That being said, two factor google auth wasn't going to save Matt Honan here. Identity, trust, and authentication on the internet are all built on a foundation of sand. We need a new model.
Please turn on two-factor authentication
31–40 of 262 posts
Re: Please turn on two-factor authentication
#32Two-factor auth gets old really fast when you have to use public computers in a setting like a college library. I had turned it on for a while, but turned it off when I had 5 minutes to print out a paper that I had emailed myself (yes, I still do that) and was fiddling with my phone to get the damn PIN. Never again.
Maybe it's just me but I only trust computers I control. If you don't have root on a box, consider it pwn3d with keyloggers listening to every juicy password you type. Take that as your friend's laptop, a library computer or even your parent's Windows XP box... Trust no one, Mr. Mulder. /tinfoilhat
Re: Please turn on two-factor authentication
#33Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…
Re: Please turn on two-factor authentication
#34I'm sure someone is probably working on this, but what about a service that generates a one off seed for the second stage of auth, married with either a desktop or smartphone app for generating it for the user. Lose your phone/laptop/PC simply cancel it remotely so it stops generating, same as you would if you lost your bank card. I'm sure I'm missing something, but I'm not sure what. EDIT: I'll let the post stand bu…
Re: Please turn on two-factor authentication
#35Earlier quoted context omitted.
the application specific passwords are 16 characters long. Four blocks of four lowercase characters. I too would rather them be longer, and involve at least some numbers if not specials... but they're not THAT short.
Really? I was sure it was only 8 when I went through the process 2 weeks ago. 2 lots of 4. Time to go and generate some new passwords!
Re: Please turn on two-factor authentication
#36Earlier quoted context omitted.
Really? I was sure it was only 8 when I went through the process 2 weeks ago. 2 lots of 4. Time to go and generate some new passwords!
Hmmm... I generated a batch about 2 months ago and another batch last week. In both cases, they were of the form llll llll llll llll (l: [a-z])
Thanks everyone!
Re: Please turn on two-factor authentication
#37Re: Please turn on two-factor authentication
#38Earlier quoted context omitted.
Maybe it's just me but I only trust computers I control. If you don't have root on a box, consider it pwn3d with keyloggers listening to every juicy password you type. Take that as your friend's laptop, a library computer or even your parent's Windows XP box... Trust no one, Mr. Mulder. /tinfoilhat
Yeah, that would be great if the damn wireless printing worked in school. Sometimes you just have to log into a public machine.
Re: Please turn on two-factor authentication
#39Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…
I didn't think Chrome any longer required an ASP?
Re: Please turn on two-factor authentication
#40Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…
I didn't think Chrome any longer required an ASP?