Earlier quoted context omitted.
FWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point. Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("…
Googles 2fa requires the user to give google his phone number before being able to add a totp authenticatior. That alone is reason for me to never use it for my google account. The popup also doesn't come up if you haven't signed up with google on your phone, obviously. There is nothing stopping them from just allowing anyone to add a normal totp 2fa generator, they just chose to not do that to get more of that sweet…
Less secure apps and your Google Account
241–250 of 272 posts
Re: Less secure apps and your Google Account
#242Earlier quoted context omitted.
FWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point. Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("…
> You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. I have two different concerns. The first is that I frequently end up having to clear my browser cookies, for a variety of reasons. Every time I do, I have to redo the 2FA dance, on every single website that requires 2FA. I suppose I could find a different cookie management…
Re: Less secure apps and your Google Account
#243Earlier quoted context omitted.
Shameless plug: move to inbox.eu. We have migration tool to move away from gmail. We use separate auto-generated IMAP password for more secure access via standard IMAP protocol. Auto-generated passwords by our experience are secure and we haven't have problems with account hacking via them
If the passwords are being used by some automated service this is probably fine, at least modulo the quality of the service implementation. If they're for actual humans, even in the best case you're vulnerable to phishing, also you are a perpetual risk because you know these passwords (or a password equivalent) so an adversary might steal your passwords (e.g. from a backup, logs, test systems, ...) and now they can i…
Re: Less secure apps and your Google Account
#244Earlier quoted context omitted.
FWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point. Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("…
> You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. I have two different concerns. The first is that I frequently end up having to clear my browser cookies, for a variety of reasons. Every time I do, I have to redo the 2FA dance, on every single website that requires 2FA. I suppose I could find a different cookie management…
To my knowledge, you can use as 2FA w/Google:
1. A prompt on your phone
2. A hardware security key
3. TOTP token from authenticator
4. one of 10 backup codes
And you can also have multiple security keys as well, which is useful if you lose one.
Re: Less secure apps and your Google Account
#245Earlier quoted context omitted.
> You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. I have two different concerns. The first is that I frequently end up having to clear my browser cookies, for a variety of reasons. Every time I do, I have to redo the 2FA dance, on every single website that requires 2FA. I suppose I could find a different cookie management…
Have you thought about multiple 2FA devices? To my knowledge, you can use as 2FA w/Google: 1. A prompt on your phone 2. A hardware security key 3. TOTP token from authenticator 4. one of 10 backup codes And you can also have multiple security keys as well, which is useful if you lose one.
I could use my password manager (Bitwarden) as my TOTP generator, and I may eventually do that just to make all of these services shut up. But, wouldn't that leave my account no more secure than it already is today? It would effectively be single-factor authentication, since the password and the generator would be in the same place, protected by the same master password.
Re: Less secure apps and your Google Account
#246I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…
Re: Less secure apps and your Google Account
#247Re: Less secure apps and your Google Account
#248The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself
github.com/bjesus/oauth-hopper/
Re: Less secure apps and your Google Account
#249Earlier quoted context omitted.
Ebay supports WebAuthn, does PayPal not?
If it does, that's be great, as I do have a PayPal account to solve a problem I had with one payment platform, but when I last looked it only offered TOTP
Re: Less secure apps and your Google Account
#250Google "engineering" excuse everytime is it is for your safety