npm: set up 2fa on your account
me: can't be bothered, it's not like I publish packages anyway
npm: 2fa! 2fa! 2fa!
me: FINE
<go to login page, enter username and password>
npm: For your security, we've sent a one-time password to your email address
me: <enter one-time password from email>
npm: 404

genius work, npm people.

What do OTP codes guard against that isn't dealt with by email-you-a-code-to-sign-in anyway? I'm in favour of adding more security than just "do you know a password", but if a site already emails you a code to confirm login, what extra security does an OTP app provide? It's more likely to break -- exporting 2fa OTP codes to new devices is still way too hard.
Is it really only "what if someone compromises your whole email account"? Which would be bad, yes, but for more reasons than npm.

@sil sending otp to the same email that gets password reset tokens gains nothing.

@falken what happens if you lose your phone? Answer: you have to email everyone to get the codes reset. Your email account is the ultimate fallback.

@sil That is well it might practically work but it's a problem that shouldn't happen. If you lose your OTP tokens (because you store them on your phone only and lose that) then you should forever lose access to your account.

Being able to get access back by social engineering is a security issue.

@falken

@juliank @falken that is rather hostile. People lose their phones. A service built for users to like should deal with that, rather than using it to further punish you. If you lose your wallet, you can ring your bank and cancel the cards and get new ones. If e we can’t even be as user-friendly as banks, who are notoriously customer-hostile, what are we doing as an industry?

@sil Banks are getting really problematic at least in Germany with their user-friendliness.

They have taken the mantra "your phone is your 2nd factor", so now all you need is aside from login details, is to pair your phone with an SMS code, and then you register your fingerprint and then you use the fingerprint to log in to your phone, log in to your app, and approve transactions.

It's a real shit show.

But as for cards, they don't send you new virtual ones. They mail physically.

@falken

@sil Mailing you physically is a stronger establishment of identity than sending you an email.

Realistically it would be preferable if they also used services that require you to present ID when receiving the card, but they are too cheap.

@falken

@juliank @falken my point here is: we should be, in my opinion, attempting to be friendly and planning how to deal with mistakes when they happen, rather than taking the attitude that if someone screws up then they lose. I think you're taking the opposite approach, which I don't agree with. My fault for using banks as a rhetorical flourish; you're right that they're also terrible, which was the point of using them as an example that we could be better than, but it's derailed the discussion.

@sil There are various different levels of security needs, and some of them may very well be life and death, or at least professional life and death.

Like you should not be able to recover my GitHub account without any of my 3 registered 2FA tokens.

my work SSO account.

my medical insurance account.

Like it is reasonable if you use electronic identity document functions or do a video call where you present ID but not "hello I am Julian and I was born on ... I lost my 2fa codes"

@falken

@sil answer: use the back up codes we gave you, or get a new account. Sometimes falling back to physical verification would be acceptable but it depends what were talking about securing. Some random site ? Just get a new account.

@falken if it's some random site where you don't care about abandoning the account and getting a new one... why bother having extra-secure 2fa OTP codes for it?

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.