8 ms·
Very sophisticated attack, I would bet most people would fall for this. I'm surprised Google encourages syncing the codes to the cloud... kind of defeats the p
by rolobio 3y ago
Very sophisticated attack, I would bet most people would fall for this.
I'm surprised Google encourages syncing the codes to the cloud... kind of defeats the purpose. I sync my TOTP between devices using an encrypted backup, even if someone got that file they could not use the codes.
FIDO2 would go a long way to help with this issue. There is no code to share over the phone. FIDO2 can also detect the domain making the request, and will not provide the correct code even it the page looks correct to a human.
- victor106 3y agoThey could’ve just had employees use Okta Verify as opposed to Google Authenticator
- softfalcon 3y ago>FIDO2 can also detect the domain making the request, and will not provide the correct code even it the page looks correct to a human. I could not agree more with this sentiment! We need more of this kind of automated checking going on for users. I'm tired of seeing "just check for typo's in the URL" or "make sure it's the real site!" advice given to the average user. People are not able to do this even when they know how to protect themselves. Humans tire easily and are often fallible. We need more tooling like FIDO2 to automate away this problem for us. I hope the adoption of it will go smoothly in years to come.
- miki123211 3y agoThe problem with Fido (and other such solutions, including smartphone-based passkeys) is that they make things extremely hard if you're poor / homeless / in an unsafe / violent family situation and therefore change devices often. It's mostly a non-issue for Silicon Valley tech employees working solely on their corporate laptops, and U2F is perfect for that use-case, but these concerns make MFA a non-starter for the wider population. We could neatly sidestep all of these issues with cloud-based fingerprint readers, but the privacy advocates won't ever let that happen.
- luma 3y agoBiometrics aren’t a great key because they cannot generally be revoked. This isn’t a privacy concern, it’s a security problem. You leave your fingerprints nearly everywhere you go, and they only need to be compromised once and then can never be used again. At best, you can repeat this process a sum total of 10 times without taking your shoes off to login.
- netik 3y agoI’ve always referred to biometrics as a “non revokable username” and not a “password.” 100% agree with you here.
- softfalcon 3y agoYou're right, software security is only really available to rich and tech minded folks. That's kind of what I was trying to get at with my previous statement about humans being tired and fallible. The way we access and protect our digital assets feels incredibly un-human to me. It's wrapped up in complexity and difficulty that is forced upon the user (or kept away from, if you want to look at it that way). As it is now, all of the solutions are only really available to someone who can afford it (by life circumstance, device availability, internet, etc) and those who can understand all the rules they have to play by to be safe. It's a very un-ideal world to live in. When I brought up FIDO2, I was less saying "FIDO2 is the answer" and more saying, "we need someone to revolutionize the software authentication and security landscape because it is very very flawed".
- supertrope 3y agoStronger security can also help the marginalized. If your abusive SO has the phone plan in their name they can order up a new SIM card and reset passwords on websites that way too often fallback from “two factor” to SMS as a root password.
- GoblinSlayer 3y agoThe claim was that fido protocol is better than totp protocol no matter where you store keys. Your claim is that hardware key storage is difficult, but it doesn't differentiate between protocols: if you lost a device with hardware totp keys, you're not in a better position than if you lost a device with hardware fido keys.
- Guvante 3y agoOn the otherhand having your device die means without cloud backup you either lose access or whoever was relying on that 2FA needs to fall back on something else to authenticate you. After all if I can bypass 2FA with my email whether 2FA is backed up to the cloud doesn't matter from a security standpoint. Certainly I would agree with the assertion that opting out for providers of codes would be nice. Even if it is an auto populated checkbox based on the QR code.
- pushcx 3y agoThe workaround I've seen is to issue a user two 2FAs keys, one for regular use and one to store securely as a backup. If they lose their primary key, they have the backup until a new backup can be sent to them. Using a backup may prompt partial or total restriction until a security check can be done. If they lose both, yes, there needs to be some kind of a reauth. In workplace context like this it's straightforward to design a high-quality reauth procedure.
- andersa 3y agoThey could do what Authy does. Codes are backed up to the cloud, so you're not completely fucked if the phone is stolen. But the backup is encrypted, and to access it on a replacement device you must enter the backup password.
- toast0 3y agoThat relies on someone remembering their backup password that they probably don't use often.
- mannykannot 3y agoI suspect that this sort of issue is the real reason for making it difficult to not back up secrets to the cloud. On the one hand, you will have some number of people pissed off because they were taken advantage of and they realize that it was enabled by having backups in the cloud. On the other, you have people pissed off because they couldn't manage the final step in keeping their shit secure and are now locked out of something. The number in the latter category is vastly larger than the number in the former.
- deleted 3y ago[deleted]
- hn_throwaway_99 3y ago> Very sophisticated attack, I would bet most people would fall for this. No. If you think people at your company would fall for this, then IMO you have bad security training. The simple mantra of "Hang up, lookup, call back" (https://krebsonsecurity.com/2020/04/when-in-doubt-hang-up-look-up-call-back/ https://krebsonsecurity.com/2020/04/when-in-doubt-hang-up-lo...) would have prevented this. Literally like 99% of social engineering attacks would be prevented this way. Seriously, make a little "hang up, look up, call back" jingle for your company. Test it frequently with phishing tests. It is possible in my opinion to make this an ingrained part of your corporate culture. Agree that things like security keys should be in use (and given Retool's business I'm pretty shocked that they weren't), but there are other places that the "hang up, look up, call back" mantra is important, e.g. in other cases where finance people have been tricked into sending wires to fraudsters.
- deleted 3y ago[deleted]
- yesimahuman 3y agoThis fails to satisfy one of the core lessons here: trust nothing, not even your own training and culture.
- _jal 3y agoSo I take it you are employed by someone that allows you to connect to nothing and change nothing? Because if you can do any of those things, your employer is clearly Doing It Wrong, based on your interpretation. (If you happen to be local-king, flip the trust direction, it ends up in the same place.)
- hooverd 3y agoEspecially not the information security team. They're the most likely to be compromised.
- SoftTalker 3y agoReminds me of a situation early in my career where I was talking with the CTO about some security concern and I said "well it's all on the internal company network" and he immediately said "why on earth do you think you can trust our internal network?"
- rakkhi 3y agoSophisticated... ok I mean it's a great reason to use U2F / Webauthn second factor that cannot be entered into a dodgy site https://rakkhi.substack.com/p/how-to-make-phishing-impossible https://rakkhi.substack.com/p/how-to-make-phishing-impossibl...
- duderific 3y agoIn my company, such a communication would never come via a text, so that would be a red flag immediately. All such communications come via email, and we have pretty sophisticated vetting in place to ensure that no such "sketchy" emails even arrive in our inboxes in the first place. Additionally, we have a program in place which periodically "baits" us with fake phishing emails, so we're constantly on the lookout for anything out of the ordinary. I'm not sure what the punishment is for clicking on one of these links in a fake phishing email, but it's likely that you have to take the security training again, so there's a strong disincentive in place.
- rainsford 3y agoAfter initially thinking it was a good idea, I've come to disagree pretty strongly with the idea of phish baiting employees. Telling employees not to click suspicious links is fine, but taking a step further to constantly "testing" them feels like it's placing an unfair burden on the employee. As this attack makes clear, well done targeted phishing can be pretty effective and hard for every employee to detect (and you need every employee to detect it). Company security should be based on the assumption that someone will click a phishing link and make that not a catastrophic event rather than trying to make employees worried to ever click on anything. And has been pointed out, that seems a likely result of that sort of testing. If I get put in a penalty box for clicking on fake links from HR or IT, I'm probably going to stop clicking on real ones as well, which doesn't seem like a desirable outcome.
- deleted 3y ago[deleted]
- wayfinder 3y agoEvery company I’ve worked with has phish baited employees and I’ve never had any problem. It keeps you on your toes and that’s good. What happened in the article — getting access to one person’s MFA one time — is not exactly a catastrophic event. It just happens, as with most security breaches, a bunch of things happened to line up together at one time to make intrusion possible. (And I skimmed the article but it sounded like the attacker didn’t get that much anyway, so it was not catastrophic.) And things lining up rarely happens but it will happen enough times for there to be an article posted to Hacker News once in a while with someone saying that it’s possible to make it perfectly secure.
- adamckay 3y ago> I'm surprised Google encourages syncing the codes to the cloud... kind of defeats the purpose Probably so when you upgrade/lose your phone you don't otherwise lose your MFA tokens. Yes, you're meant to note down some recovery MFA codes when you first set it up, but how many "normal people" do that?
- Master_Odin 3y agoA number of sites I've signed up for recently have required TOTP to be setup, but did not provide back up codes at the same time. There's a lot of iffy implementations out there.
- cottsak 3y agogross
- GoblinSlayer 3y agoThe totp recovery code is just a base32 encoded secret key, which is also present in qr encoded url.
- aeyes 3y agoWith Google Authenticator some years ago it wasn't even possible to restore your codes even if you had a local backup of the device. I'm not sure if that still is the case today but it was a common issue which we saw at our service desk before we switched to a different solution.
- SoftTalker 3y agoYeah I had to re-enroll my phone when I got a new one a few years ago. I never did get around to doing all of them so I still have the old phone in a drawer for those rare times I need it.
- tongueinkek 3y ago[dead]
- bawolff 3y ago> I'm surprised Google encourages syncing the codes to the cloud... kind of defeats the purpose. Depends on what you think the purpose is. People talk about TOTP solving all sorts of problems, but in practise the only one it really solves for most setups is people choosing bad passwords or reusing passwords on other insecure sites. Pretty much every other threat model for it is wishful thinking. While i also think the design decision is questionable, the gain in security from people not constantly losing their phone probably outweighs for the average person the loss of security of it all being in a cloud account (as google cloud for most people is probably one of their most well secured account)
- luma 3y agoTOTP is helpful when you don’t fully trust the input process. If rogue javascript is grabbing creds from your page, or the client has a keylogger they don’t know about, TOTP can help.
- bawolff 3y agoNo it can't. The rouge javascript or keylogger would just steal the totp code, prevent the form submission, and submit its own form on the malicious person's server. Not to mention if your threat model includes attacker has hacked the server and added javascript, why doesn't the attacker just take over the server directly? If the attacker installed a keylogger why dont they just install software to steal your session cookies? This threat model doesn't make sense. It assumes a powerful attacker doing the hard attack and totally ignoring the trivially easy one.
- thayne 3y ago> attacker has hacked the server and added javascript adding javascript doesn't necessarily mean the server is hacked. XSS attacks usually don't require actually compromising the server. Or a malicious browser plugin could inject javascript onto a site.
- hinkley 3y agorogue javascript. It's naughty, not red.
- halfcat 3y ago> I sync my TOTP between devices using an encrypted backup, even if someone got that file they could not use the codes. What do you use to accomplish this?
- fn-mote 3y agoAfter the sync, you have exactly two devices that you can use to answer the MFA challenge, instead of one. It's a backup.
- mos_basik 3y agoNot OP, but I store my TOTP secrets along with all my other passwords in a KeePass database and sync the encrypted database to my devices with Dropbox. All the clients I use to open a KeePass database can generate TOTP codes from the secrets at this point, so I don't use a dedicated TOTP app like Google Authenticator or Authy anymore. Not multifactor anymore, but also not vulnerable to catastrophic phone destruction or Google account banning. It is what it is.
- gmerc 3y agoNot surprised. A team at Google identified this as a vector to juice growth, submitted the metrics which now govern their PSC and didn’t add the necessary counter-metrics to measure negative effects. That’s normal because that’s how the game is played. All the way up the chain to the org leader, there is no incentive to not do this.
- rossjudson 3y agoYou live in a funny alternate reality. You should consider what it might be like to live in one where everyone else isn't dumber than you. I will tell you a truth: People who think they're smarter than everyone else are generally missing important context or information.
- gmerc 3y agoPlease don’t project your inferiority complex onto me.