Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

61–70 of 262 posts

Re: Please turn on two-factor authentication

#61
post #47

Earlier quoted context omitted.

I don't think you need to get them a phone number. I use Google Authenticator app on my iPhone, and didn't give them anything. It just scanned a barcode on a webpage IIRC.

The bar code was actually just a code to initialize the code generation (I think it is based on that randomly generated seed and the time, so that then server and client generate the same keys). You could have also typed in the code by hand.

You're absolutely right. My parent was talking about giving Google his/her phone number, which I was responding to :)

Re: Please turn on two-factor authentication

#62
post #11

Earlier quoted context omitted.

You can run the Authenticator app on an iPod. But 2-factor does mean there in an expectation you will have to carry some kind of token device.

You shouldn't have to carry an electronic device, though: a list of codes on paper can work fine. That's how the NemID system works, for example ( http://en.wikipedia.org/wiki/NemID ): I have a big list of challenge/response codes that I carry in my wallet, and each is used once. I use that one successfully to log into my bank with two-factor authentication, but since I have no cell phone, iPod, iPad, or Android devi…

>edit: Hmm actually thought of a possible solution. Looking into how hard it'd be to port the Google Authenticator to a non-mobile platform so I can run it on my laptop.

Just install an android emulator, e.g. YouWave, and use that virtual android device to run GA.

Re: Please turn on two-factor authentication

#63
post #44

I just turned two-factor authentication on and it forced me to set "program specific" passwords for like 10 different apps and seriously messed up my phone. I had to deactivate it. What's with the hassle?

Not everything supports the 2-factor auth. And of course you have to set up specific passwords for those. ONCE! You wont have to do that again. What did you expect? That it magically made everything work? Some people -.-

And I have no clue how you managed to mess up your phone… By entering new passwords??

Re: Please turn on two-factor authentication

#64
post #44

I just turned two-factor authentication on and it forced me to set "program specific" passwords for like 10 different apps and seriously messed up my phone. I had to deactivate it. What's with the hassle?

For the second factor to mean anything, all the apps that don't support it need a password that has less rights.

Hopefully they figure out a nice way to make the rights more granular (so that a chat app can't mess with email or whatever).

Re: Please turn on two-factor authentication

#65
post #14
post #8

Earlier quoted context omitted.

Yes you are, and I suspect you know this. Even in most third world countries cell-phones are common.

Still, if I plan to use Google Authenticator, I don't want to give Google my phone number at all. When they insist to get the phone number from me, I don't like it.

Sorry, a bit off-topic, but that reminded me of one fun fact.

In Russia, most social networks these days require that you sign up with a mobile number. You cannot start using your account without receiving an SMS verification code.

Re: Please turn on two-factor authentication

#66
post #6

I did this a few months ago, but I'm thinking of turning it off. I know it's trivial, but there's something deeply annoying about being dinged $0.20 a pop for the SMS message to get the code. I'll have to see if I can set up the Google Authenticator; I hadn't heard of that before.

You pay for incoming SMS? How does that even work?

It is standard to pay for receiving as well as sending SMS in the US. Everybody knows this is insane.

Re: Please turn on two-factor authentication

#67
post #11

Earlier quoted context omitted.

You can run the Authenticator app on an iPod. But 2-factor does mean there in an expectation you will have to carry some kind of token device.

You shouldn't have to carry an electronic device, though: a list of codes on paper can work fine. That's how the NemID system works, for example ( http://en.wikipedia.org/wiki/NemID ): I have a big list of challenge/response codes that I carry in my wallet, and each is used once. I use that one successfully to log into my bank with two-factor authentication, but since I have no cell phone, iPod, iPad, or Android devi…

There is a windows version, and various java versions, and still others:

http://en.wikipedia.org/wiki/Google_Authenticator#Implementa...

Re: Please turn on two-factor authentication

#68
post #6

I did this a few months ago, but I'm thinking of turning it off. I know it's trivial, but there's something deeply annoying about being dinged $0.20 a pop for the SMS message to get the code. I'll have to see if I can set up the Google Authenticator; I hadn't heard of that before.

You pay for incoming SMS? How does that even work?

Standard American mobile billing is to bill both parties, both caller and callee, for both voice and SMS. Contrary to the European practice where caller/sender pays everything.

Mostly it's a downside for Americans, but one plus is that it means the caller's fee doesn't vary based on callee: unlike in some European countries (or Skype), calling a landline vs. a mobile phone doesn't charge the caller different rates.

Re: Please turn on two-factor authentication

#69
I hear a lot of people advising to turn on two factor auth on Google because of this incident, but I haven't heard anyone say that we should be deleting our card details from Amazon. Well, I have, and you should too. Lots of places use the last 4 digits of your card as "authentication", and Amazon happily displays those details in your account.

Re: Please turn on two-factor authentication

#70

Earlier quoted context omitted.

You shouldn't have to carry an electronic device, though: a list of codes on paper can work fine. That's how the NemID system works, for example ( http://en.wikipedia.org/wiki/NemID ): I have a big list of challenge/response codes that I carry in my wallet, and each is used once. I use that one successfully to log into my bank with two-factor authentication, but since I have no cell phone, iPod, iPad, or Android devi…

There is a windows version, and various java versions, and still others: http://en.wikipedia.org/wiki/Google_Authenticator#Implementa...

Oh cool, thanks; I was only looking at http://code.google.com/p/google-authenticator/ and didn't think to check Wikipedia.
Post reply on HN