Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> You can have

Yes you can have proper security. But this is about the Microsoft solution where you don’t, where you can first guess the password and then guess the 2fa code. Which is not very smart, considering it’s not that much harder to check both at the same time and fail when either is wrong.



> it’s not that much harder to check both at the same time and fail when either is wrong.

You can't do that. Try to imagine what this looks like:

You're at the Microsoft login screen. Microsoft needs you to present both a password and...

* WebAuthn sign-in credentials, for which it must send data to your client

* a TOTP code, from the authenticator you may or may not have

* the SMS code, which you er... wait, what SMS code, how can Microsoft send it to you if you didn't say who you are?

* the email code, which again er... Microsoft can't send this until it knows who you are

OR

* any other technology Microsoft adds later which may require any of the above or something else.


They can switch to display the right one when you enter your email address, they already do this. And of course indeed it doesn’t work with methods like sms and emailing codes, both of which are not secure anyway.


> They can switch to display the right one when you enter your email address, they already do this

So the effect here is this gives bad guys a free targeting feature. Just type in any email addresses and Microsoft will tell you which 2FA is enabled if any.

> And of course indeed it doesn’t work with methods like sms and emailing codes

So, it doesn't help at all for the good case, and it breaks the bad case worse, what was the goal again?


Sorry, but if you think emailing codes is the good case you’re beyond help.


WebAuthn is the good case, which is the case you didn't break since it doesn't care about any of this. And you made the bad cases worse. So good news I guess, "At least Microsoft aren't as bad at this as tinus_hn".


Ah, so you just don’t get it. That’s fine. Other people will improve things along the way.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: