Currently the tfa system doesn't protect against one-time-use of all the tokens. A recovery code or sms code provided by tfa_basic are immediately used and cannot be re-used, but the TOTP code can be re-used inside of the interval (defaulted to 90 seconds).

If an attacker is able to sniff the traffic of a victim they can get username/password and the TOTP code which they can then re-use.

The README and perhaps project page should encourage the use of https/ssl and hsts to reliably encrypt traffic and reduce the likelihood of sniffing credentials or a one-time-use code.

Comments

banviktor’s picture

In the meantime #2329867: Prevent the re-use of TOTP codes got committed, so TOTP reuse is not possible.
However encouraging SSL is always a good thing (see #2548483: Option to require SSL connection to show Recovery codes, or insist on sending them through email instead) so we might still want to do this.
Thoughts?

cmlara’s picture

Version: 7.x-2.x-dev » 2.x-dev

In preparation for D7 EOL in a couple days moving this to 2.x branch.

While using SSL should be 'common knowledge' for anyone deploying MFA I could see room for it to be included somewhere in the documentation. Possibly under the Install Hardening section? (Maybe rename to "Deployment Hardening" to be more agnostic to setup itself?). Could also be a good option to create a "Security Considerations" as I could see us desiring to document the DB storage and multi-environment related concerns.