Two-factor security is the best lock for your digital life, but it’s not perfect

Two-factor authentication has become something of an online security buzzword over the last few years. Most of us have logged into one service or another only to be presented with a message urging us to implement this form of our protection on an account.

But two-factor authentication isn’t some silver bullet capable of stopping hackers in their tracks. It’s a useful countermeasure to have among your defenses, but ultimately, it’s no substitute for a working knowledge of the biggest threats we face online.

Activate two-factor authentication wherever the opportunity is offered up — but don’t make the mistake of relying on its protection if you don’t understand what it can and cannot defend against. As 2016 proved, the keeping data secure is complex, and overconfidence can leave you open to attack.

Are you who you say you are?

At its core, two-factor authentication is all about checking credentials. It’s a way of making sure that someone is who they claim to be, by verifying two distinct types of evidence. This kind of system has been around for years.

If you don’t understand the basics of computer security, you shouldn’t be allowed to bank on the Internet.

Chip-and-PIN credit card payments are perhaps the most ubiquitous example; they rely on the user having a physical card in their possession, and knowledge of their PIN. While a thief could feasibly steal a card and learn the PIN, it’s not easy to manage both.

There was a time, not so long ago, when financial transactions were the only reason people would have to authenticate their identity on a regular basis. Today, anyone that uses the internet has an array of accounts that they wouldn’t want just anyone to have access to, for a variety of reasons.

The financial industry managed to implement two-factor authentication very easily, because the only hardware that needed to be distributed was a bank card. Distributing a similar system for everyday websites is nearly impossible, so two-factor is enabled through other means. And those methods have flaws of their own.

User experience

“I am really sick of all the convenient things in life suddenly become too cumbersome to use,” reads a comment posted to a 2005 SlashDot article about the imminent rise of two-factor authentication in relation to online banking. “I would really, really hate to have a hard token to carry around.”

“Politicians have no idea what impact this has on the real world,” agreed a second, lamenting the threat of users being forced to purchase extra hardware. “If you don’t understand the basics of computer security, you shouldn’t be allowed to bank on the Internet,” added another commenter.

Today, complaints like these seem positively foolish, but in 2005 users were more considered about the cost and annoyance of carrying some form of two-factor token. User response can prove even more negative when something less important than banking is protected. In 2012, a class action lawsuit was filed against game developer Blizzard Entertainment after the company introduced an authenticator peripheral designed to defend users’ accounts, per a report from the BBC.

lastpass new family sharing features

Efforts to implement this kind of two-factor authentication had been in place since the 1980s, when Security Dynamics Technologies patented a “method and apparatus for positively identifying an individual.” By the 2000s, the infrastructure and manufacturing ability was in place for organizations ranging from financial institutions to video game publishers to enforce their own means of two-factor authentication.

Unfortunately, users decided not to co-operate. Whether the second factor of authentication was as simple as an LCD screen that delivered a unique code, or as complex as a fingerprint scanner, the idea of having yet another piece of physical hardware — and potentially one for every different service that required a unique log-in — was unappealing to the masses.

It’s possible to imagine an alternative history where two-factor never caught on because of this problem. Fortunately for us, Apple introduced the iPhone, and Google introduced Android. Smartphones put a device capable of two-factor authentication into the hands of billions worldwide, resolving the convenience issue that users complained about in 2005.

Smartphones are convenient, but have their own risks

The ubiquitous nature of smartphones has allowed sites and services to remove the hassle from the two-factor authentication process. “The ones that use your cellphone tend to be very easy to use, very low impact,” said security expert and Harvard fellow Bruce Schneier, speaking to Digital Trends earlier this month. “Because it’s something that you have already. It’s not something new that you have to carry around with you.”

It’s possible to imagine an alternative history where two-factor never caught on.

In certain scenarios, this approach can offer definite benefits. For instance, if you’re logging into a service from a new computer, you might be asked to input a code sent to a trusted device as well as your standard password. This is a good example of how to use two-factor authentication; someone else could have stolen your password and tried to log in to the associated account from their system — but unless they’ve already stolen your phone, they won’t be able to gain access.

However, there are threats that this kind of protection simply can’t handle. In 2005, Schneier wrote that “two-factor authentication isn’t our savior” in a blog post delving into its weaknesses.

He went on to describe how a man-in-the-middle attack could hoodwink the user into thinking that they’re on a legitimate website, and convince them to offer up both forms of authentication to a phony log-in screen. He also notes that a Trojan could be used to piggyback off a legitimate log-in that was carried out using two forms of authentication. There’s also the problem of centralizing security on a single device; most people use a smartphone-enabled two-factor for multiple websites. If that phone is stolen and compromised, all those sites are at risk.

Knowledge is power

“When you’re logging into your account, two-factor is great,” said Schneier. “My university, Harvard, uses it, my company uses it. Lots of people have adopted it, and it’s very useful. But what I was writing about then, the problem was it was looked at as a panacea, it’ll solve everything. Of course, we know it doesn’t.”

Financial gain is always going to motivate malicious hackers to cultivate new techniques for accessing other people’s accounts. As long as there’s a benefit to possessing someone else’s credentials, we’re going to see hacking evolve continually.

“There are a lot of different threats, and a lot of different security mechanisms,” Schneier explained. “There’s not just one threat, not just one mechanism, there are many threats and many mechanisms.”

The best defense is a continuous stream of new and improved countermeasures. If we continue to change and update the methods we use to keep our accounts secure, we make things harder for anyone trying to gain access without permission.

Unfortunately, the attackers have the initiative. It took years for two-factor authentication to become accepted by the masses. As new forms of protection become available, we as users need to commit to take advantage of them. And that puts us right back on the Slashdot forums, circa-2005. We all once again become users complaining about convenience, instead of worrying about security.

It’s difficult to ignore how commonplace large-scale hacks have become, and there’s no sign that this form of criminality is going to die off. There is no defense that’s 100 percent capable of blocking any kind of attack; criminals will always find a way to exploit even the smallest weakness. Although it’s not easy, the best way to stay safe online is to be aware of the threats, and aware of what can be done to safeguard against those threats.

Online security is like paying for insurance, or going to the dentist. It doesn’t seem that important, until it is. It’s not enough to simply opt-in to the forms of protection we’re offered by various sites and services. Knowing what kind of attacks these protections defend us from — and what they don’t — is the only way to take charge of your own security.


Google+ continues to sink with a second massive data breach. Abandon ship now

Google+ was scheduled to shut its doors in August 2019, but the second security breach in only a few months has caused the company to move its plan forward a few months. It might be a good idea to delete your account sooner than later.
Smart Home

Porch pirate problems? Keep them away with these tips and tricks

The holiday season is fast approaching and the packages are arriving on our doorsteps. Are you worried about porch pirates stealing your gifts this holiday season? Here are some tips to help protect your purchases.

These are the 5 best free antivirus apps to protect your MacBook

Malware protection is more important than ever, even if you eschew Windows in favor of Apple's desktop platform. Thankfully, protecting your machine is as easy as choosing from the best free antivirus apps for Mac suites.

How to change your Gmail password in just a few quick steps

Regularly updating your passwords is a good way to stay secure online, but each site and service has their own way of doing it. Here's a quick guide on how to change your Gmail password in a few short steps.

Leak reveals that Nvidia’s RTX 2060 gaming chipsets will be headed to laptops

The latest leaks of Nvidia's upcoming RTX 2060 have given performance benchmarks and further detail about the future chipset and its capabilities, while a RTX 2060 Max-Q variant has also been discovered for thin and light gaming machines.

Want to save a webpage as a PDF? Just follow these steps

Need to quickly save and share a webpage? The best way is to learn how to save a webpage as a PDF file, as they're fully featured and can handle images and text with ease. Here's how.

Supermicro investigation: no spy chips found on our motherboards

Supermicro announced the results of an investigation into the controversy surrounding its motherboards. The investigation was launched in response to reports that alleged the motherboards were compromised with malicious hardware.

New rumors say the Pixelbook 2 could show up at CES 2019

What will the Pixelbook 2 be like? Google hasn't announced it, but thanks to rumors and leaks, we think we have a pretty good idea of what the potential new flagship Chromebook will be like.

A dead pixel doesn't mean a dead display. Here's how to repair it

Dead pixel got you down? We don't blame you. Check out our guide on how to fix a dead pixel and save yourself that costly screen replacement or an unwanted trip to your local repair shop.

You could spend $1,000 on an iPhone, or buy one of these awesome laptops instead

Finding a decent laptop is easy, but finding one under $1,000 is a bit tricky. Luckily, we've taken some of the guesswork out of picking out a budget laptop. Here are some of our favorites, the best laptops under $1,000.

Don't know what to do with all your old DVDs? Here's how to convert them to MP4

Given today's rapid technological advancements, physical discs are quickly becoming a thing of the past. Check out our guide on how to convert a DVD to MP4, so you can ditch discs for digital files.

Here’s how to install Windows on a Chromebook

If you want to push the functionality of your new Chromebook to another level, and Linux isn't really your deal, you can try installing Windows on a Chromebook. Here's how to do so, just in case you're looking to nab some Windows-only…

We want every laptop to be as thin as an iPhone. But is it practical?

The Acer Swift 7 is the thinnest notebook you can buy, and it feels like the notebook of the future. But it makes too many compromises along the way, and some weird design choices hold it back.

Photographers can now customize the layout of Lightroom Classic controls

Tired of scrolling past Lightroom tools that you don't use? Adobe Lightroom Classic now allows users to reorganize the Develop panel. The update comes along with new sharing options in Lightroom CC, and updates to the mobile Lightroom app.