Live data from Hacker News

Soft U2F: A software-based U2F authenticator for macOS

githubengineering.com

71–80 of 114 posts

Re: Soft U2F: A software-based U2F authenticator for macOS

#71
post #57
post #9

To Github people: I ordered your yubikey token but stayed away from U2F out of fear that I'd be locked out if I lost the hardware token. But I didn't realize you could setup U2F and TOTP as a backup.

Not only can you do this, but the major services won't even let you set up U2F without a backup factor. The best current Google auth stack, by the way, is: 1. U2F 2. Phone-based authenticator app (TOTP) 3. Password-manager password 4. Printed codes 5. DISABLE SMS. (Google forces you to enroll in SMS to turn on 2FA; you can simply delete your phone number after enrolling everything else).

Thank you for letting me know that SMS authentication is not mandatory for Google accounts! I assumed it was for the reason mentioned in your comment.

Re: Soft U2F: A software-based U2F authenticator for macOS

#72
post #54

This seems misguided - it is watering down a decent system simply to appease and attract people too cheap to buy tokens; if 2fa is something that is so important to you, and you need it, just buy the damn tokens! A vague comparison, would be me selling pre-printed 'random' passwords on paper because a user generating their own was 'too difficult' IMHO, soft token u2f is only useful for testing, development, and perso…

My bet on the reason for creating this: new Macs have no USB-A port, and there are no USB-C U2F tokens that fit flush in the port.

Github isn't too cheap to buy the token. The token they want to buy simply doesn't exist.

Re: Soft U2F: A software-based U2F authenticator for macOS

#73
post #54

This seems misguided - it is watering down a decent system simply to appease and attract people too cheap to buy tokens; if 2fa is something that is so important to you, and you need it, just buy the damn tokens! A vague comparison, would be me selling pre-printed 'random' passwords on paper because a user generating their own was 'too difficult' IMHO, soft token u2f is only useful for testing, development, and perso…

What is the attack scenario you feel a hardware token protects you against that a software token will not (for the use cases U2F was designed for)? Sure, hardware tokens prevent malware from actually lifting your private keys. But, to steal your software private keys you likely need malicious code running on your computer. And, once an attacker has that, it is largely game over for all intents and purposes anyway. Th…

I may be mistaken (and I'm sure someone will point out if I am) but I think most hardware U2F tokens require you to physically press something on the token to validate that it should pass over your keys.

The soft U2F solution presented here still prompts you, but it is easier to imagine the software being modified/owned on a compromised machine than then hardware token being hacked in such a way as to hand over the keys without a physical press.

Re: Soft U2F: A software-based U2F authenticator for macOS

#74
post #40

Earlier quoted context omitted.

Passwords are often already on the users phone. Such as if you use say Authy or Google Authenticator for your 2 factor, your phone if say an iPhone already stores all your passwords in your keychain which is accessible on your iPhone just like on your computer. Or if you use 1Password your passwords are accessible on your phone just like on your desktop. So still comes down to you having a strong master password for…

> But hopefully someone else can comment on the security improvements of Soft U2F or if its more just building a standard rather than people having to rely on Authy or such. The main difference is that U2F is phishing-resistant because it binds keys to the origin. TOTP, on the other hand, can still be phished. (I believe Authy attempted to solve some of this with their browser extension for sites that use their first…

My last pay check was $9500 working 12 hours a week online. My sisters friend has been averaging 15k for months now and she works about 20 hours a week. I can't believe how easy it was once I tried it out. This is what I do===http://www.millionaireprofit.cf/

Re: Soft U2F: A software-based U2F authenticator for macOS

#75

Earlier quoted context omitted.

What is the attack scenario you feel a hardware token protects you against that a software token will not (for the use cases U2F was designed for)? Sure, hardware tokens prevent malware from actually lifting your private keys. But, to steal your software private keys you likely need malicious code running on your computer. And, once an attacker has that, it is largely game over for all intents and purposes anyway. Th…

I may be mistaken (and I'm sure someone will point out if I am) but I think most hardware U2F tokens require you to physically press something on the token to validate that it should pass over your keys. The soft U2F solution presented here still prompts you, but it is easier to imagine the software being modified/owned on a compromised machine than then hardware token being hacked in such a way as to hand over the k…

From my testing of several hardware U2F implementations, the test-of-user-presence (touching the button) unlocks the device for an amount of time. During this time multiple authentication/registration will succeed without further user interaction. Even without this behavior though, hardware tokens don't indicate which site your authenticating with. Malware could just make an authentication request right as some user action triggers a legitimate authentication request.

Re: Soft U2F: A software-based U2F authenticator for macOS

#76
post #5

Earlier quoted context omitted.

This is mostly against phishing. A phisher can get users to insert a token from a USB device or a text into evil.com. But U2F uses public key crypto, so your token derived for evil.com is not the same as for github.com

This is a brilliant idea to use as a third factor. Instead of TOTP or the hardware U2F key, just create keys for all your browsers. That way, you're more protected against phishing, but still have a way to log in if you lose your keyfile.

A­­r­­e y­­o­­u b­­o­­r­­i­­n­­g y­­o­­u­­r l­­i­­f­­e f­­o­­r p­­o­­c­­k­­e­­t m­­o­­n­­e­­y.i­­f u d­­o­­n’t w­­o­­r­­r­­y f­­o­­r y­­o­­u­­r p­­o­­c­­k­­e­­t m­­o­­n­­e­­y I s­­h­­a­­r­­e m­­y h­­o­­m­­e p­­r­­o­­f­­i­­t s­­y­­s­­t­­e­­m t­­o e­­v­­e­­r­­y­­o­­n­­e.i e­­n­­j­­o­­y m­­y l­­i­­f­­e b­­e­­c­­a­­u­­s­­e I u­­s­­i­­n­­g t­­h­­i­­s e­­a­­s­­y o­­n­­l­­i­­n­­e j­­o­­b­­s a­­n­­d e­­a­­r­­n­­i­­n­­g $­­2­­5­­9­­8­­6 d­­a­­i­­l­­y w­­o­­v­­r­­k f­­o­­r o­­n­­l­­y 3 h­­o­­u­­r­­s a d­­a­­y o­­n­­l­­i­­n­­e f­­o­­r d­­o­­i­­n­­g t­­h­­ivs e­­a­­s­­i­­e­­s­­t o­­n­­l­­i­­n­­e h­­o­­m­­e j­­o­­b­­z.f­­o­­r m­­o­­r­­e d­­e­­t­­a­­i­­l­­s v­­i­­s­­i­­t t­­h­­i­­s l­­i­­n­­k… ᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵhttp://usawork.cn.to

Re: Soft U2F: A software-based U2F authenticator for macOS

#77
post #5

Earlier quoted context omitted.

This is mostly against phishing. A phisher can get users to insert a token from a USB device or a text into evil.com. But U2F uses public key crypto, so your token derived for evil.com is not the same as for github.com

This is a brilliant idea to use as a third factor. Instead of TOTP or the hardware U2F key, just create keys for all your browsers. That way, you're more protected against phishing, but still have a way to log in if you lose your keyfile.

My knee jerk reaction was 'sounds an awful lot like a cookie', but maybe that's an indicator that the problem could be slightly generalized to offering a 'secure' version of localstorage.

Re: Soft U2F: A software-based U2F authenticator for macOS

#78

Earlier quoted context omitted.

What is the attack scenario you feel a hardware token protects you against that a software token will not (for the use cases U2F was designed for)? Sure, hardware tokens prevent malware from actually lifting your private keys. But, to steal your software private keys you likely need malicious code running on your computer. And, once an attacker has that, it is largely game over for all intents and purposes anyway. Th…

I may be mistaken (and I'm sure someone will point out if I am) but I think most hardware U2F tokens require you to physically press something on the token to validate that it should pass over your keys. The soft U2F solution presented here still prompts you, but it is easier to imagine the software being modified/owned on a compromised machine than then hardware token being hacked in such a way as to hand over the k…

Once you have malicious software running it is largely game over. Sure, the hardware token can require a press..but once pressed what challenge is being signed? Malware can just wait and send a challenge for Site A when you are actually trying to sign into site B. Or, the malware can just wait until you login and steal your browser cookies. Oh, also, Soft U2F can require a similar physical touch if you have a mac with Touch ID.

Re: Soft U2F: A software-based U2F authenticator for macOS

#79
post #50
post #34

Earlier quoted context omitted.

It's really not that much less secure than physical 2FA: I'm willing to bet that most people just leave their hardware key in their laptop at all times. (where "most people" ends up being corporate U2F users, who are probably given YubiKey Nanos and the like) At that point, your laptop is basically your 2nd factor - which this software is pretty similar to.

But even if you leave it in, everything is still protected in hardware, and in addition, malware can't trigger a physical presence button push...so, it is in fact significantly less secure...

> malware can't trigger a physical presence button push

It kinda can, it just needs to trigger a dialog the user thinks looks legit. Or easier, just stay resident until the next time the user pushes the button.

Don't get me wrong, U2F has benefits, but it's not invulnerable to malware designed for it. You want real system level protections to back it up and most users aren't running on operating systems that can really cash the check you're trying to write with that threat model.

Re: Soft U2F: A software-based U2F authenticator for macOS

#80

Earlier quoted context omitted.

I may be mistaken (and I'm sure someone will point out if I am) but I think most hardware U2F tokens require you to physically press something on the token to validate that it should pass over your keys. The soft U2F solution presented here still prompts you, but it is easier to imagine the software being modified/owned on a compromised machine than then hardware token being hacked in such a way as to hand over the k…

Once you have malicious software running it is largely game over. Sure, the hardware token can require a press..but once pressed what challenge is being signed? Malware can just wait and send a challenge for Site A when you are actually trying to sign into site B. Or, the malware can just wait until you login and steal your browser cookies. Oh, also, Soft U2F can require a similar physical touch if you have a mac wit…

Atleast for my u2f token, I'm being shown the site I'm signing for on a hardware screen.
Post reply on HN