I've seen many articles advocating the use of 2FA to improve online security, but I think average home users benefit very little from 2FA and here's why
Some assumptions before I argue my point:
- our scenarios only include average home users, that means a pc and a wifi router and nothing more. enterprise users behind complex firewall and VPN setups are not considered since enterprise security would be an entirely different topic
- once the user's machine is authenticated, online services won't ask for 2FA (which is the case for most websites and apps)
With that in mind, there are two prerequisites for 2FA to be triggered:
- the attacker has the victim's password
- the attacker doesn't have control of the victim's machine
I'll first elaborate on prereq 2. An attacker who has control of the victim's computer is able to impersonate the victim if they had previously logged in to a online service, thereby bypassing 2FA altogether (see assumption 2). In the case of web services provided via browser (like online banking), stealing cookies and using a proxy located in the victim's city is enough.
Apps are a little more complicated because they vary in their techniques to cache authentication info; some do it similar to browser cookies while others that encrypt local data or require matching hardware IDs are harder to fool. Either way having access the the victim's machine opens up endless possibilities to monitor and extract data (reverse shell, remote desktop, keylogger, you name it). To unsuspecting home users, 2FA really doesn't mean a lot when the attacker knows everything the victim owns, does and sees on their pc.
So let's further assume the attackers are not able to tap into the user's computer, leaving only 5 options to acquire the password:
- try to reuse hacked passwords
- brute force
- phishing
- MITM
- tie the victim to a chair and ask for the password
Points 4 and 5 are certainly possible, SSL and TLS have had (and will have) vulnerabilities, and the good old wrench method is arguably one of the most effective ways to break passwords. It comes down to the the question of whether something is worth defending against if it has little to no chance of happening, and in this case I think the answer is no. Vulnerabilities in communication protocols are quickly patched, and 2FAs won't help when the user is physically threatened.
As for 1, 2, and 3, just having good security habits is enough to thwart those attempts. Don't open links in email without checking? should be common sense. And choosing strong passwords and not reusing passwords? That's always a recommended practice, 2FA or not.
Why bother with 2FA when following good security practices alone is sufficient? Of course having extra layers of security always makes your data safer, even by just a little; but at the same time it increases the risk of you locking yourself out. Got a new number? Remember to change the 2FA phone number on all 50 of the websites you use. Bought a new phone? Remember to add it on the Duo app, and god forbid if your current phone gets broken. Having been on both sides of the 2FA experience, I think I have much higher chance of forgetting to babysit my 2FA enabled apps and websites than typing in my password on a phishing link I got in email.
What do you guys think? Is a password manager and some common sense enough to replace 2FA in our day-to-day life?
[link] [comments]
SOCIAL SHARE CARD GENERATOR