from you. All the attacker needs to do is wait for you to attempt to login to the system before attempting to login himself.

When we have penetration tests run against us, this is exactly what is happening. We give the penetration tester a desk, a connection to the internal corporate network, and the same bare level of access we would give to a temporary contract employee.

Re: Thoughts on Twitter's new Two-Factor Authentication

#33
post #10

Earlier quoted context omitted.

I don't think they can be, as I don't have a Twitter account. Certainly I would be pissed beyond belief if I tried to login to my bank (assuming they ever pull their heads out of their asses to support 2FA) and couldn't because I don't have cellular service in addition to Internet.

I already have this problem; both my bank and my credit union introduced 2FA but only with SMS. Once enabled, any attempt to log in using a not-yet-authorized browser or app is stalled until I get that text message. Presumably a call to customer service would sort it out eventually, but that prospect isn't terribly pleasant.

Every time I have to call customer support to reset a bank password it makes me realize how bad of a security hole most phone support is. Security through two-factor authentication is only as strong as the process for bypassing it.

Re: Thoughts on Twitter's new Two-Factor Authentication

#34
post #23

Not a tremendously compelling argument, and I think the company may come to regret the know-it-all tone of the post. Hubris is not what you want in a security platform company. The author cites two "flaws": 1. Your phone is offline sometimes. Twitter has a backup code mechanism that covers this case. They talk about it, right in the post. 2. An attacker can send verification requests that look exactly like yours. The…

While I agree that Twitter's mechanism addresses the vast majority of potential attacks against a person's Twitter account (which would almost always be remote), it's not hard to imagine a scenario like Authy describes. Imagine you're at work, logging in to a two-factor system. Now imagine your attacker is sitting 15 feet away from you. All the attacker needs to do is wait for you to attempt to login to the system be…

And if you see multiple requests on your phone, you know it's an attack and you should reject both. The criticism is basically "someone might see a bunch of requests and, not knowing which is theirs, approve them all." If someone is that foolish, you're already in trouble.

Re: Thoughts on Twitter's new Two-Factor Authentication

#35

Earlier quoted context omitted.

While I agree that Twitter's mechanism addresses the vast majority of potential attacks against a person's Twitter account (which would almost always be remote), it's not hard to imagine a scenario like Authy describes. Imagine you're at work, logging in to a two-factor system. Now imagine your attacker is sitting 15 feet away from you. All the attacker needs to do is wait for you to attempt to login to the system be…

And if you see multiple requests on your phone, you know it's an attack and you should reject both. The criticism is basically "someone might see a bunch of requests and, not knowing which is theirs, approve them all." If someone is that foolish, you're already in trouble.

I agree except for the part about not caring about foolish users.

For me, it is more about asking yourself what approach will increase the overall security of a system. User adoption is a critical consideration. That is where Twitter's approach shines. It's something that is super easy to adopt, no numbers to type in, which means literally millions more users may adopt it. Authy is undervaluing that consideration.

Yes, this is vulnerable to a) foolish users who approve duplicate requests and b) have an attacker looking over their shoulder.

Pretty good tradeoff IMHO.

Post reply on HN