Live data from Hacker News

Make Your Email Hacker Proof

codinghorror.com

11–20 of 161 posts

Re: Make Your Email Hacker Proof

#12
"You should start thinking of security for your email as roughly equivalent to the sort of security you'd want on your bank account. It's exceedingly close to that in practice."

Actually, I want (and arguably already have) better than that. In the last 4 months I have had two unauthorized debits from my bank accounts: one a result of a mail thief stealing my rent check from my mailbox, the other an error made by a bank employee. In the 15 years I've been using email I've never knowingly had any of my email accounts hacked.

Re: Make Your Email Hacker Proof

#14
post #2

What happens when you travel abroad and your phone does not work? I am wondering if Gmail could implement security questions to avoid cases where the 2-step verification works against the user

That's exactly what I've been wondering about enabling two factor authentication for something I use as often as email.

Apparently you can print a series of one-time use verification codes that work any time to sign into your two-factor account. Stick a few on a card in your wallet and don't forget to generate more before you're out!

https://support.google.com/accounts/bin/answer.py?hl=en&...

Re: Make Your Email Hacker Proof

#18
post #5

What happens for IMAP accounts? e.g through Mail.app or Thunderbird?

It's in the article, but basically you just generate app-specific passwords for each one, which you can revoke at any time.

The sucky part is that nothing enforces their app-specificness. It would be neat if I could generate a password that only works from my home connection. Or only works for GChat, but not other services.

Re: Make Your Email Hacker Proof

#19
post #8

> Hey, This Sounds Like a Pain! Yes, because it is a pain. Try going on a vacation, you know the one where you don't use cell roaming. SMS is out, so then one must find a Wifi hotspot to use one of the smartphone time based tokens (edit: seems the token don't need a network connection, could have fooled me). And those time based tokens go out of wack if your phone didn't sync the timezone properly to match Google's s…

When you reach a point where you have, say, half of your backup verification codes remaining and for some reason your timezone is that far out of sync that Google Authenticator no longer works (and for some reason you can't just sync your clock), then simply generated new backup verification codes and print those out. It seems like a pretty weird assumption that your clock will go out of sync and you won't be able to even manually sync. If you can get online to reach a Google login page, why can't you get within 30 seconds of the correct time for Google Authenticator to work?
Post reply on HN