zlacker

[parent] [thread] 6 comments
1. unethi+(OP)[view] [source] 2022-01-27 21:06:22
TOTP is not going anywhere for much of the Internet. Hold on while I get a Yuibikey to my dad who thinks "folders can't be in other folders" because that's not how they work in real life.

TOTP is a great security enhancement, and while phishable, considerably raises the bar for an attacker.

The fact that TOTP is mentioned as a bad practice in this document is an indicator that this should not be considered a general best practices guide. It is a valid best practice guide for a particular use case and particular user base.

replies(3): >>adgjls+42 >>tptace+R2 >>konklo+oZ
2. adgjls+42[view] [source] 2022-01-27 21:15:25
>>unethi+(OP)
the advantage of fido2/webauthn is actually biggest for non techies. tech people are the ones who won't fall for take bad phishing attempts. stopping malicious logins from fake sites is a massive win.
3. tptace+R2[view] [source] 2022-01-27 21:19:22
>>unethi+(OP)
Yubikeys aren't the serious long-term alternative to TOTP; software keys embedded in phones are what we're going to end up with.
replies(2): >>zie+iw >>takumi+IZ2
◧◩
4. zie+iw[view] [source] [discussion] 2022-01-27 23:41:30
>>tptace+R2
I want to disagree, but I can't, because you are right. Though perhaps as wearable tech grows(watches and what not), perhaps the keys will exist there also.
5. konklo+oZ[view] [source] 2022-01-28 03:42:13
>>unethi+(OP)
The document distinguishes between enterprise-facing and public-facing systems. For enterprise-facing (government employees, contractors, etc.), it's talking about discontinuing use of TOTP. For public-facing systems, it doesn't impose any restrictions, since (as you're saying) the general public really needs options.
◧◩
6. takumi+IZ2[view] [source] [discussion] 2022-01-28 18:04:09
>>tptace+R2
I have a newbie question: Can't we embed a hardware key into a phone, and that'd be just as good as a Yubikey? Do we already do this, or is there a reason why we don't?
replies(1): >>totony+Br4
◧◩◪
7. totony+Br4[view] [source] [discussion] 2022-01-29 04:22:12
>>takumi+IZ2
Laptops can have smart cards so there's no reason a phone couldn't
[go to top]