Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

31–40 of 262 posts

Re: Please turn on two-factor authentication

#31
I was worried this would be a major pain when I enabled it, but I have to say, it has been much more painless than I thought it would be. Most of the time, I don't even think about it. Most of my consumption of google mail is through clients on my laptops, iPhone, or iPad. So in that sense, it's not much different from a regular password. The difference is that someone else has a much harder time cracking my account. It's actually much less obtrusive than using lastpass (also highly recommended, but not as transparently usable).

That being said, two factor google auth wasn't going to save Matt Honan here. Identity, trust, and authentication on the internet are all built on a foundation of sand. We need a new model.

Re: Please turn on two-factor authentication

#32
post #17

Two-factor auth gets old really fast when you have to use public computers in a setting like a college library. I had turned it on for a while, but turned it off when I had 5 minutes to print out a paper that I had emailed myself (yes, I still do that) and was fiddling with my phone to get the damn PIN. Never again.

Maybe it's just me but I only trust computers I control. If you don't have root on a box, consider it pwn3d with keyloggers listening to every juicy password you type. Take that as your friend's laptop, a library computer or even your parent's Windows XP box... Trust no one, Mr. Mulder. /tinfoilhat

Yeah, that would be great if the damn wireless printing worked in school. Sometimes you just have to log into a public machine.

Re: Please turn on two-factor authentication

#33
post #18

Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…

I didn't think Chrome any longer required an ASP?

Re: Please turn on two-factor authentication

#34

I'm sure someone is probably working on this, but what about a service that generates a one off seed for the second stage of auth, married with either a desktop or smartphone app for generating it for the user. Lose your phone/laptop/PC simply cancel it remotely so it stops generating, same as you would if you lost your bank card. I'm sure I'm missing something, but I'm not sure what. EDIT: I'll let the post stand bu…

Already on the market - YubiKey.

Re: Please turn on two-factor authentication

#35

Earlier quoted context omitted.

the application specific passwords are 16 characters long. Four blocks of four lowercase characters. I too would rather them be longer, and involve at least some numbers if not specials... but they're not THAT short.

Really? I was sure it was only 8 when I went through the process 2 weeks ago. 2 lots of 4. Time to go and generate some new passwords!

They've been 16 chars for at least several months.

Re: Please turn on two-factor authentication

#36

Earlier quoted context omitted.

Really? I was sure it was only 8 when I went through the process 2 weeks ago. 2 lots of 4. Time to go and generate some new passwords!

Hmmm... I generated a batch about 2 months ago and another batch last week. In both cases, they were of the form llll llll llll llll (l: [a-z])

Happy to stand corrected. My apologies all round.

Thanks everyone!

Re: Please turn on two-factor authentication

#37
I've been avoiding doing this, and I'm not certain the reason is valid - I don't want Google to have my mobile phone number. Perhaps I'm being overly cautious, but the fact Google already collects such a huge amount of data on me, coupled with the increasing insistent requests to enable two-factor with my mobile phone number, has made me not do it. I got so sick of being pestered about it that I stopped using Gmail a little while ago.

Re: Please turn on two-factor authentication

#38
post #32

Earlier quoted context omitted.

Maybe it's just me but I only trust computers I control. If you don't have root on a box, consider it pwn3d with keyloggers listening to every juicy password you type. Take that as your friend's laptop, a library computer or even your parent's Windows XP box... Trust no one, Mr. Mulder. /tinfoilhat

Yeah, that would be great if the damn wireless printing worked in school. Sometimes you just have to log into a public machine.

You couldn't use a USB key instead?

Re: Please turn on two-factor authentication

#39
post #33
post #18

Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…

I didn't think Chrome any longer required an ASP?

[deleted]

Re: Please turn on two-factor authentication

#40
post #33
post #18

Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…

I didn't think Chrome any longer required an ASP?

Still did as of a month or two ago when I turned on two-factor.
Post reply on HN