Live data from Hacker News

The bleak picture of two-factor authentication adoption in the wild

elie.net

81–90 of 96 posts

Re: The bleak picture of two-factor authentication adoption in the wild

#81
post #56

Earlier quoted context omitted.

There are others which aren't listed there, like OVH (the largest European hosting company). The dearth of banks is real though. And sad. I have only seen client-side certificates used twice. Once at now infamous StartSSL and second at a bank but for vendor access, not regular customers. Its huge downside is that it's a second factor which doesn't protect against a compromised device.

Client-side certificates are widely used among the Estonian population btw. It's basically the rest of the world that has caused the need for U2F/TOTP because they can't deploy smartcards with certs to users.

There's a wiki page that describes the authentication process in Estonia: https://eid.eesti.ee/index.php/Authenticating_in_web_applica...

Re: The bleak picture of two-factor authentication adoption in the wild

#82
post #56
post #53

Earlier quoted context omitted.

Yes, but one has to buy another device, and only a limited number of companies support it at the moment [1]. It doesn't look like any of the banks I use, any of the credit cards I use, or the tax filing service I use support it. Not to mention that this website and other forums I log into aren't mentioned there either. Some of those companies offer SMS or email based 2FA as an option. In any case, every single one of…

There are others which aren't listed there, like OVH (the largest European hosting company). The dearth of banks is real though. And sad. I have only seen client-side certificates used twice. Once at now infamous StartSSL and second at a bank but for vendor access, not regular customers. Its huge downside is that it's a second factor which doesn't protect against a compromised device.

> Its huge downside is that it's a second factor which doesn't protect against a compromised device.

That's true, but I think that if people used an encrypted private key (protected by a passphrase), then that would be less of an issue.

Re: The bleak picture of two-factor authentication adoption in the wild

#83
post #76

Earlier quoted context omitted.

So I need a physical token for each of my bank accounts (3 bank accounts), each of my investment accounts (2 investment accounts), each of my e-mail providers (2 e-mail providers) and one for every other service which might want to offer 2FA. Or, instead of that, I can have one smartphone, which has an app which handles all of those 2FA codes for me. Can you understand why I would prefer the smartphone option?

loose your phone and all your accounts are locked until you can resolve it. that may be fine for some things, but surely not my bank account

I have far more confidence in my ability to hang on to a single smartphone than I have in my ability to hang on to a dozen or more separate 2FA hardware tokens.

Re: The bleak picture of two-factor authentication adoption in the wild

#85
post #65

Earlier quoted context omitted.

So I need a physical token for each of my bank accounts (3 bank accounts), each of my investment accounts (2 investment accounts), each of my e-mail providers (2 e-mail providers) and one for every other service which might want to offer 2FA. Or, instead of that, I can have one smartphone, which has an app which handles all of those 2FA codes for me. Can you understand why I would prefer the smartphone option?

So you also can possibly enjoy having 2FA demolish by a simple smartphones vulnerabilities that perhaps grab both passwords and token in a single action... We can't trust smartphones/connected devices in general, that's why IMO is better, for safe auth only, use offline stuff.

So you also can possibly enjoy having 2FA demolish by a simple smartphones vulnerabilities that perhaps grab both passwords and token in a single action...

Can you point to any instances where that's actually happened? Yes, sure, it's theoretically possible for someone to break into my fully patched phone and steal my 2FA secrets. But it's also theoretically possible for a mobster to break into my house, hold a gun to my head, and force me to log in to all of my banks accounts so that he or she can drain the money from them.

There is no such thing as perfect security, and I would much rather have people using a 2FA app on their phone than just username/password. Is it perfect? No, of course not. But insisting that the existence of phone vulnerabilities makes 2FA apps on phone unacceptable, and that the only form of acceptable security is for people to juggle dozens of authenticator tokens is making the perfect the enemy of the good. It's because of "advice" like this that people ignore armchair security experts.

Re: The bleak picture of two-factor authentication adoption in the wild

#86
post #74

Earlier quoted context omitted.

It's disturbing how many developers simply gloss over the fact that requiring a smartphone with one of two non-free OSes installed (Android and IOS) is severely limiting the user's freedom in their use of digital services. In the Netherlands the ING bank was testing the waters this year by holding back on announcing a non-smartphone alternative to their ageing authentication methods (either SMS or a list of pre-gener…

could you give some exapmples on how it limits the use of your device? while i agree with you, i seem to lack the imagination to come up with realistic examples that i can present as arguments. i am afraid anything i think of would get a response like "yeah, sure, but noone uses their phone like that" or they'll simply accuse me of being paranoid.

I do not want proprietary software nor I want to depend on black boxes to use a service. So if a bank, a public administration etc demand using proprietary stuff that does not came from them they force their customers to buy such black boxes and suffer all their limitations.

For instance I hate in the same way countries that ask users to install proprietary crappy software's to pay taxes instead simple pdfs/standard WebUI.

Re: The bleak picture of two-factor authentication adoption in the wild

#87
post #65

Earlier quoted context omitted.

So you also can possibly enjoy having 2FA demolish by a simple smartphones vulnerabilities that perhaps grab both passwords and token in a single action... We can't trust smartphones/connected devices in general, that's why IMO is better, for safe auth only, use offline stuff.

So you also can possibly enjoy having 2FA demolish by a simple smartphones vulnerabilities that perhaps grab both passwords and token in a single action... Can you point to any instances where that's actually happened? Yes, sure, it's theoretically possible for someone to break into my fully patched phone and steal my 2FA secrets. But it's also theoretically possible for a mobster to break into my house, hold a gun t…

Does you credit card ever lock you out? For most people no it's not happen, for Julian Assange we know it happen. Does we have an nuclear warhead explode by accident?

A dangerous thing remain dangerous even before accidents happen.

Re: The bleak picture of two-factor authentication adoption in the wild

#88
post #76

Earlier quoted context omitted.

loose your phone and all your accounts are locked until you can resolve it. that may be fine for some things, but surely not my bank account

I have far more confidence in my ability to hang on to a single smartphone than I have in my ability to hang on to a dozen or more separate 2FA hardware tokens.

Your ability may be relevant but only to a certain extent: for instance I can restore my personal desktop with data and software from scratch quickly and easily from my multiple backups.

I use NixOS so my OS will replicate autonomously, I have dotfiles managed via org-mode+stow (and trying homeManager), rsync and unison at hand. I'm pretty confident that I can survive many kind of crush quickly with enough safety.

My phone however is an entirely different story: I can't backup it properly, I have to relay to obscure, proprietary and totally unreliable mechanism that prove to being able to restore only parts of my phone "operating environment" and in an unpredictable manner.

What you can do with all your soft-token if your phone suddenly die?

Another example in the past banks have had bankbook on paper, essentially ledgers that banks and their consumers have in hand, so both parties can prove a transaction. Now it's all on bank's servers, I can prove nothing as a consumers, I can only hope my bank do it's job well. Same if you buy shares, in the past you obtain a paper document that prove the transaction, now it's all on someone else server. You can take screenshots, perhaps have some sort of pdf receipts but they have essentially no legal value, anyone can forge them. Credit card are the same, internally they operate like paper bankbook, recording a certain number of transactions, however you have no control on that.

That's the BIG point: it doesn't matter how skilled and provident you are, the systems it more and more designed in a way that you are TOTALLY powerless, no matter how many things you know and how attentive you are.

Re: The bleak picture of two-factor authentication adoption in the wild

#89
post #74

Earlier quoted context omitted.

It's disturbing how many developers simply gloss over the fact that requiring a smartphone with one of two non-free OSes installed (Android and IOS) is severely limiting the user's freedom in their use of digital services. In the Netherlands the ING bank was testing the waters this year by holding back on announcing a non-smartphone alternative to their ageing authentication methods (either SMS or a list of pre-gener…

could you give some exapmples on how it limits the use of your device? while i agree with you, i seem to lack the imagination to come up with realistic examples that i can present as arguments. i am afraid anything i think of would get a response like "yeah, sure, but noone uses their phone like that" or they'll simply accuse me of being paranoid.

> could you give some exapmples on how it limits the use of your device?

Forcing me to use a smartphone app means I can't use a normal desktop or laptop computer, or even a non-Android, non-IOS smartphone. It means that institutions that provide a semi-public utility (e.g., banks) force people to support and agree with the terms of use supplied by a (foreign) megacorporation to function as a citizen in the digital realm. That is inherently undemocratic and a threat to our freedoms.

Expecting the vast majority of citizens to have access to a computing device with a modern web browser is somewhat reasonable (as long as those who can't are supported by other means). You can at least choose what software you run, and there are free software options available. With smartphone apps (well-built web applications excluded) that freedom does not exist.

Re: The bleak picture of two-factor authentication adoption in the wild

#90
post #76

Earlier quoted context omitted.

loose your phone and all your accounts are locked until you can resolve it. that may be fine for some things, but surely not my bank account

I have far more confidence in my ability to hang on to a single smartphone than I have in my ability to hang on to a dozen or more separate 2FA hardware tokens.

my hardware tokens are locked safely at home or in the company office (to manage accounts for work), and only taken out when i need them.

the phone i carry always around. the risk if loss or theft is always lingering.

my wife just dropped her phone. it crashed. took 5 minutes to boot, i guess a filesystem check after the crash. it could have died completely too. my previous phone stopped working because of a botched update. we had a phone stolen...

there are just to many uncertainties to trust a single portable device.

Post reply on HN