[HN Gopher] Phishing 2FA 25 years ago
       ___________________________________________________________________
        
       Phishing 2FA 25 years ago
        
       Author : pbear2k23
       Score  : 34 points
       Date   : 2023-10-06 18:34 UTC (4 hours ago)
        
 (HTM) web link (twitter.com)
 (TXT) w3m dump (twitter.com)
        
       | br1 wrote:
       | The old solutions to phishing, education and weak 2fa, are in the
       | way of the new and improved solutions, FIDO, passkeys. Nobody
       | wants to admit that the old ways were lacking. They were hipped
       | too hard. It's like when new health guidelines appear and
       | contradict the old ones.
        
         | kstrauser wrote:
         | Me! _waves hand in the air_ I admit the old ways were lacking.
         | We just didn 't have a lot of better alternatives at the time.
         | SMS 2FA beats no 2FA. TOTP beats SMS 2FA. FIDO/passkeys/etc
         | beat TOTP.
         | 
         | We've made a lot of progress as new methods and technologies
         | have become available.
        
       | lcnPylGDnU4H9OF wrote:
       | https://en.wikipedia.org/wiki/Universal_2nd_Factor
       | 
       | https://www.yubico.com/
       | 
       | A 2FA _token_ is simply another  "thing you know". A plugged-in
       | USB dongle is actually "something you have". (Although,
       | technically, it's still "something you know" because it has a
       | secret key; it's _considerably_ more difficult to phish this
       | key.)
        
         | TestingTest5 wrote:
         | Right now the most basic USB-C Yubico Key-Dongle goes for
         | around $80 (considering taxes and shipping in Europe). As
         | yubico state themselves, you really need 2 dongles just in
         | case.
         | 
         | Most people are not paying $160 for this, period, when 2FA and
         | passkeys are a "good enough" thing.
        
       | throw0101c wrote:
       | In addition to tokens there were software-only solutions:
       | 
       | * https://en.wikipedia.org/wiki/S/KEY (RFC 1760)
       | 
       | * https://en.wikipedia.org/wiki/OPIE_Authentication_System
       | 
       | * https://en.wikipedia.org/wiki/OTPW
        
       | Dachande663 wrote:
       | Do people not track the last used time window of a TOTP and
       | require a newer window for subsequent events? Most libraries I've
       | used come with that as part of the interface.
        
         | gs17 wrote:
         | It wouldn't help here, the OTP was only actually used when he
         | received the phished login. The fake site didn't submit it to
         | the AOL servers.
        
       ___________________________________________________________________
       (page generated 2023-10-06 23:01 UTC)