OT: Authenticator Apps on Windows Desktop

May 03, 2024 Last reply: 2 years ago 55 Replies

My sugery offers Patient Access. I have a password manager on my Win10 machine and when I log in I receive a code to my mobile.



Patient Access now seems to want to push people to install an Authenticator App.



Pros/Cons/Experiences would be helpful as I don't like IT complication as it too often goes wrong.



I personally prefer them, as they are less hassle than waiting for a text.

And it's possible (if they use the MS/Google app) to hack up stuff to authenticate yourself, if you are a nerd!

Do you need a different one for each website?

I prefer to use iOS built in authenticator.

The one time passcode will be auto filled when you signing in into website.

Some password managers can also generate a 2FA for you, if you can get the "secret" that seeds the code. Although 2FA is looking rather frayed, as passcodes are now being used by the big boys.

Good thing about a *decent* password manager is you can store notes aganst logins. Which is an ideal way to save the emergency codes that can be provided for offline access. Obviously for mission critical stuff a hardcopy of the codes is the final backstop.

Yes.

Generally they generate a "secret" from your email address and their URL and pipe it into a timed (30 seconds) algorithm. This is why it's essential to have your clock synced.

Somewhere I have a link

formatting link
that lets you create a QR code for an authenticator with custom parameters.

In my current role, I setup 2FA for all the key accounts and screenshot the QR code into a folder and hardcopy print which lives in the CEOs safe. If necessary any account should be recoverable in the event of an authenticator being out of commission for whatever reason.

Interestingly this was published today. Notice how it effectively deprecates 2FA

formatting link

On Fri, 03 May 2024 13:17:57 +0000, Jethro_uk wrote: <snip>

<snip>

This caught my eye.

Does this have any implications when you have multiple PCs you use for access to sensitive sites?

No reliance on using the same clock each time?

Not looked into this so far so a drive by question.

Cheers

Dave R

And what might one of them be?

Without reading into the spec in a detail I don't need to, I would educate a guess that as long as each devices clock produces the code expected for itself, that's enough. The timekeeping requirement is relative, not absolute.

That said not long ago, I was waiting for a new code to be generated as the existing one was only 4-5 seconds from expiring. A colleague said that even after a new code has been generated, the old one works "for a bit".

So there may be some float in the system to account for you getting a code at t+29s and it being entered at t+35s. It[s certainly something I would try to design in to avoid a deluge of help desk calls about the code "not working".

The registration and authentication codes are different for each website (that's the point), but you don't need a different app per website.

The common protocol is called TOTP and is supported by apps like Microsoft and Google Authenticator. But there are many other apps which also implement TOTP and you can use them interchangeably - and there are apps for desktop as well as mobile.

Some password managers include TOTP functionality which means the password manager can generate the TOTP codes as well as store your saved password.

That's usually the downside of 2FA: you need a good channel by which you can reset the account if you lose your authentication device. While this reset process can be a point of weakness, too many online companies just say 'sorry, you'll never have access to your account again' which is not good enough when people lose codes for a variety of good reasons.

Theo

Amazon, Google, MS, AWS, Zoho, all allow (in some cases "require") the generation of codes for offline use. These are device independent.

I gave up dealing with a lot of very dim people about 5 years ago whose sole reason for not signing up to 2FA was "what if I can't get a signal ?". Which in many cases is really an invented excuse (see also the bus queue vs. single person choice for autonomous cars) that has never ever happened. Certainly not to them.

The only reason I got a mobile fone with wifi calling was that where was living HAD NO SIGNAL. None. Nada. No DTB TV either.

And I needed to receive SMS texts

Oh I don't doubt there are *some* people that have experienced no signal. I did use to caravan.

However, it wasn't the people who worried about it that experienced it. Another instance of worrying on someone elses behalf.

I worried about it enough to get a mobile I didn't otherwise want.

Somehow I now feel less comforted after reading the comments.

I know security is an increasingly important issue, I just worry about the robustness of the whole system and the inflexibility of getting through to any suppport when something fails.

One might be WinAuth but others may be available :)

formatting link

What I find annoying is web sites that require ridiculous levels of security that are quite unnecessary.

I really, really, don't care if argos.co.uk knows my name and address, the whole world knows my name and address. So why do I have to jump through hoops and have an ultra-secure password to buy something from Argos?

Much more important is whether I leave my credit card details with them, no chance - except that I doubt if **their** security is good enough to be sure that my details have been deleted.

Ah, you're talking about a software PINSentry, is that it? Why can't I just use my PINSentry?

No, PINsentry is what Barclays call the card authentication system, generally known as EMV CAP. That's where you put your card in a reader and use your PIN (you can use any EMV CAP reader for that, doesn't have to be Barclays' branded one)

PatientAccess is using TOTP which doesn't use cards, only software. (although there are many implementations, so you can use an implementation with a physical token if you choose to)

Theo

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required