Live data from Hacker News

Adding a security key to Gmail

techsolidarity.org

1–10 of 126 posts

Re: Adding a security key to Gmail

#3
Thanks for writing this!

One nitpick: the guide says "If you're curious why it's important to not have a phone number on your account, see the security key FAQ", but the linked security FAQ doesn't actually appear to say why it's important.

Re: Adding a security key to Gmail

#4
post #3

Thanks for writing this! One nitpick: the guide says "If you're curious why it's important to not have a phone number on your account, see the security key FAQ", but the linked security FAQ doesn't actually appear to say why it's important.

Sorry about that, I'm updating that FAQ next.

The answer is that SMS is not a secure second factor (it's easy to hijack and eavesdrop on), and in some cases when you give a service a phone number, it becomes possible to take over the account with just control of the phone number.

Re: Adding a security key to Gmail

#5
The HyperFIDO Mini (U2F Security Key) is the cheapest and smallest key I've found so far for $10. (Amazon)

The Yubico are probably the best key chain candidate. No one wants to trust their key to a weak nylon thread.

You can also set up a Google account to use more than one U2F key.

As for Google 2FA, I think Google caused a lot of confusion by how they set up the Google Authenticator app. Always opt for the text generator codes instead of a barcode. You can then use the code to use on a second Google Authenticator app on another device. Google at one time stated that you could only set up 2FA on a single device, which makes most users leary as one could lose his or her phone.

Re: Adding a security key to Gmail

#7

The HyperFIDO Mini (U2F Security Key) is the cheapest and smallest key I've found so far for $10. (Amazon) The Yubico are probably the best key chain candidate. No one wants to trust their key to a weak nylon thread. You can also set up a Google account to use more than one U2F key. As for Google 2FA, I think Google caused a lot of confusion by how they set up the Google Authenticator app. Always opt for the text gen…

There's noting stopping you from scanning the barcode multiple times

Re: Adding a security key to Gmail

#8

The HyperFIDO Mini (U2F Security Key) is the cheapest and smallest key I've found so far for $10. (Amazon) The Yubico are probably the best key chain candidate. No one wants to trust their key to a weak nylon thread. You can also set up a Google account to use more than one U2F key. As for Google 2FA, I think Google caused a lot of confusion by how they set up the Google Authenticator app. Always opt for the text gen…

There's noting stopping you from scanning the barcode multiple times

Didn't it change the web page on your computer browser after you successfully added it into Google Authenticator?

I suppose you could always take a photo of the QR code and then rescan that. Text seems simpler.

edit: Anyone else remember this behavior? Old version? Browser specific?

Re: Adding a security key to Gmail

#9
The article says that any key will do. Is there any concern with buying a less expensive security key from a less established company, or even a third party seller on a site like Amazon? Could a malicious entity make an intentionally weak security key and sell it? How would such an attack be detectable?
Post reply on HN