Live data from Hacker News

Make Your Email Hacker Proof

codinghorror.com

101–110 of 161 posts

Re: Make Your Email Hacker Proof

#102
post #4

What I really want is for the second factor to kick on only in suspicious situations, e.g.: * I'm logging in from a computer that I've never logged in from before * I'm searching my mail history for terms like "password" * I'm opening an email that appears to contain a password-reset link * I'm messing with my mail-forwarding options * I'm accessing messages in bulk But I do not want to have to do second factor just…

Since you're at Google, I hope you've been able to suggest this to gmail team. Even better if it's being worked on, especially the first item.

Re: Make Your Email Hacker Proof

#103
post #78

Earlier quoted context omitted.

A _startlingly_ large number of people are (still) re-using passwords across multiple sites. The Gawker/Sony(/PerlMonks for me) compromises revealed a _lot_ of email addresses and passwords, some significant portion of which almost certainly allowed attackers access not only to the specific website that was attacked, but also to the email service of the exposed user. I'm pretty sure none of Jeff's advice helps you ag…

My name is Alan Byrne, I work in IT and I'm a password re-user :( On that note, does anyone know of a secure keysafe app that will sync across my various PCs, iPad and Android phone? This is what is stopping me from going the single use password route.

I use Keepass (or KeepassX, or KeepassDroid, and there's an iOS app too) and Dropbox.

Re: Make Your Email Hacker Proof

#105
post #101

dropbox really needs this too. although my information on that account is not nearly as sensitive as on gmail, i'm sure it will amount to a similar sensitivity in the future.

Indeed, anytime I login a a mental note pops up saying how insecure this is considering the files stored on Dropbox. Yesterday I received a phonecall from a friend whose Gmail and Facebook were hacked, after I had advised her to use 2-factor authentication and she ignored it. So glad that I do use it but now Dropbox remains the weakest link.

Re: Make Your Email Hacker Proof

#106

For now I have a really long email password, but I'm considering moving my sensitive data/email out of my general email account and into a new email address that requires 2 factor authentication. The thing I really want is a "lockbox" folder in my general email that: 1. Requires 2 factor authentication to access the folder but not my general inbox 2. I can move messages I consider sensitive from my general inbox to t…

Wow, this would be an excellent feature. Although I've got 2 factor authentication set up for my whole account and it doesn't really bother me, I would like to see something like this. An extra measure to protect certain emails would be really helpful.

Re: Make Your Email Hacker Proof

#107
I’ve enabled and stayed with 2-factor auth on my Google account, but it broke my Google Talk login on Adium and I’ve never found anyone to talk to about it (bug report on Adium went unnoticed and Google got rid of bug reporting for Google Talk). Hopefully a burst of attention will throw up some other people with the same problem.

Re: Make Your Email Hacker Proof

#108
post #54

(You can check the "remember me for 30 days on this device" checkbox so you don't have to do this every time.) No thanks. Google remembers a lot more than "this device," more like everything I do within that device thanks Search cookies, Adsense, Analytics on millions of sites and who knows what else

I always have my gmail logged-in in a separate browser and I don't use that for any other browsing.

I use this method also

Re: Make Your Email Hacker Proof

#109
post #2

What happens when you travel abroad and your phone does not work? I am wondering if Gmail could implement security questions to avoid cases where the 2-step verification works against the user

That's exactly what I've been wondering about enabling two factor authentication for something I use as often as email. Apparently you can print a series of one-time use verification codes that work any time to sign into your two-factor account. Stick a few on a card in your wallet and don't forget to generate more before you're out! https://support.google.com/accounts/bin/answer.py?hl=en&...

When you do run out of verification codes, but you do have a working phone the 6 digit codes can also be sent to you through text messages or even a phone call from Gmail.

Re: Make Your Email Hacker Proof

#110
post #99

Earlier quoted context omitted.

Do you really think your shared host drops blocks when you delete them from your virtual disk, and do you really think that requests to mlock memory with crypto keys are really honored? Maybe if you have a dedicated box, but not if you are using a virutal host. (Have you ever physically seen "your own" mail server? If not, why do you trust it?) Also consider what happens to unencrypted email you send or receive: any…

Yow! The ONLY secure server for TOTAL EMAIL SAFETY is an obsolete LAPTOP running in your mother's LIVING ROOM! (Not kidding, I really do that.)

My mother spills too much wine for that to be totally safe...
Post reply on HN