Bitcoin Forum
May 02, 2024, 01:49:51 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Traditional Authentication, 2FA and 2SV  (Read 606 times)
This is a self-moderated topic. If you do not want to be moderated by the person who started this topic, create a new topic.
Luzin (OP)
Hero Member
*****
Offline Offline

Activity: 1428
Merit: 779



View Profile
June 17, 2020, 04:06:23 PM
Last edit: June 17, 2020, 04:25:46 PM by Luzin
Merited by Husna QA (5), The Cryptovator (5), vapourminer (3), ShowOff (1), AakZaki (1), cheezcarls (1), OcTradism (1), Peanutswar (1)
 #1

I create this from my tread in the local board:Here through several revisions and discussions.

Some exchange accounts, social media, and several other accounts, there are some differences authentication to log in. From this it can be concluded about the fundamental differences in the security system on several accounts that I made.
1. Traditional Authentication
Thi is only use a username / account email address combination password.
2. Two Factor Authentication
This is Authentication used by many people in the crypto, Verification of ownership using OTP (one time password) additional authentication, or we usually call it 2fa. So in the authentication system using username password an then passcode or token from another device (Yubikey, GA / Authy or others), this process matches our code and the server.
3. Two Step Verification
Almost similar 2fa. But I think this is different. The Two Step Verification use pasword/username and code or link Verification from server, this code was sent via short messages, emails or etc. The difference with 2fa the server gives us the code, this code only the server knows, whereas our 2fa has the same code and only needs to match.

Of the three security when log in account, I found several other combinations >> username / password> 2FA> 2SV but this happens if the IP is different, example if you log in Indodax Exchange or Bittrex. I think this combinations security authentication is good, if applied to all websites relating crypto asset and other website relating to important data.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|
██░░░░░░░░░░░░░░░░░░░░░░██
▀█▄░▄▄░░░░░░░░░░░░▄▄░▄█▀
▄▄███░░░░░░░░░░░░░░███▄▄
▀░▀▄▀▄░░░░░▄▄░░░░░▄▀▄▀░▀
▄▄▄▄▄▀▀▄▄▀▀▄▄▄▄▄
█░▄▄▄██████▄▄▄░█
█░▀▀████████▀▀░█
█░█▀▄▄▄▄▄▄▄▄██░█
█░█▀████████░█
█░█░██████░█
▀▄▀▄███▀▄▀
▄▀▄
▀▄▄▄▄▀▄▀▄
██▀░░░░░░░░▀██
||.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
FAZE CLAN
SSC NAPOLI
|
1714614591
Hero Member
*
Offline Offline

Posts: 1714614591

View Profile Personal Message (Offline)

Ignore
1714614591
Reply with quote  #2

1714614591
Report to moderator
1714614591
Hero Member
*
Offline Offline

Posts: 1714614591

View Profile Personal Message (Offline)

Ignore
1714614591
Reply with quote  #2

1714614591
Report to moderator
1714614591
Hero Member
*
Offline Offline

Posts: 1714614591

View Profile Personal Message (Offline)

Ignore
1714614591
Reply with quote  #2

1714614591
Report to moderator
You get merit points when someone likes your post enough to give you some. And for every 2 merit points you receive, you can send 1 merit point to someone else!
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714614591
Hero Member
*
Offline Offline

Posts: 1714614591

View Profile Personal Message (Offline)

Ignore
1714614591
Reply with quote  #2

1714614591
Report to moderator
1714614591
Hero Member
*
Offline Offline

Posts: 1714614591

View Profile Personal Message (Offline)

Ignore
1714614591
Reply with quote  #2

1714614591
Report to moderator
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
June 17, 2020, 04:19:44 PM
 #2

Sending authentication keys as an oto either on Google auth and sms are something used widely across the whole financial industry from what I've seen.

The ubikey/cryptographic signature part though is a well welcomed part here at increasing security, I've sedn a lot of sites using it but quite a few don't and it'd be nice if they did so hopefully they can notice this topic (or new devs might at least)...
andriyana
Full Member
***
Offline Offline

Activity: 842
Merit: 100


View Profile
June 17, 2020, 05:04:46 PM
 #3

I think Two-Step Verification is very good to use for an exchange or email account
because when we log in to account the server send a secret code to enter, this may be very recommended
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18509


View Profile
June 17, 2020, 06:58:39 PM
Merited by Luzin (1)
 #4

Using those definitions, then "Single Factor, 2 step verification" is insecure and shouldn't be used.

Many exchange accounts or web wallets which are hacked are hacked because the attacker gains access to the victims email account or phone number, and then uses that to reset the password on the relevant exchange or wallet account. If your two step verification involves entering a code sent by email or by SMS, then it achieves nothing since the attacker will already have access to these. The number of email account password which have been leaked in various database breaches is astronomical, and since people frequently reuse passwords, these can often be easily hacked. An attacker can transfer your phone number and therefore receive all your SMS messages with a little bit of knowledge from your social media profiles/online presence and a single phone call to your mobile provider. If they can log in to your exchange account and provide the two step code all from a single point of failure, then that set up is no more secure than just using a single password.

The whole point of 2FA is in the name - 2 factor verification. Your second factor needs to be something completely separate - at the very least an authenticator app, but even better if you use a hardware key like a Yubikey (many crypto hardware wallets can also be used as a 2FA hardware key).
hatshepsut93
Legendary
*
Offline Offline

Activity: 2954
Merit: 2145



View Profile
June 17, 2020, 09:42:04 PM
Merited by o_e_l_e_o (2)
 #5

Using those definitions, then "Single Factor, 2 step verification" is insecure and shouldn't be used.

If it's a matter of choice between "no 2 step verification" and "2 step verification", then it should obviously be picked. Hacking email would indeed bypass it, but there are many other attacks which can be mitigated with is - XSS, CSRF, session hijacking, phishing, password cracking.

It's better to always look for a services that use 2FA, but if there's no other way, then 2 step verification is better than nothing.

.BEST.CHANGE..███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Luzin (OP)
Hero Member
*****
Offline Offline

Activity: 1428
Merit: 779



View Profile
June 18, 2020, 04:44:56 AM
Last edit: June 18, 2020, 05:39:48 AM by Luzin
 #6

Using those definitions, then "Single Factor, 2 step verification" is insecure and shouldn't be used.
The whole point of 2FA is in the name - 2 factor verification. Your second factor needs to be something completely separate - at the very least an authenticator app, but even better if you use a hardware key like a Yubikey (many crypto hardware wallets can also be used as a 2FA hardware key).

Yes, in many cases simswap or simjacking, the fraudster exploits the ability of cell phone service providers to port phone numbers to devices that contain other customer identity (SIM) modules. Fraudsters collect personal data about victims, usually by phishing emails or buying from identity thieves. But the 2SV 2FA combination authentication system seems to be quite good, although it is rather risky if the authentication is sent via short message or email. More than that, we must be careful.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|
██░░░░░░░░░░░░░░░░░░░░░░██
▀█▄░▄▄░░░░░░░░░░░░▄▄░▄█▀
▄▄███░░░░░░░░░░░░░░███▄▄
▀░▀▄▀▄░░░░░▄▄░░░░░▄▀▄▀░▀
▄▄▄▄▄▀▀▄▄▀▀▄▄▄▄▄
█░▄▄▄██████▄▄▄░█
█░▀▀████████▀▀░█
█░█▀▄▄▄▄▄▄▄▄██░█
█░█▀████████░█
█░█░██████░█
▀▄▀▄███▀▄▀
▄▀▄
▀▄▄▄▄▀▄▀▄
██▀░░░░░░░░▀██
||.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
FAZE CLAN
SSC NAPOLI
|
OcTradism
Hero Member
*****
Offline Offline

Activity: 1722
Merit: 801



View Profile WWW
June 18, 2020, 01:19:11 PM
 #7

Good topics on security and privacy.

.
.Duelbits.
█▀▀▀▀▀











█▄▄▄▄▄
TRY OUR
  NEW  UNIQUE
GAMES!
.
..DICE...
███████████████████████████████
███▀▀                     ▀▀███
███    ▄▄▄▄         ▄▄▄▄    ███
███   ██████       ██████   ███
███   ▀████▀       ▀████▀   ███
███                         ███
███                         ███
███                         ███
███   ▄████▄       ▄████▄   ███
███   ██████       ██████   ███
███    ▀▀▀▀         ▀▀▀▀    ███
███▄▄                     ▄▄███
███████████████████████████████
.
.MINES.
███████████████████████████████
████████████████████████▄▀▄████
██████████████▀▄▄▄▀█████▄▀▄████
████████████▀ █████▄▀████ █████
██████████      █████▄▀▀▄██████
███████▀          ▀████████████
█████▀              ▀██████████
█████                ██████████
████▌                ▐█████████
█████                ██████████
██████▄            ▄███████████
████████▄▄      ▄▄█████████████
███████████████████████████████
.
.PLINKO.
███████████████████████████████
█████████▀▀▀       ▀▀▀█████████
██████▀  ▄▄███ ███      ▀██████
█████  ▄▀▀                █████
████  ▀                    ████
███                         ███
███                         ███
███                         ███
████                       ████
█████                     █████
██████▄                 ▄██████
█████████▄▄▄       ▄▄▄█████████
███████████████████████████████
10,000x
MULTIPLIER
NEARLY UP TO
.50%. REWARDS
▀▀▀▀▀█











▄▄▄▄▄█
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!