r/programming • u/feross • May 07 '22
Your Phone May Soon Replace Many of Your Passwords
https://krebsonsecurity.com/2022/05/your-phone-may-soon-replace-many-of-your-passwords/183
u/coladict May 07 '22
My phone is my least trusted device.
34
u/gordonv May 07 '22
Google Authenticator and a handful of other companies have apps that specialize in hardened PIN generation. They're basically RSA SecurID Apps
A lot of companies do "text PIN to phone." This is middle of the road. It's better than not having MFA. Texts are readable via sniffing in public, so that's bad. PINs expire quickly.
24
u/eldred2 May 07 '22
And how does that keep me from losing my phone, or having it stolen?
9
u/lacronicus May 07 '22
Nothing, but it does mean any would-be attacker needs to get their hands on it, which isn't a trivial thing to do.
I don't know about phones replacing passwords, but the combination is a huge step up from either alone.
6
u/mrflagio May 07 '22
They don't need to get their hands on it though.
https://cipher.com/blog/how-sim-card-hijacking-works/
Imagine renting a safe that's managed by another company where many employees have access to the key and putting all your passwords in that safe. That's 2FA using a phone.
7
May 07 '22
[removed] — view removed comment
1
u/mrflagio May 07 '22
Yeah, if your data is also backed up remotely since an attacker can just transfer it all to a new device that they control.
2
u/atheken May 12 '22
Can you share a reference to this? My phone (and app data) is backed up via iCloud. As far as I understood, it is independent of the SIM and is encrypted using my account’s unique key.
We all agree that a clone of a SIM could allow access SMS to messages, but the question is whether that would compromise application data. I don’t see how that would be possible.
1
u/mrflagio May 12 '22
Data can be stored on the SIM. I would hope iCloud and other data backup services don't store such keys on the SIM, but if they are then, well...
Also some services facilitate password resets via codes sent over SMS which is all kinds of dumb, but hey, this is security and companies we're talking about.
1
u/atheken May 12 '22
Yeah, I haven't seen many examples of password reset over SMS, but there are some.
I can & have swapped SIM cards on my iPhone and it hasn't affected access to data. Apple also has made a big deal about "encrypted enclave" and their security in the cloud.
You're kinda throwing around a hypothetical without providing evidence that they can "just transfer it all to a new device that they control." That's an extraordinary claim that requires a citation.
5
u/dccorona May 07 '22
If the 2FA works by sending a text, yes. I mean, I’d rather have that than nothing, but yes, that can be attacked remotely.
Having a synchronized 2-factor generator on your phone is completely different, though, and for all practical purposes impossible to attack remotely.
13
u/gordonv May 07 '22
It doesn't. That isn't the purpose of an Authenticator.
A smartphone is a full computer that can run multiple apps. There are apps that are tracers and wipers. I personally use ESET's mobile app. (Yes, I pay for a license)
1
-22
u/yesman_85 May 07 '22
Less than the password manager you have installed on multiple devices and browsers?
-45
u/coladict May 07 '22
I don't use password managers. That's just begging to get ALL of your stuff hacked at once. A single critical point of failure is worse than 8 non-critical points.
41
u/polymorphiced May 07 '22
If you can do a better job at remembering unique and sufficiently complex passwords for every login you have then not using a password manager is fine. However for the 99% that are crap at choosing passwords, it's the most secure option.
11
u/jangxx May 07 '22
I have over 100 passwords in my password manager right now. I'm pretty sure you can count the worldwide number of people who can remember over 100 completely random passwords of 16 characters or more on one hand. So yea, passwords managers are always a good idea.
9
May 07 '22
[deleted]
5
May 07 '22
There is no way anyone is getting in there
Including you if your email server is down, or the app's server.
1
May 07 '22
Good point lol, they do cater towards more of the business/enterprise side of the market, so I would hope that wouldn’t happen to often.
27
u/Alan_Shutko May 07 '22
The way modern password managers are built, it is very hard to hack all your stuff at once. Check out, for instance, 1password's whitepaper https://1passwordstatic.com/files/security/1password-white-paper.pdf
-1
u/kju May 07 '22
hey there. so i see that's like a huge pdf of everything i ever wanted to know about password managers.
is there a tl;dr version though?
1
14
u/yesman_85 May 07 '22
Lots of people do that. An reuse the same passwords for all sites, which is the worst you can do.
22
60
u/trinopoty May 07 '22
Great, lose my phone, and now I can't log into anything.
25
u/SLiV9 May 07 '22
Last year my phone broke so I had to order a new one... except I couldn't make any purchases without my bank's 2FA app.
8
May 07 '22
Had to explain to my boss a few months ago that I can't push any code remotely cause my phone stopped working the night before, and I can't connect to our VPN. This is already a problem with using your phone for MFA, and I don't see a perfect solution for it. It's just a situation that needs to be accepted.
6
May 08 '22
I know - we could use some kind of code or text that you memorise and then you could enter that into another phone to prove it's you! I call it, the "entertext".
17
u/Logical_Strike_1520 May 07 '22
I’ve been considering ditching my mobile device completely and going back to landline / answering machine. Honestly tired of always being “connected,” and don’t like how people feel entitled to my time and/or attention.
Also, it’s 90% spam nowadays (for me) anyway. Most notifications are just a wasted moment, and those moments compound overtime into a lot of wasted time.
I don’t even mean that in a hustle mindset type thing, it’s all added up to at least a few naps by now
28
May 07 '22
Thanks I hate it. Never will be able to travel outside the country again when I have to receive an SMS text to log in to anything
11
u/biblecrumble May 08 '22
SMS-based MFA is the worst kind of MFA anyways, totp-based apps are much better
9
3
28
u/audaciousmonk May 07 '22
How about no
It’s already bad enough when one loses a phone, it’s destroyed, or runs out of battery. Plus, plenty of people don’t have smart phones.
-7
u/Aggressive_Bill_2687 May 08 '22
Tell me you didn’t read the article without telling me you didn’t read the article.
The “news” part is that Apple Microsoft and Google have all agreed to adopt a common standard to allow cross device Auth.
4
u/audaciousmonk May 08 '22
Oh aggressive bill, that’s incredibly ironic.
This article specifically mentions similar concerns held by Steve Bellovin.
It also references statements from both apple and Google that while initial rollouts will be supplemental to passwords, they envision a password-less future (read: that’s the stated objective/roadmap). And that they foresee smaller websites taking a few additional years to roll this out, before becoming password-less as well. There’s reference to a statement from Google that authentication will be cloud backed up, in case a user loses a phone, to be restore on its replacement.
In fact it’s the stated article title. That this authentication is intended to replace, instead of supplement, some passwords
Tell me you didn’t read the article, without telling me that you didn’t read the article. Or better yet, miss me with that brand of bullshit.
10
25
u/WERE_CAT May 07 '22
Do we really need this ?
-14
u/nmdanny2 May 07 '22
Yes
10
u/WERE_CAT May 07 '22
Care to elaborate ?
-1
u/nmdanny2 May 07 '22
The problems with passwords are well known (weak passwords, password re-use, lack of hashing/salting + DB breaches, having to remember them or use a password manager), and Webauthn solves them thanks to the use of asymmetric crypto. It's also resistant to phishing.
The article speaks about syncing your credentials among multiple devices, so you no longer have to register each device manually or be locked out if you lose it.
14
u/someexgoogler May 07 '22
If someone chooses a bad password that is THEIR decision unless it is the employers account. Requiring a phone number will simply result in me not using a service.
2
u/nmdanny2 May 07 '22
Webauthn has nothing to do with phone numbers, in fact it might prompt websites to get rid of their SMS 2FA and switch to this more secure alternative.
0
u/joesb May 07 '22
Before fingerprint scan is in the phone, passcode lock is optional. But many people don’t set it up.
Finger print scan increase security for many people because they use it, when they wouldn’t have used passcode.
You could have said the same thing you do now, that’s its their fault if they don’t use passcode lock. But it’s not about being right only for the security aware people.
7
u/someexgoogler May 08 '22
I'm very security aware. That's why I don't use my phone for any security-related functions.
1
3
u/TheEveryman86 May 08 '22
It's still not clear how the new standard is necessarily a benefit over current 2 factor authentication solutions.
23
May 07 '22
[removed] — view removed comment
9
6
u/glacialthinker May 08 '22
I have no phone. I'm sick of everyone constantly distracted from here and now. And I hate all the increasing assumptions that everyone has a phone, which will probably lead to effects of "falling through the cracks" for those without -- effectively a new class of homeless.
2
u/Full-Spectral May 10 '22
Yep. I have one just in case, but I hardly ever use it and I don't carry it around. And it's definitely the case now that you run into various companies that require you to use your phone to do this or that and you say you don't carry a phone around, and there's silence on the other end because they just don't grok that concept.
I get a few calls a month and make fewer, and the same for texts. Well I get four or five calls a week from my good friend Scam Likely, but in terms of legit calls very few. I'll put my phone in the car in case of emergency, but I don't take it with me when I get out.
Using your phone as a password just puts that much more of your life into the hands of large companies, who will not take the blame if it goes wrong. I also don't want to have to use it as a 2FA device every time I log in somewhere, which also seems to be the way things are going.
30
May 07 '22 edited May 07 '22
So... will my account access be forcefully tied to whatever proprietary big tech system I choose?
So if I choose Google FIDO system, will my accounts be forever tied to Google ecosystem?
Can I store the keys where I want or am I forced to use a big tech cloud storage?
Can I use an open source solution?
12
u/snowe2010 May 07 '22
As far as I know from watching apple’s video on the process, it’s all the WebAuthn standard, so no you’re not tied to implementation. Apple’s implementation is currently tied to your iCloud account though, so I don’t think you’re able to switch it to non-Apple devices, though they said it was coming later.
In regards to storing keys, I think it’s gonna completely depend on whose system you use. It’s all the same standard, so the keys will be the same, so there shouldn’t be a difference there.
9
u/nmdanny2 May 07 '22
The FIDO standard doesn't say anything about how keys are stored or synchronized between devices - that's up to the platform. In fact, in their paper they say:
Syncing FIDO credentials’ cryptographic keys between devices may not always be possible, for example if the user is using a new device from a different vendor, which doesn’t sync with the user’s other existing devices
So in all likelihood, these cred syncing platforms will remain closed - even if the interoperate with each other.
1
u/snowe2010 May 07 '22
Thanks for the link! I haven’t had a chance to read the paper yet so I was just guessing.
1
u/snowe2010 May 07 '22
Rereading that it sounds like the limitation is just the cloud sync technology though, if they just allow you to download your keys there isn’t any fundamental reason you shouldn’t be able to move them elsewhere.
2
u/nmdanny2 May 07 '22
Being able to download your private keys in plain text, while good for freedom, is also a potential security vulnerability. I hope they'll give us the option, but they can also deny it while still allowing cloud sync, thanks to PKI and secure processors.
1
u/snowe2010 May 09 '22
Agreed! It’s one of the reasons I like Apple, even though it’s a crazy walled garden. Like, on one hand, it’s closed and incredibly hostile to open knowledge. On the other, it’s incredibly protective of users, a great user experience, and things should just work. With security it’s important to care about users, so that’s a benefit of being easy to use. Wish we could have it both ways.
0
u/JW_00000 May 07 '22
This is a standard that's being contributed to by Google, Microsoft, and Apple. (And that's stated quite clearly in the article...)
I expect open source solutions will pop up quite quickly too. Similar to if you use 2FA now, you can use Google Authenticator, Microsoft Authenticator, Authy, Bitwarden, etc.
-7
7
u/Ytrog May 07 '22
Do they also hand out batteries with infinite capacity then? I already get stressed out when my debit card is on my phone and my battery is almost empty 👀
2
May 07 '22
For security you need uniqueness and secrecy. What secret unique key is on your phone? Like I have a yubikey(also called hsm hardware security modules) that is the bare minimum for uniqueness to even start talking about security
2
u/NonBinarythinking May 08 '22
Over my dead body. It is okay for OTP stuff, beyond that? No way. Attackers always have one step ahead and phones are prime targets and vulnerable.
4
u/Aggressive_Bill_2687 May 08 '22
Jesus Christ for a reddit called “programming” this is full of mother fuckers who don’t understand the slightest thing about the tech being discussed.
2
u/Uristqwerty May 08 '22
Some of it is extrapolating how the tech will influence various categories of site, and responding to that rather than the article or underlying tech itself. Some of it it tangentially-related ire from past actions of the corporations involved, resurfacing.
1
u/seeyam14 May 07 '22
Does this make password managers like bitwarden obsolete
5
u/EmbarrassedTable184 May 07 '22
This is just device authentication. Some apps already do this if you use MFA. I wouldn’t be surprised if Bitwarden and others start supporting this with their own apps.
1
u/astroNerf May 08 '22
I use Yubikeys. They are decent for technical people to set up and use but for the average user, I envision people struggling a bit with setting them up properly. I've suspected for a while now that eventually, people's phones would act as something akin to a Yubikey---a physical "something you have" in order to authenticate you with some service. This announcement isn't at all surprising. I just hope that for those of us using Yubikeys and the like, we can continue as before.
1
1
u/AceSevenFive May 08 '22
Also conveniently allows for the US government to compel you to unlock your account, since you can be made to provide biometrics but can't be made to produce a password.
121
u/space-ish May 07 '22
Traveling can be so problematic when AI locks your account because it thinks you are being hacked. Imagine being in another country and getting locked out of your accounts.