Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

You're not Dave. Who are you?


computers / comp.misc / Re: best option for "archival" 2fa?

SubjectAuthor
* best option for "archival" 2fa?Eli the Bearded
+- Re: best option for "archival" 2fa?Richard Kettlewell
+- Re: best option for "archival" 2fa?Rich
`- Re: best option for "archival" 2fa?Javier

1
best option for "archival" 2fa?

<eli$2105071413@qaz.wtf>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=599&group=comp.misc#599

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!usenet.goja.nl.eu.org!3.eu.feeder.erje.net!2.eu.feeder.erje.net!feeder.erje.net!goblin2!goblin3!goblin.stu.neva.ru!panix!qz!not-for-mail
From: *...@eli.users.panix.com (Eli the Bearded)
Newsgroups: comp.misc
Subject: best option for "archival" 2fa?
Date: Fri, 7 May 2021 18:18:09 +0000 (UTC)
Organization: Some absurd concept
Lines: 44
Message-ID: <eli$2105071413@qaz.wtf>
NNTP-Posting-Host: panix5.panix.com
X-Trace: reader1.panix.com 1620411489 10970 166.84.1.5 (7 May 2021 18:18:09 GMT)
X-Complaints-To: abuse@panix.com
NNTP-Posting-Date: Fri, 7 May 2021 18:18:09 +0000 (UTC)
X-Liz: It's actually happened, the entire Internet is a massive game of Redcode
X-Motto: "Erosion of rights never seems to reverse itself." -- kenny@panix
X-US-Congress: Moronic Fucks.
X-Attribution: EtB
XFrom: is a real address
Encrypted: double rot-13
User-Agent: Vectrex rn 2.1 (beta)
 by: Eli the Bearded - Fri, 7 May 2021 18:18 UTC

I have a bazillion accounts that I don't log into regularly. Many can be
configured with email or SMS two-factor auth. Some can be configured
with other types.

I'm curious if people have opinions about what would be the best choice
for long term neglect. For this exercise, I'm less concerned with
security and more concerned with "I can successfully use it in ten
years."

Email, particularly to a hostname I own, is pretty good.

Email to my current ISP account is a very close second. (I've had this
address for ~ 24 years and there is little likilihood of the ISP going
away in such a way that email addresses would cease to work. Even if
the company went away, there are a lot of highly technical customers
who could band together to recreate it for email use, and the private
ownership is very friendly to customers.)

SMS, not as good. I've three cell phone numbers during the period of
time I've had my main ISP account. My wife has had four numbers in the
same period. Phone number portability is good, but probably wouldn't
be great if I moved out of country. (I have no current plans to do so,
but I'd also like to keep options open.)

Yubikey works great for day to day use. But for a ten year "set it and
forget it"? Too high a chance of me losiing it, or it breaking in two
to five years. I've seen photos of older ones beat up from years of use.

OTP tools like Google Authenticator and Authy also work fine for day to
day, but closed source and would seem difficult to migrate off of a device
and on to an emulated device.

So things to consider:
- If it is something I have to pay for as a subscription, what is the
likelihood of the thing still being available on the market in a
decade?
- If it is something I have to pay for as a one time purchase, what is
the likelihood I can still use it in a decade?
- If it is a free thing, can it be backed up and restored without help
from the a device or software maker?

Elijah
------
has not, eg, logged into gmail for the last two years

Re: best option for "archival" 2fa?

<87czu21gnr.fsf@LkoBDZeT.terraraq.uk>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=600&group=comp.misc#600

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!aioe.org!nntp.terraraq.uk!.POSTED.nntp.terraraq.uk!not-for-mail
From: inva...@invalid.invalid (Richard Kettlewell)
Newsgroups: comp.misc
Subject: Re: best option for "archival" 2fa?
Date: Fri, 07 May 2021 20:35:04 +0100
Organization: terraraq NNTP server
Message-ID: <87czu21gnr.fsf@LkoBDZeT.terraraq.uk>
References: <eli$2105071413@qaz.wtf>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Injection-Info: mantic.terraraq.uk; posting-host="nntp.terraraq.uk:2a00:1098:0:86:1000:3f:0:2";
logging-data="5030"; mail-complaints-to="usenet@mantic.terraraq.uk"
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux)
Cancel-Lock: sha1:x1GxoLavqH+ExCuSA29kLusjnS8=
X-Face: h[Hh-7npe<<b4/eW[]sat,I3O`t8A`(ej.H!F4\8|;ih)`7{@:A~/j1}gTt4e7-n*F?.Rl^
F<\{jehn7.KrO{!7=:(@J~]<.[{>v9!1<qZY,{EJxg6?Er4Y7Ng2\Ft>Z&W?r\c.!4DXH5PWpga"ha
+r0NzP?vnz:e/knOY)PI-
X-Boydie: NO
 by: Richard Kettlewell - Fri, 7 May 2021 19:35 UTC

Eli the Bearded <*@eli.users.panix.com> writes:
> I have a bazillion accounts that I don't log into regularly. Many can be
> configured with email or SMS two-factor auth. Some can be configured
> with other types.
>
> I'm curious if people have opinions about what would be the best choice
> for long term neglect. For this exercise, I'm less concerned with
> security and more concerned with "I can successfully use it in ten
> years."

I think your analysis of the suitability of the different approaches is
sound, and the answer is that you have to see second factor migration as
a normal part of the security lifecycle, just like you occasionally need
to change passwords (e.g. following a data breach, or advances in the
state of the art in password cracking).

A handful of years back I went through my online accounts and closed
those I wasn’t using (where possible). If I need them again I’ll create
new ones.

--
https://www.greenend.org.uk/rjk/

Re: best option for "archival" 2fa?

<s7487b$6ba$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=601&group=comp.misc#601

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: ric...@example.invalid (Rich)
Newsgroups: comp.misc
Subject: Re: best option for "archival" 2fa?
Date: Fri, 7 May 2021 20:33:47 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 33
Message-ID: <s7487b$6ba$1@dont-email.me>
References: <eli$2105071413@qaz.wtf>
Injection-Date: Fri, 7 May 2021 20:33:47 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="d36e93777c6ef5a790614fc87df762ab";
logging-data="6506"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19tn9NP3m/yLjwh+BUH0zXo"
User-Agent: tin/2.0.1-20111224 ("Achenvoir") (UNIX) (Linux/3.10.17 (x86_64))
Cancel-Lock: sha1:e2KPui1I0FcoG3JjIWJrsULLy3M=
 by: Rich - Fri, 7 May 2021 20:33 UTC

Eli the Bearded <*@eli.users.panix.com> wrote:
> OTP tools like Google Authenticator and Authy also work fine for day to
> day, but closed source and would seem difficult to migrate off of a device
> and on to an emulated device.

G.Authenticator is difficult to migrate off, because as I understand
how it works that app disallows one to get at the underlying "secret
number" used for the TOTP algorithm, so one is "stuck" to that app
once one imports the QR code (unless one thought to archive the QR code
when adding it to the app).

But, if you have an android device, this one:

https://f-droid.org/en/packages/org.liberty.android.freeotpplus/

Handles TOTP, and allows you to, from within the app, create a backup
of the secrets data to either a JSON or a URI format file. The JSON
format preserves all of the internal app data, including the 'secrets'
from the QR barcode.

From there, moving the file off the device to a desktop would allow you
can backup the "secrets" however you wish in whatever secure manner you
wish, and having the secrets available would allow use of those
yourself outside of any app (i.e., on that desktop machine) with a bit
of programminng:

https://en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm

The algorithm is not hard to follow, and libraries for the hash used
exist for most languages one would use.

And, all the f-droid.org apps are opensource. FreeOTP+ is Apache 2.0
licensed.

Re: best option for "archival" 2fa?

<i8WdnQc1hKkCKQj9nZ2dnUU78VfNnZ2d@brightview.co.uk>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=602&group=comp.misc#602

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!3.eu.feeder.erje.net!feeder.erje.net!border1.nntp.ams1.giganews.com!nntp.giganews.com!buffer1.nntp.ams1.giganews.com!buffer2.nntp.ams1.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Fri, 07 May 2021 16:43:59 -0500
From: inva...@invalid.invalid (Javier)
Subject: Re: best option for "archival" 2fa?
Newsgroups: comp.misc
References: <eli$2105071413@qaz.wtf>
Message-ID: <i8WdnQc1hKkCKQj9nZ2dnUU78VfNnZ2d@brightview.co.uk>
Date: Fri, 07 May 2021 16:43:59 -0500
Lines: 37
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-hpFi07N+DLnKDFtbgBRDBUF+8YUNDqnjeW2+K16SImq60oEm5M2Pp4u/+mZU1ZRqDDEMoxSwNi0zCWk!gllJFggfqstyopDxI894a2oFj+rkyrWtnTlmujOCvgJqjItLh5AzZrOwaWayZtJRcnrXs7oGQgFx!HRdlp3trHL90FwELRp2DT5v9V9A=
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 2758
 by: Javier - Fri, 7 May 2021 21:43 UTC

Eli the Bearded <*@eli.users.panix.com> wrote:
> SMS, not as good. I've three cell phone numbers during the period of
> time I've had my main ISP account. My wife has had four numbers in the
> same period. Phone number portability is good, but probably wouldn't
> be great if I moved out of country. (I have no current plans to do so,
> but I'd also like to keep options open.)
>
> So things to consider:
> - If it is something I have to pay for as a subscription, what is the
> likelihood of the thing still being available on the market in a
> decade?
> - If it is something I have to pay for as a one time purchase, what is
> the likelihood I can still use it in a decade?
> - If it is a free thing, can it be backed up and restored without help
> from the a device or software maker?

Instead of SMS and mobile numbers you can use a VoIP phone, which is
much lower cost than mobile. SMSs can be forwarded to to email.
Prices went up 5 years ago, because of making VoIP numbers to pay for
911 costs. But costs are still reasonable. Keeping a US termination
number is just $15 per year, and you can use it for other things like
calling relatives.

Using a VoIP phone number abroad has the advantage that unlike mobile
it has no roaming costs.

I think Eli lives in the USA whose phone network does not have a
different prefix for mobile numbers, so they are almost
indistinguishable from landlines. Possibly some companies are
inteligent enough to discriminate mobile numbers (google? skype?, my
memory is fuzzy and I don't remmeber well), but that's not the case
for most companies (even big ones as Paypal). I can confirm that
Paypal US does not care about VoIP.

In Europe is different and mobile phones use different prefixes, so
possibly getting a mobile number on VoIP may be hard (I don't know,
since I never tried myself to that in Europe).

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor