Live data from Hacker News

Your Android Phone Is a Security Key

blog.google

41–50 of 144 posts

Re: Your Android Phone Is a Security Key

#41
post #30

Off topic: This is the state of web we are in, and this is coming from Google. [1] I have literally 20% of the screen displaying useful information. The others are all useless navigation or related crap. Just seeing it nearly got me to puke. It is one those problem in general where the web page is responsive and mobile first. [1] https://ibb.co/fCfmW6h

I see this: https://ibb.co/ZJQ7Z2h

The extra wide padding on the sides is still wasteful, but it is not as bad as your experience.

However, none of the javascript on the page is executed, because I also run NoScript in default deny mode, and for the screen shot, all the JS is blocked. It looks like the javascript is partially responsible for part of the extra you are seeing.

Yes, testing with javascript allowed, it is the javascript that is adding the fixed top and bottom banners to the page.

Re: Your Android Phone Is a Security Key

#42
post #30

Off topic: This is the state of web we are in, and this is coming from Google. [1] I have literally 20% of the screen displaying useful information. The others are all useless navigation or related crap. Just seeing it nearly got me to puke. It is one those problem in general where the web page is responsive and mobile first. [1] https://ibb.co/fCfmW6h

Sticky elements that follow you around while scrolling a web page should be banned like the blink tag. Especially in a mobile browser.

I know where the navigation bar is, if I want to use it, I'll scroll back up and touch something on it. If I want to read related articles, I'll scroll down past your piece, which is where that kind of nonsense always is.

But it gets better: you know what's almost always sticky? Those hideous share/"post this to a social networking site" badges! As shown in that screenshot, even Google can't resist that one!

Why are you covering my viewport with everything but the content you want me to read? Are you trying to make me leave? You know I only have so many pixels on my five inch mobile screen, right??

Re: Your Android Phone Is a Security Key

#44
post #30

Off topic: This is the state of web we are in, and this is coming from Google. [1] I have literally 20% of the screen displaying useful information. The others are all useless navigation or related crap. Just seeing it nearly got me to puke. It is one those problem in general where the web page is responsive and mobile first. [1] https://ibb.co/fCfmW6h

Looks like you're zoomed in or have a larger default font size, so it's not fair to say this is the state of the web

But looking at a web page nearly made his body vomit!

Re: Your Android Phone Is a Security Key

#45
post #19

I like the idea behind it in principle, since it will simplify 2FA for the masses and may lead more people to adopt it. But, apart from that: 1. It's only on Chrome (for now(?)) 2. It's only for Google products (for now (?)) 3. It's only on Android that Google fully controls remotely (and probably it will stay there). All these give even more power to Google at the expense of convenience and allows a single company t…

The problem isn't even Google, it's just lack of actual support for services that need it. You have to have the right client, the right device, and every website has to implement it. Government websites won't support it, nor most financial services, your gym, school, job, etc. Sensitive records like your SSN will be kept in walled gardens accessible by a simple user and password, and maybe a security question. Most p…

Well, that depends where you live. Google is available for everyone, not just technologically-backward places.

Here millions are currently checking their pre-filled tax returns, which they have accessed using smartcard authentication, so Gmail ain't that far ahead.

Re: Your Android Phone Is a Security Key

#46

Can someone explain how TFA (or any security feature that relies on my phone) works when the phone is unresponsive -- dead battery, no cell or internet reception, hardware failure.

I am interested in how frequent travelers manage these security measures (especially abroad). For SMS: quickly obtain a burner phone, log in to Chrome, something something SMS or Authenticator? For Authenticator: log in to Chrome on any machine you can locate that you can trust? For the printed backup codes, you carry them with you as you travel, and through security? I am trying to develop a security process that I…

When possible, I completely avoid services that use SMS 2FA. If given the option, I always opt for authenticator apps or codes-via-email 2FA, in that order. I use SMS 2FA so infrequently that I've never encountered a situation where I needed to get a code SMSed to me while abroad.

I store my printed backup codes for most of my services in an encrypted file in my Dropbox (encrypted with a different password than the password used for Dropbox).

I then also have printed backup codes for my primary email account and for my Dropbox account that I carry with me on an unmarked piece of paper stashed deep in a semi-hidden pocket in one of my bags. I also have printed backup codes for my email and Dropbox stashed in a semi-hidden place in my home, with the thought that in a last case scenario (or I lose my bags or something like that), I can phone my roommate and have him read me the code.

It isn't perfect and I feel like it could be improved, but so far it works fine.

Re: Your Android Phone Is a Security Key

#47
post #22

> Now, you have one more option—and it’s already in your pocket. Starting today in beta, your phone can be your security key—it’s built into devices running Android 7.0+. You know, it's nice they phrase this as an "option", but in my experience Google has the habit of forcing me to have my phone on me when I login from a new location / new device, something I never asked for and apparently cannot disable.[0] This has…

Google has always given me other options, does it really enforce having a phone now?

Re: Your Android Phone Is a Security Key

#48
post #19

I like the idea behind it in principle, since it will simplify 2FA for the masses and may lead more people to adopt it. But, apart from that: 1. It's only on Chrome (for now(?)) 2. It's only for Google products (for now (?)) 3. It's only on Android that Google fully controls remotely (and probably it will stay there). All these give even more power to Google at the expense of convenience and allows a single company t…

This is 2FA for Google accounts so of course it's on Google products?

Re: Your Android Phone Is a Security Key

#49
post #22

> Now, you have one more option—and it’s already in your pocket. Starting today in beta, your phone can be your security key—it’s built into devices running Android 7.0+. You know, it's nice they phrase this as an "option", but in my experience Google has the habit of forcing me to have my phone on me when I login from a new location / new device, something I never asked for and apparently cannot disable.[0] This has…

Google has always given me other options, does it really enforce having a phone now?

I don't know how they determine what options to offer, but using my phone was the only one given, despite entering a correct password. The only other option, which I either found from the "Learn more" link or after exhausting the "login with your phone" attempts, was to create a support ticket for my G-suite account which, in this case, would have been slower than returning to home a few hours later where I had left my phone.
Post reply on HN