One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…
>> I'm surprised the cut-throat world of registrars don't compete on this. How many people go looking for that though? For most people my guess is people go shopping for CHEAP first, EASY second, maybe LOOKS GOOD third, and some where down that list is "much more secure". I hate to say, I rarely go looking for the more secure option of anything.
Two-factor authentication is a mess
21–30 of 112 posts
Re: Two-factor authentication is a mess
#22One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…
this is something that my bank is testing on its users now, whether I need to confirm the transaction or cancel my automatic deposit prolongation it asks me to make a photo and send it to them for confirmation, which takes them in average 5-10 minutes. Though it is not a ver comfortable way for an end-customer, I guess some kind of biometric authentication/confirmation will take place as soon as a user will tolerate…
Hopefully our concept of authentication doesn't slip down the slope so far that we start allowing biometrics for it.
Re: Two-factor authentication is a mess
#23One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…
Re: Two-factor authentication is a mess
#24> Avoid: SMS has been at the center of a lot of two-factor hacks, most recently as a way to hijack Telegram accounts in Iran. High-security accounts are already moving away from it, but a frightening number of services still keep it as an option, giving anyone who compromises your carrier account an easy way in. I feel like this is badly phrased. SMS 2FA is far worse than other types, but still better than no 2FA.
I think SMS 2FA is worse than no 2FA, given that you can often reset a password using SMS as verification. If your phone number is hijacked, you're owned completely. Without SMS 2FA, you have to reset your password via email, or resort to contacting the company directly.
Re: Two-factor authentication is a mess
#25One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…
physical mail is not secure by _any_ stretch of the imagination
Re: Two-factor authentication is a mess
#26Earlier quoted context omitted.
I think SMS 2FA is worse than no 2FA, given that you can often reset a password using SMS as verification. If your phone number is hijacked, you're owned completely. Without SMS 2FA, you have to reset your password via email, or resort to contacting the company directly.
If you can reset your password with it, it's not a second factor. It's just a different factor.
Requiring a physical, government-issued ID to be presented at an office can work for some scenarios, but not for the vast majority of online services.
Re: Two-factor authentication is a mess
#27https://medium.com/@joelrunyon/instagrams-security-features-...
Re: Two-factor authentication is a mess
#28I'm still amazed by how many websites still use this "security question" mechanism. It's almost always the same questions too, "what's your mother's maiden name", "what's your childhood's pet name" etc... It's so easy to get the answers to these questions through the tiniest bit of social engineering, or even just exploring their facebook profiles.
It's crazy how many websites manage to handle auth credentials incredibly poorly, it ought to be a solved problem by now. Last week I created an account on https://www.comedie-francaise.fr/, it used javascript to prevent me from pasting the password in the field (very convenient when you use a password manager, I had tweak the source to remove the limitation). Now that's pretty silly, but what's even sillier is that they then emailed me a password "reminder" in plaintext!
So when so many websites can't seem to handle regular user+password login properly, it's not surprising that 2FA ends up being a huge mess.
Re: Two-factor authentication is a mess
#29I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an eight digit number I have to provide when making any changes. Better than nothing, but something tells me their CS people would still cave too easily to social engineering.
Re: Two-factor authentication is a mess
#30It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…