fa

farMFA – Generate TOTP Codes via Shamir's Secret Sharing

Hacker News

farMFA – Generate TOTP Codes via Shamir's Secret Sharing

It's kind of half-baked but the core idea works, so I thought it was time to get some external feedback before I continue with the yak shaving! I started this a while ago, basically the problem we had back then was how to store credentials to access the root user of the management account of an AWS Organization. (This is applicable to anything using TOTP though, not just AWS) The username and password would go in the team password manager, but what about MFA? For those not familiar with AWS, this is the most powerful super user you can have there. It's irrelevant to explain how bad it is if this is compromised; but the thing is even a clueless, good faith user can screw up badly if they use it incorrectly. So it's really, really important that it is secure. With other credentials, we had hardware tokens in a safe, or a printed TOTP QR code also in the safe. I think this is a good, high friction process in normal times. But, we were in full pandemic mode back then, and the team was distributed across the country. That was a bit too high friction... Eventually, we decided to use TOTP as second authentication factor. We set it up during a screen sharing session, and 2 or 3 of our team just added the secret to our personal phones. Now, the few of us would know what to do in a break-glass scenario, and clueless good faith users from above, randomly stumbling upon the AWS credentials in the shared password manager, would not be able to use the username and password alone. This is when I came up with the idea for farMFA - what if, instead of each of us having the full TOTP secret - would only have a "share" of it? With enough shares (n out of m), one could then temporarily reconstruct the TOTP secret, get the current time, generate a code, and complete the authentication process. Vault uses this concept[^1] (and in fact, I used their Shamir's Secret Sharing implementation for this) to initiate the "unsealing" process. The master encryption key is split across multiple users: when the server comes up, at least some of those users (the exact number is configurable) must provide their share to reconstruct the key, and allow decrypting the vault in memory. An attacker with access to the physical storage would then be unable to retrieve the decryption key. Here, we do the same with the TOTP secret (the QR code, basically), splitting it across multiple users. When somebody needs access, they ask everyone else to submit their share to a server, which will then generate and return the TOTP code for a limited amount of time. [^1]: https://developer.hashicorp.com/vault/docs/concepts/seal#sha...

Share card

Actual performance

2points
Did not reach leaderboard

Launch Intel predictions

Analyze your own launch →
Indie HackersFits the IH revenue-focused audience · Strong signals: started · Missing: supports, reddit linkedin, podcasting
91%91% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Product HuntOn track for Day 1 leaderboard · Strong signals: user, physical, using · Missing: mac, agents, macos
78%78% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
Hacker NewsMay not resonate with HN audience · Strong signals: ide, io · Missing: https docs, excited, just released
46%46% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
AppSumoMay struggle as an AppSumo deal · Strong signals: users · Missing: plus, platform, intuitive
46%46% predicted probability of success on AppSumo, based on ML models trained on real launch data.
TrustMRRLess likely to generate early MRR · Strong signals: personal, users · Missing: mobile apps, ios, entrepreneurs
33%33% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
12%12% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Missing: web3, chat, crypto
0%0% predicted probability of success on BetaList, based on ML models trained on real launch data.

Correct prediction on native model

Similar products

SH
SHOW HN: Secret sharing in the browser57%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

SHOW HN: Secret sharing in the browser

Hacker News2
Di
DiceSlice – Secret Sharing in the Browser62%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

DiceSlice – Secret Sharing in the Browser

Hacker News1
Mu
Multipass, secret sharing for teams55%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Multipass, secret sharing for teams

Hacker News2
CL
CLI App for Shamir's Secret Sharing40%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

CLI App for Shamir's Secret Sharing

Hacker News4
Ho
Horcrux, a Playground for Shamir Secret Sharing54%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Horcrux, a Playground for Shamir Secret Sharing

Hacker News151
Sh
Shamir Secret Sharing in Java 11+36%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Shamir Secret Sharing in Java 11+

Hacker News3
Sh
Shamir Secret Sharing TypeScript Implementation42%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Shamir Secret Sharing TypeScript Implementation

Hacker News1
Se
Secret combinations of the CCP and other threats to democracy49%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Secret combinations of the CCP and other threats to democracy

Hacker News2
Se
Secret Sauce to Get Funds58%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Secret Sauce to Get Funds

Hacker News1
Remolo
Remolo48%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Secret :)

Indie Hackerscommitment-side-project