{"id":36484,"date":"2022-07-12T15:30:01","date_gmt":"2022-07-12T19:30:01","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=36484"},"modified":"2022-07-12T19:29:28","modified_gmt":"2022-07-12T23:29:28","slug":"multi-factor-authentication-recovery-distrust","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2022\/07\/12\/multi-factor-authentication-recovery-distrust\/","title":{"rendered":"Multi-Factor Authentication Recovery Distrust"},"content":{"rendered":"<p><a href=\"https:\/\/utcc.utoronto.ca\/~cks\/space\/blog\/tech\/MFAAccountRecoveryDistrust\">Chris Siebenmann<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=32054476\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/utcc.utoronto.ca\/~cks\/space\/blog\/tech\/MFAAccountRecoveryDistrust\"><p>But both of these situations have some things in common. I can actually talk to real people in both situations, and both have out of band means of identifying me (and communicating with me).<\/p><p>Famously, neither of these is the case with many large third party websites, which often have functionally no customer support and generally no out of band ways of identifying you (at least not ones they trust). If you (I) suffer total loss of all of your means of doing MFA, you are probably completely out of luck. One consequence of this is that you really need to have multiple forms of MFA set up before you make MFA mandatory on your account (better sites will insist on this).<\/p><p>[&#8230;]<\/p><p>More broadly, this is a balance of risks issue. I care quite a bit about the availability of my accounts, and I feel that it&rsquo;s much more likely that I will suffer from MFA issues than it is that I will be targeted and successfully phished for my regular account credentials (or that someone can use &lsquo;account recovery&rsquo; to take over the account). If loss of MFA is fatal, my overall risks go way up if I use MFA, although the risk of account compromise goes way down.<\/p><\/blockquote>\n<p>It seems like most sites that use two-factory authentication don&rsquo;t offer recovery codes.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/06\/29\/passkeys\/\">Passkeys<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2012\/11\/15\/kill-the-password\/\">Kill the Password<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2012\/08\/04\/find-my-mac-and-remote-wipe\/\">Find My Mac and Remote Wipe<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Chris Siebenmann (Hacker News): But both of these situations have some things in common. I can actually talk to real people in both situations, and both have out of band means of identifying me (and communicating with me).Famously, neither of these is the case with many large third party websites, which often have functionally no [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2022-07-12T19:30:05Z","apple_news_api_id":"7cf3068c-d7ed-461b-b16d-1285f0581057","apple_news_api_modified_at":"2022-07-12T23:29:31Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAA==","apple_news_api_share_url":"https:\/\/apple.news\/AfPMGjNftRhuxbRKF8FgQVw","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[48,2090,96],"class_list":["post-36484","post","type-post","status-publish","format-standard","hentry","category-technology","tag-security","tag-two-factor-authentication-2fa","tag-web"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/36484","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=36484"}],"version-history":[{"count":2,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/36484\/revisions"}],"predecessor-version":[{"id":36495,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/36484\/revisions\/36495"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=36484"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=36484"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=36484"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}