Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

11–20 of 262 posts

Re: Please turn on two-factor authentication

#11

Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."

You can run the Authenticator app on an iPod.

But 2-factor does mean there in an expectation you will have to carry some kind of token device.

Re: Please turn on two-factor authentication

#12

I really hope other services start offering it as a feature. Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector. Also, RE the Google one time use passwords for POP/IMAP. They are all lower case, alpha/numeric, and 8 chars long. How secure are they against brute force? Why wouldn't Google offer 16 char options, or even longer? Is 8 good enough?

> Is 8 good enough?

Depends on how good their intrusion detection is.

Re: Please turn on two-factor authentication

#13

Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."

Buy a cheap used phone and a prepaid card, you should be able to get by just "recharging" 20$ of credit every 6 months or so.

Re: Please turn on two-factor authentication

#14
post #8

Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."

Yes you are, and I suspect you know this. Even in most third world countries cell-phones are common.

Still, if I plan to use Google Authenticator, I don't want to give Google my phone number at all. When they insist to get the phone number from me, I don't like it.

Re: Please turn on two-factor authentication

#15
post #6

I did this a few months ago, but I'm thinking of turning it off. I know it's trivial, but there's something deeply annoying about being dinged $0.20 a pop for the SMS message to get the code. I'll have to see if I can set up the Google Authenticator; I hadn't heard of that before.

Even without GA (which, if you have an Android or iPhone, I don't see why you'd have to be without) $0.20 a month seems an incredibly small price to pay for the benefit of 2-factor auth.

Re: Please turn on two-factor authentication

#16

I really hope other services start offering it as a feature. Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector. Also, RE the Google one time use passwords for POP/IMAP. They are all lower case, alpha/numeric, and 8 chars long. How secure are they against brute force? Why wouldn't Google offer 16 char options, or even longer? Is 8 good enough?

the application specific passwords are 16 characters long. Four blocks of four lowercase characters.

I too would rather them be longer, and involve at least some numbers if not specials... but they're not THAT short.

Re: Please turn on two-factor authentication

#17
Two-factor auth gets old really fast when you have to use public computers in a setting like a college library. I had turned it on for a while, but turned it off when I had 5 minutes to print out a paper that I had emailed myself (yes, I still do that) and was fiddling with my phone to get the damn PIN. Never again.

Re: Please turn on two-factor authentication

#18
Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords.

I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need access to everything. But you'd get full access to my account if you compromised any of these.

They already have this for the Connected Sites, Apps, and Services. I sent them a feature request for this a while ago but it hasn't been answered (and there's no way to view it online).

Re: Please turn on two-factor authentication

#20
post #14
post #8

Earlier quoted context omitted.

Yes you are, and I suspect you know this. Even in most third world countries cell-phones are common.

Still, if I plan to use Google Authenticator, I don't want to give Google my phone number at all. When they insist to get the phone number from me, I don't like it.

Are you talking about Google Authenticator the Android app, or the SMS service?
Post reply on HN