Live data from Hacker News

Adding a security key to Gmail

techsolidarity.org

11–20 of 126 posts

Re: Adding a security key to Gmail

#11

Earlier quoted context omitted.

There's noting stopping you from scanning the barcode multiple times

Didn't it change the web page on your computer browser after you successfully added it into Google Authenticator? I suppose you could always take a photo of the QR code and then rescan that. Text seems simpler. edit: Anyone else remember this behavior? Old version? Browser specific?

It changes when you input current code. You can scan it multiple times, print it, and then input the code from one of your devices.

Re: Adding a security key to Gmail

#12

Is there any point in doing this if you do not use Chrome?

Only Chrome supports U2F. Firefox has experimental support of you enable special flags in about:config but I never got it to work.

U2F will be superseded by Web Authentication [0] that includes U2F and will be supported by all major browsers. Edge includes draft spec API that uses TPM to store keys.

[0]: https://w3c.github.io/webauthn/

Re: Adding a security key to Gmail

#13

The HyperFIDO Mini (U2F Security Key) is the cheapest and smallest key I've found so far for $10. (Amazon) The Yubico are probably the best key chain candidate. No one wants to trust their key to a weak nylon thread. You can also set up a Google account to use more than one U2F key. As for Google 2FA, I think Google caused a lot of confusion by how they set up the Google Authenticator app. Always opt for the text gen…

Remember to add at least two U2F keys. It's easy to lock yourself out in case the only one or lost / broken.

Re: Adding a security key to Gmail

#14
I'd like some advice about safely accessing gmail from your phone.

In particular an android phone that might not have the latest version of android on it.

Also for situations where not only do you access your gmail from your phone but also your google authenticator app is installed on it.

Re: Adding a security key to Gmail

#15
post #12

Is there any point in doing this if you do not use Chrome?

Only Chrome supports U2F. Firefox has experimental support of you enable special flags in about:config but I never got it to work. U2F will be superseded by Web Authentication [0] that includes U2F and will be supported by all major browsers. Edge includes draft spec API that uses TPM to store keys. [0]: https://w3c.github.io/webauthn/

You can use U2F in firefox with extension. Last time I tried it worked. However I use chrome most of the time so I am not sure if it still does.

https://addons.mozilla.org/en-Us/firefox/addon/u2f-support-a...

Re: Adding a security key to Gmail

#17
post #14

I'd like some advice about safely accessing gmail from your phone. In particular an android phone that might not have the latest version of android on it. Also for situations where not only do you access your gmail from your phone but also your google authenticator app is installed on it.

The recommended way are app passwords. You basically generate a password for each app that needs to access your mail account. You can easily revoke access for a single app in case something goes wrong. Also, nobody gets the chance to read your actual password.

Re: Adding a security key to Gmail

#18
post #14

I'd like some advice about safely accessing gmail from your phone. In particular an android phone that might not have the latest version of android on it. Also for situations where not only do you access your gmail from your phone but also your google authenticator app is installed on it.

Upvoted because I would love an answer to this as well. An associate in the phone-cracking hobby has mentioned to me that _no_ Android phone is malware-free. They have cracks and methods for phones and OS versions that have yet to hit the market. I've understood from him that the only "secure" device is the iPhone, and even that is not secure from targeted (government) attacks.

That said, I personally would never own an iPhone and I'm happily bliss on my Note 3 with Android 4.4. But I don't access my mail, bank, or anything else sensitive on the device. For me it is no more than a phone, camera, and Anki interface!

Re: Adding a security key to Gmail

#19
post #3

Thanks for writing this! One nitpick: the guide says "If you're curious why it's important to not have a phone number on your account, see the security key FAQ", but the linked security FAQ doesn't actually appear to say why it's important.

Because it can be a way to compromise your account[0]. HN discussion[1]:

[0]: https://blog.coinbase.com/on-phone-numbers-and-identity-423d...

[1]: https://news.ycombinator.com/item?id=12597609

Re: Adding a security key to Gmail

#20
post #16

Bought a U2F Yubikey more than a year ago. It is pretty sturdy. Better buy two and use one as a backup. U2F is really convenient to use. Compare that to all the OTP apps out there.

My Yubikey recently died, so I'd +1 on this approach to have another as backup. They offered to replace it under warranty, though.
Post reply on HN