Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

91–100 of 262 posts

Re: Please turn on two-factor authentication

#91
post #43
post #33

Earlier quoted context omitted.

I didn't think Chrome any longer required an ASP?

It still does; I had to go through this yesterday. I don't mind Chrome so much per se , but this also means you need an application-specific password for Chrome OS, at least for he initial sign-on, which I find oddly frustrating.

It does if you set up the sync account via the Settings page, but if you ignore the request to sign in, visit some Google page that requires login and log in, Chrome will produce a yellow bar at the top of the screen asking if you want to use that account for Chrome sync. Click yes and you don't need to sign in any further.

Re: Please turn on two-factor authentication

#92
post #82

Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."

You can use a YubiKey for Google 2-factor along with a helper app like Yubikco's "sidekick" for Windows [1] or my company's OneTime on Mac [2]. A YubiKey costs about $25 but is very portable, fast and convenient option. [1] http://yubico.com/totp [2] http://zetetic.net/software-onetime

[deleted]

Re: Please turn on two-factor authentication

#93
post #80

Like the second class citizens of the web we are, Nigeria does not have 2 factor authentication. Ghana, Pakistan, Iran, North Korea, Russia, all have 2 factor authentication. Why not Nigeria? This is just another example why being Nigerian is kinda hard on the internet. https://accounts.google.com/b/0/SmsAuthConfig http://oonwoye.com/2011/01/23/life-as-a-second-class-citizen...

> Why not Nigeria? Can Nigerians use the Google Authenticator app? If yes, then the answer is probably high SMS costs.

High SMS costs?

It is exactly why I put the range of countries above. Can we be in a worse situation than them all?

Re: Please turn on two-factor authentication

#94
post #8

Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."

Yes you are, and I suspect you know this. Even in most third world countries cell-phones are common.

Perhaps I meant it as a half-rhetorical question; I'm not the only person I know who doesn't have a cell phone, and if you take moment to consider it, I'm sure you'll realize that you know some people in the same position.

There are in fact significant demographics - children and the elderly - where cell phone adoption is rather low. Ironically enough, these are the very groups where enhanced security measures may be most useful.

Re: Please turn on two-factor authentication

#95
post #44

I just turned two-factor authentication on and it forced me to set "program specific" passwords for like 10 different apps and seriously messed up my phone. I had to deactivate it. What's with the hassle?

For the second factor to mean anything, all the apps that don't support it need a password that has less rights. Hopefully they figure out a nice way to make the rights more granular (so that a chat app can't mess with email or whatever).

Do those passwords have less rights? I figured that if any of those passwords got compromised, you were screwed (until you found out which one and revoked it).

Re: Please turn on two-factor authentication

#96
post #86

I hear a lot of people advising to turn on two factor auth on Google because of this incident, but I haven't heard anyone say that we should be deleting our card details from Amazon. Well, I have, and you should too. Lots of places use the last 4 digits of your card as "authentication", and Amazon happily displays those details in your account.

Note that they had to break into the account in order to view those last 4 digits. You seem to be implying that they show them to anyone. Either way, using the last 4 digits as 'security' is just stupid. You can get those from a receipt.

* Edit: Ah, technically they did break into the email account. The first time I read this I thought that they just had access to the account info page (doing things, such as purchasing or accessing account settings, requires password-entry by Amazon)

No, they did not have to break into the Amazon account.

http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-hona...

> First you call Amazon and tell them you are the account holder, and want to add a credit card number to the account. All you need is the name on the account, an associated e-mail address, and the billing address. Amazon then allows you to input a new credit card. (Wired used a bogus credit card number from a website that generates fake card numbers that conform with the industry’s published self-check algorithm.) Then you hang up.

> Next you call back, and tell Amazon that you’ve lost access to your account. Upon providing a name, billing address, and the new credit card number you gave the company on the prior call, Amazon will allow you to add a new e-mail address to the account. From here, you go to the Amazon website, and send a password reset to the new e-mail account. This allows you to see all the credit cards on file for the account — not the complete numbers, just the last four digits. But, as we know, Apple only needs those last four digits. We asked Amazon to comment on its security policy, but didn’t have anything to share by press time.

Re: Please turn on two-factor authentication

#97
OK, so I turn on two-factor authentication for GMail, but...

1) I immediately have to create a application specific password to actually read my mail on my iPhone.

2) If anyone ever gets access to that secret password, or any of the others I create, they have full access to my email and any password resets they generate.

3) I will have no idea this is happening since I would expect my mail to access that app password daily.

So your fancy two factor authentication still ends up resting on one piece of secret info as the weak point. Am I missing something?

Re: Please turn on two-factor authentication

#98

I did this but was expecting more from Google. As an example, it was easier to add two factor auth to my Blizzard account (and install their authenticator) than it was for Google. These are the steps for Google: - Add mobile phone to account - Enter code from SMS - Generate random passwords for multiple apps which don't support two factor auth (this took awhile). - I wasn't given any instructions on how to switch fro…

The difference is, as you mention, that for your Blizzard account there is one app that needs to be changed to use 2FA, whereas with Google you are using your account from dozens of apps that they do not control and that can not be made to support the 2FA login process. It's an unfair comparison.

Re: Please turn on two-factor authentication

#100
post #59

Is there a way to use a separate hardware device? Using my phone as the second factor is nice, but my phone is vulnerable to theft because of its value for resale. A sealed gizmo that shows a number just looks like an el-cheapo souvenier. Without knowing my username and password too, it really is worthless.

The linked article mentioned this: http://static.yubico.com/var/uploads/pdfs/Howto_GmailYubiKey...

YubiKeys are relatively cheap and would provide a nice alternative to using a phone, IMO.

Post reply on HN