2FA, WTF? at Rails Remote 2016

8ec1383b240b5ba15ffb9743fceb3c0e?s=47 Phil Nash
October 13, 2016

2FA, WTF? at Rails Remote 2016

Everyone is hacking everything. Everything is vulnerable. Your site, your users, even you. Are you worried about this? You should be! Don't worry, Phil is not trying to scare you (that much). You have plenty of safeguards against attempts on your applications' user data. We all (hopefully) recognise Two Factor Auth as one of those safeguards, but what actually goes on under the hood of 2FA?

You will discover how to generate one-time passwords and implement 2FA in your applications, and hear the only real-life compelling use case for QR codes. Together, we'll make the web a more secure place.



rotp package: https://github.com/mdp/rotp

Authy: https://www.authy.com/developers/

Tutorial on implementing Authy in Rails 4: https://www.twilio.com/blog/2016/01/two-factor-authentication-in-rails-4-with-devise-authy-and-puppies.html

Authy OneTouch: https://www.authy.com/product/options/#onetouch

Top passwords 2015: https://www.teamsid.com/worst-passwords-2015/
Ashley Madison passwords: http://cynosureprime.blogspot.ie/2015/09/how-we-cracked-millions-of-ashley.html
Have I Been Pwned? - https://haveibeenpwned.com/


Phil Nash

October 13, 2016