aislop.day
TUESDAY, 10 MAY 2022

Terms Governing Two Factor Interruption

The OTP expires in thirty seconds. The phone was in another room.

3 MIN READonline fatigue

FIELD GUIDE Subject: Managing Two-Factor Authentication Interruption Events. Audience: Anyone with accounts.


What This Guide Covers

This guide covers the operational reality of two-factor authentication as experienced by the person it is supposed to protect. The security benefits are real and are not in dispute. This guide concerns what happens between the initiation of a login and the successful completion of it.

Phase One: Initiation

The login is begun on one device. The login requires a one-time password to be sent to a second device. The second device is not in the same room as the first device.

This situation occurs in approximately sixty percent of two-factor authentication attempts. The phone is in the other room. It is on charge. It is face-down. It is in a bag. It is somewhere specific that the user knows and can reach in under ninety seconds, which is the time available before the OTP expires.

The one-time password is a test of spatial proximity dressed as a security protocol.

Phase Two: Retrieval

The user proceeds to the second device. Optimal conditions: the second device is within eight meters, unlocked or biometric-accessible, and the notification is visible on the screen. In optimal conditions, the OTP is retrieved in under fifteen seconds.

Non-optimal conditions occur more frequently than optimal conditions.

Non-optimal condition A: the phone is locked. The biometric unlock requires the thumb that the user is currently not pointing at the sensor because the user is holding the device at an angle designed for reading, not unlocking.

Non-optimal condition B: the notification has been dismissed. The SMS app must be opened. The correct thread must be located among threads that have not been cleared since November.

Non-optimal condition C: the thirty-second window has expired. The OTP is now a six-digit code attached to a moment that no longer exists.

Phase Three: Expiration

Return to phase one. Request a new code.

The security system is protecting the account from the account holder with approximately the same frequency as it protects the account from unauthorized actors. This is noted in the security literature under the term "friction." The friction is a feature.

Consequence Map

First consequence: the user now keeps the phone on the same desk as the laptop during any activity likely to require a login. This is a behavioral adaptation to a security protocol. The security protocol caused a lifestyle change.

Second consequence: authenticator apps exist and eliminate this problem entirely. They require setup. The setup has been meaning to happen for a while.

Third consequence: some accounts now have "remember this device for thirty days" enabled, which reduces the occurrence of two-factor events and therefore reduces the security feature's frequency of operation. Both things are true simultaneously.

Governing Rule

The OTP countdown begins the moment the SMS is sent, not the moment the user reads it. These are different moments. The gap is the field guide's subject.

Contradiction

The device receiving the OTP is the phone. Logging into the phone's own applications requires the phone to send a code to itself. The phone sends it. The phone receives it. The phone is in one room.

Guide current as of Q2 2022. Setup of authenticator app still pending.

TAGSonline fatigue
Share this