tags: #authN
Password managers are a must. We all know you should (ideally) use one, and let it pick long/strong passwords, and not reuse the same password across multiple sites.
Where this becomes an issue is with 2FA (two-factor authentication) or TOTP (Time-based One Time Password) – this is typically a 6-digit code that changes every 30 seconds, and you need some sort of app to compute it.
Traditional wisdom said that you should not allow the same password manager to also keep the TOTP secrets and show you the 6-digit code when asked. Why? Because “two factor” means it has to be some other tool/device.
Well… not quite. In fact it’s perfectly safe to put all your eggs in one basket in this specific case.
(Note: I hesitate to tag this as either “intro” or “expert”; ideally everyone should read this but not everyone will appreciate the details, sadly).
Two-factor authentication has benefits from two different points of view.
From my (a normal user) point of view, it blocks attackers trying to login as me on, say, gmail, even if the password is somehow compromised.
From the service provider’s point of view, they improve the security baseline for their users – even users who don’t know/don’t care about security are forced into, effectively, using a unique, random secret.
Let’s understand what threats a two-factor authentication system is actually trying to mitigate. Broadly, these are:
Both these attacks are very common in “mass” attacks from Russia, China, Iran, North Korea, and many other countries. And in both these cases, having a second factor prevents the attacker from successfully logging in to your account.
But in fact, both these problems can be mitigated if you use a password manager. For credential stuffing, all good password managers trivially have features that help you pick better passwords and ensure you don’t reuse them.
For phishing, you are protected if you use a password manager like KeePassXC and its browser extension, and you tell KeePassXC the URL it should expect for each userid/password you add. The browser extension reads the actual URL from the browser, and if it does not match the URL in any of the entries in the password database, it won’t enable the auto-type-password mechanism! (In fact, see the “side note” below for an example where TOTP fails to protect the user, but a proper password manager manages to defeat the attacker!)
So in fact, if you use a password manager already, and use it properly, the second factor is not even a critical need, so why does it matter if you let the same password manager handle that also?
(The only time you would still need this separation is if you think someone can crack your password manager itself – that would be “very very bad” :) Then you better be sure (a) all your important sites are 2FA enabled and (b) your 2FA/TOTP app is on a different device and that it also has not been cracked!)
The real insight here is that the old “something you know, something you have” etc., is not that important. What is more important and useful is to have a response (password, code, …) that changes every time. This of course means you need a device, because a human being cannot “compute” these fast-changing codes in his head.
But that’s the only reason you need a device – to compute the code. It does not matter where that device is, nor what else it is doing (in my case, also managing my passwords!).
There are two kinds of phishing. In the older, more traditional, kind, a phishing site fools you into typing your userid and password, then stores it for future use. This is the kind that TOTP can protect against.
The second kind could be called “active” or “man-in-the-middle” phishing. In this, the attacker site behaves like a “middleman” between you and the genuine website, and when the genuine website asks for the TOTP code, it sends that query back to you, you type it in, and the attacker site forwards it to the genuine website. After that they can even disconnect you because now they are “in”, so to speak. TOTP does not protect against this, but a properly configured password manager can – because the URL won’t match what you specified in the password entry!