Hacker News new | ask | show | jobs
by Rebles 937 days ago
authenticator apps +1
2 comments

I don't care much for third parties inserting themselves into (and likely collecting data on) things that have nothing to do with them. What kind of authenticator app would make it impossible for the maker of that app to know who I am or what services I'm using and when/how often I use them?
What about people who don't have a smartphone?
There is no smartphone requirement in RFC 6238. Smartphones are simply the device that a lot of people use as their user-agent, but you can use a computer if you prefer.

https://www.rfc-editor.org/rfc/rfc6238

You could get those little mini RSA token things that are just a battery-powered thing the size of a USB stick. I assume those are still around... haven't used one in years tho.
These are pretty insecure because OTPs are easily phishable. WebAuthn devices are just as inexpensive, but prevent most phishing attacks.
Couldn't you just set up a text service to request a one time token? That way you could fall back to SMS, but it wouldn't be required.

(e.g., anyone could create a service that someone could use, which would allow them to request a 2fa code to be issued over SMS at any time after enrolling it via the OTP pairing process)

What happens when the attacker uses that fallback to perform the exact same attack that they perform today?
They'll get a government-issued ankle monitor/smartphone..