Live data from Hacker News

The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

blog.opencore.ch

51–60 of 64 posts

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#51
post #47

Passkeys seem overrated for three reasons: (1) Their use of public-key cryptography is not quantum safe (against quantum computing). In contrast, passwords are very much quantum safe. (2) They are tied to the provider. Why on Earth would I want to have the provider own my passkeys? Why would I want this vendor lock-in for my authentication? (3) What if I want multiple accounts for a site? Some passkey vendors may sup…

1. Neither are passwords… Unless you use a quantum safe hashing algorithm which I believe I’ve only seen Apple adopt, maybe others but most of the internet isn’t using it. 2. By definition this isn’t true 3. Again not true, don’t confound whatever terrible implementation you have used with what is allowed or capable

1. A regular hash algorithm is already very safe against quantum computing if the hash is sufficiently long, which it easily is or can be for passwords. A special hashing algorithm isn't needed for quantum safety. At worst the hash length has to be doubled for ultimate quantum safety. The assertion of needing a special hashing algorithm is bogus.

2. It is risked in practice.

3. It too is risked in practice.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#52
post #34
post #29

Earlier quoted context omitted.

The issue I'm having with this sort of "something you own and something you know/are" two-factor authentication is that it has some potential to cause violence - both can be beaten out of you: https://www.citizen.co.za/network-news/lnn/article/banking-a...

What can't though?

Staying anonymous. For every single multimillionaire or billionaire out there flaunting their wealth, there is another who's equally secretive about it. There are many folks with tens of billions in assets who don't make their wealth part of their brand.

Like that guy in Texas whose estate paid billions in tax when he passed away.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#53

The article starts with this description of 2FA: > an electronic authentication method in which a user is granted access to a website or application only after successfully presenting two or more distinct types of evidence (or factors) to an authentication mechanism. and concludes with (emphasis mine): > For the average user, the smartphone has become a single point of failure, where the theft of one device and one p…

Compromising the smartphone can let you get the password though, making it one factor. It would be more 2FA if you entered password on one device and used another (Yubikey, physical totp token) as a second factor.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#54
post #47

Earlier quoted context omitted.

1. Neither are passwords… Unless you use a quantum safe hashing algorithm which I believe I’ve only seen Apple adopt, maybe others but most of the internet isn’t using it. 2. By definition this isn’t true 3. Again not true, don’t confound whatever terrible implementation you have used with what is allowed or capable

1. A regular hash algorithm is already very safe against quantum computing if the hash is sufficiently long, which it easily is or can be for passwords. A special hashing algorithm isn't needed for quantum safety. At worst the hash length has to be doubled for ultimate quantum safety. The assertion of needing a special hashing algorithm is bogus. 2. It is risked in practice. 3. It too is risked in practice.

Seeing as we won’t agree on 2 and 3, let’s discuss 1.

Your argument hinges on us getting access to a quantum computer that is stable enough for Shor’s algorithm to run invalidating RSA and ECC, current password hashes being updated using algorithms that are secure, or long enough, and a quantum safe algorithm not existing for PKi.

Do you understand how this sequence of events is extremely unlikely, specifically since we already have quantum safe Public Key Algorithms and there is still ongoing research whereas it isn’t even known whether we will get a stable Quantum computer with enough qubits ever.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#55

Earlier quoted context omitted.

Buy an older iPhone for ~$150. Install financial apps on it and don't use it for anything else. Keep it in a safe place, only carry it around if you must. If you need to manage non-trivial amounts of money through your phone, having a specific device to do that is a no-brainer.

Is the risk that someone's going to steal my phone, forcibly hold it to my face, and wire my money somewhere? So far I've known two close friends who got mugged, the robber didn't think of this. Last time I tried intentionally wiring a large amount of money to someone, it took forever and involved tons of approval.

It's common in London, phones are being stolen for the access to financial accounts, not the value of the phone itself. They steal the phone out of your hands while it is unlocked. For example:

https://www.bbc.com/news/articles/cy8y70pvz92o.amp

I'm not sure exactly how they get around security features, perhaps by social engineering customer support, if they have enough PII.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#56
post #36
post #34

Earlier quoted context omitted.

What can't though?

A TAN generator or security key stored in a drawer at home. At least it reduces the opportunities for theft since people don't carry these devices with them all the time as opposed to their phones. Opportunity makes the thief.

if i have to use it every time i want to make a payment, then i have to carry it with me,

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#57

Earlier quoted context omitted.

Is the risk that someone's going to steal my phone, forcibly hold it to my face, and wire my money somewhere? So far I've known two close friends who got mugged, the robber didn't think of this. Last time I tried intentionally wiring a large amount of money to someone, it took forever and involved tons of approval.

It's common in London, phones are being stolen for the access to financial accounts, not the value of the phone itself. They steal the phone out of your hands while it is unlocked. For example: https://www.bbc.com/news/articles/cy8y70pvz92o.amp I'm not sure exactly how they get around security features, perhaps by social engineering customer support, if they have enough PII.

Uhm yeah in order to actually wire money in my banking app I need to input a fingerprint. Smart people developed these apps banks are not stupid.

Obviously people can still kidnap you and torture you but that's no different from before smartphones.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#58

So the threat model is someone physically stealing your phone and guessing/seeing your password. The #1 proposed solution is a Yubikey. Can't they steal that too?

YK's FIDO2 action can be passphrase protected. Mine has passphrases for FIDO2 and gpg. So stealing it won't help anyone.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#59
post #12

> Passkeys, particularly when bound to a physical security key And _only_ when bound to a physical security key. Unfortunately by tying into the marketing of passkeys, there is going to be a pervasive assumption that ecosystem/on-device passkeys are just as secure. Overall a good set of points, and I think it highlights the issues with a lot of the lauded 'convenience' factors in the Apple ecosystem.

> Unfortunately by tying into the marketing of passkeys, there is going to be a pervasive assumption that ecosystem/on-device passkeys are just as secure. Passkeys are an improvement over passwords. Security keys have a place for high security applications like enterprise deployments or the security paranoid. Passkeys stored on security keys can be trivially made worse by allowing users to set bad PINs (like 0000). I…

The problem is that passkeys are opaque, non-portable, inaccessible, magic boxes lacking a backup or a portability mechanism.

Passwords can be shared, stored, backed-up. Passkeys are locked away and hidden.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#60
post #54

Earlier quoted context omitted.

1. A regular hash algorithm is already very safe against quantum computing if the hash is sufficiently long, which it easily is or can be for passwords. A special hashing algorithm isn't needed for quantum safety. At worst the hash length has to be doubled for ultimate quantum safety. The assertion of needing a special hashing algorithm is bogus. 2. It is risked in practice. 3. It too is risked in practice.

Seeing as we won’t agree on 2 and 3, let’s discuss 1. Your argument hinges on us getting access to a quantum computer that is stable enough for Shor’s algorithm to run invalidating RSA and ECC, current password hashes being updated using algorithms that are secure, or long enough, and a quantum safe algorithm not existing for PKi. Do you understand how this sequence of events is extremely unlikely, specifically since…

You want people to bury their head in the sand, and unwillingly accept the unnecessary risk for little reward.
Post reply on HN