Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

21–30 of 262 posts

Re: Please turn on two-factor authentication

#21

I really hope other services start offering it as a feature. Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector. Also, RE the Google one time use passwords for POP/IMAP. They are all lower case, alpha/numeric, and 8 chars long. How secure are they against brute force? Why wouldn't Google offer 16 char options, or even longer? Is 8 good enough?

> Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector.

The least they could do if offer IP whitelisting like Linode does.

Re: Please turn on two-factor authentication

#22

I really hope other services start offering it as a feature. Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector. Also, RE the Google one time use passwords for POP/IMAP. They are all lower case, alpha/numeric, and 8 chars long. How secure are they against brute force? Why wouldn't Google offer 16 char options, or even longer? Is 8 good enough?

the application specific passwords are 16 characters long. Four blocks of four lowercase characters. I too would rather them be longer, and involve at least some numbers if not specials... but they're not THAT short.

Really? I was sure it was only 8 when I went through the process 2 weeks ago. 2 lots of 4.

Time to go and generate some new passwords!

Re: Please turn on two-factor authentication

#23
post #14
post #8

Earlier quoted context omitted.

Yes you are, and I suspect you know this. Even in most third world countries cell-phones are common.

Still, if I plan to use Google Authenticator, I don't want to give Google my phone number at all. When they insist to get the phone number from me, I don't like it.

I don't think you need to get them a phone number. I use Google Authenticator app on my iPhone, and didn't give them anything. It just scanned a barcode on a webpage IIRC.

Re: Please turn on two-factor authentication

#24
I'm sure someone is probably working on this, but what about a service that generates a one off seed for the second stage of auth, married with either a desktop or smartphone app for generating it for the user. Lose your phone/laptop/PC simply cancel it remotely so it stops generating, same as you would if you lost your bank card.

I'm sure I'm missing something, but I'm not sure what.

EDIT: I'll let the post stand but I need to read more clearly, I thought Google Authenticator was purely for Google services.

Re: Please turn on two-factor authentication

#25

I really hope other services start offering it as a feature. Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector. Also, RE the Google one time use passwords for POP/IMAP. They are all lower case, alpha/numeric, and 8 chars long. How secure are they against brute force? Why wouldn't Google offer 16 char options, or even longer? Is 8 good enough?

I'm getting 16 character app specific passwords having just turned it on on one of my Google Accounts (all lowercase alpha though).

Re: Please turn on two-factor authentication

#26
post #17

Two-factor auth gets old really fast when you have to use public computers in a setting like a college library. I had turned it on for a while, but turned it off when I had 5 minutes to print out a paper that I had emailed myself (yes, I still do that) and was fiddling with my phone to get the damn PIN. Never again.

Maybe it's just me but I only trust computers I control.

If you don't have root on a box, consider it pwn3d with keyloggers listening to every juicy password you type. Take that as your friend's laptop, a library computer or even your parent's Windows XP box...

Trust no one, Mr. Mulder.

/tinfoilhat

Re: Please turn on two-factor authentication

#27

Earlier quoted context omitted.

the application specific passwords are 16 characters long. Four blocks of four lowercase characters. I too would rather them be longer, and involve at least some numbers if not specials... but they're not THAT short.

Really? I was sure it was only 8 when I went through the process 2 weeks ago. 2 lots of 4. Time to go and generate some new passwords!

Hmmm... I generated a batch about 2 months ago and another batch last week. In both cases, they were of the form

    llll llll llll llll
(l: [a-z])

Re: Please turn on two-factor authentication

#28

Do you trust the minimum wage customer service reps of your phone company to not be susceptible to social engineering? Two factor-auth, via SMS, may not have saved Matt Honan.

Use the app, it's not vulnerable to such an attack.

Or buy a prepaid phone, and don't use the number for anything else.

Re: Please turn on two-factor authentication

#29
post #17

Two-factor auth gets old really fast when you have to use public computers in a setting like a college library. I had turned it on for a while, but turned it off when I had 5 minutes to print out a paper that I had emailed myself (yes, I still do that) and was fiddling with my phone to get the damn PIN. Never again.

Well, is that 5-minutes-to-print an edge case or a more than occasional situation? If the latter, how hard is it to create an alternate email account in which you send non-confidential emails/docs on the spur of a moment?

If it's an edge case, it seems like a trivial one for reducing your security so much. As your documented online data grows, the chance of being hacked only grows. And once you've been hacked, there's really no going back if the attacker decides to do a data-dump and now forever holds your information in perpetuity.

Post reply on HN