I've been avoiding doing this, and I'm not certain the reason is valid - I don't want Google to have my mobile phone number. Perhaps I'm being overly cautious, but the fact Google already collects such a huge amount of data on me, coupled with the increasing insistent requests to enable two-factor with my mobile phone number, has made me not do it. I got so sick of being pestered about it that I stopped using Gmail a…
You don't need to enter your phone number to use Google's two factor. You can use their smartphone application to generate codes. If you don't want to do that, the algorithm is free and open-source so you can probably find an alternate implementation that works fine.
Please turn on two-factor authentication
111–120 of 262 posts
Re: Please turn on two-factor authentication
#112Earlier quoted context omitted.
It's not a 5 second hassle. I don't get a cell signal in the steel gymnasium even though the wifi works fine. I physically have to go outside to get a code every time I want to log in. And then if my phone is not working, or I leave it at home, I'm screwed.
That's a fairly special case though right? The most common concern I hear (other than it's just too complicated) is privacy concerns. People are asking "why does Google want my cell"? What else is that number used for?
Re: Please turn on two-factor authentication
#113Earlier quoted context omitted.
You can run the Authenticator app on an iPod. But 2-factor does mean there in an expectation you will have to carry some kind of token device.
You shouldn't have to carry an electronic device, though: a list of codes on paper can work fine. That's how the NemID system works, for example ( http://en.wikipedia.org/wiki/NemID ): I have a big list of challenge/response codes that I carry in my wallet, and each is used once. I use that one successfully to log into my bank with two-factor authentication, but since I have no cell phone, iPod, iPad, or Android devi…
Re: Please turn on two-factor authentication
#114Earlier quoted context omitted.
Yes you are, and I suspect you know this. Even in most third world countries cell-phones are common.
Perhaps I meant it as a half-rhetorical question; I'm not the only person I know who doesn't have a cell phone, and if you take moment to consider it, I'm sure you'll realize that you know some people in the same position. There are in fact significant demographics - children and the elderly - where cell phone adoption is rather low. Ironically enough, these are the very groups where enhanced security measures may be…
Actually no, I can't think of anyone. Buy an iPod Touch and install Google Authenticator, you will have all the inconveniences of not having a phone but enjoy the security benefits of two-factor authentication.
Re: Please turn on two-factor authentication
#115It's not worth it.
I don't run a business. I'm not a celebrity. I don't keep confidential information in my e-mail. And I don't register all of my various accounts at sites around the web to just one e-mail address. If someone got access to one of my e-mail accounts it would probably be a general-use one, and quite honestly it wouldn't affect me much.
It's also annoying to have to verify every time I log in. I probably log in more often than most people. When my browser session ends, all my cookies, cache and history are erased (not because i'm paranoid, but to help guard against CookieMonster, history probing and similar attacks on sites that don't do secure browsing right). Even though it may only be occasionally, having to go find my phone to authenticate the login takes away from my browsing experience, and I don't find the tradeoff worth the hassle.
It doesn't help that Google's authenticator medium is SMS. As a hacker, I find there's way too many avenues to intercept the token (not the least of which is an already-logged-in Google Voice session!). I like the idea of using a YubiKey, but if I have to stick the device into my computer, it's annoying. I prefer plain-old tokens like RSA's SecurID or the PayPal token (I got mine when it was still only $5). But it's not automatic. I have to do a bunch of work to set it up, and i'm lazy.
At the end of the day, even once you set up two factor, a good attacker will still get past it if they really want to. Separation of accounts will go a lot farther towards keeping your digital self safe than putting all your eggs into a two-factor single-account Google basket.
Edit: This post has encouraged me to pay the $20 for Bank of America's SafePass Card, which I consider to be much more secure than an app or sms.
Re: Please turn on two-factor authentication
#116Re: Please turn on two-factor authentication
#117Google 2-step auth is very hard to use and for how hard it is to use it doesn't provide all that much protection. It protects against phishing (mostly) but not against someone who has your phone. Malicious ex-girlfriend trying to do you harm? Google 2-factor won't help you a bit as long as at some point she had access to your phone.
Any security improvement is better than no improvement so let's concentrate on the real issue which is ease of use.
1. Google 2-factor auth requires application specific passwords are deeply confusing
I founded Clickpass and I can only just get my head around this. One password per application? This is a very confusing concept and very difficult for the average person to understand. There's no indication of whether you can reasonably create one password and reuse it in all your apps (which I think you can).
Application specific passwords are very confusing and not that much more secure than one revokable password for all applications.
2. Application specific passwords are almost impossible to use on mobile apps
Ever tried copying a 12-digit long string into a keyboard which only shows you the last letter you entered and even then only for half a second? It's really hard. You can't copy and paste them and you have to have a computer nearby to do it (it's very hard to use the Google password-generator page on mobile)
Here is the list of the application-specific passwords that have to be individually entered (10+ characters each):
On my mobile
- iphone mail
- iPhone Google account (through browser)
- iphone work mail
- iPhone (work Google account through browser)
- iphone calendar
- iPhone calendar (work)
DUPLICATE ALL OF THE ABOVE FOR iPad
DUPLICATE ALL OF THE ABOVE FOR MacBook Air
Switch on 2-factor auth and you immeidately find all these apps go dead until you do this. It will take you about 15m at least to do this and you'll have to do it again if you change your password or get a new device. You can't copy and paste because the Google auth-token page is unusable on moble.
What we need is easy, incremental security improvement
The problem with Google 2-factor auth is that it was designed by security geeks. It takes 3m just to watch their setup video! The system needs to be designed by usability geeks and audited by security geeks.
2-factor auth is no use at all if it's switched off. Contrast my switched off 2-factor auth with my Facebook auth which texts me every time someone logs in from a new machine and you contrast a system which provides me with a bit more security (FB) and one which pertains to be secure (Google) but which adds nothing.
Google needs to rip the security guys out of their security team and put the user experience people in. End-user security is a UX problem and Google is in a powerful position to effect change.
[Edited above for (a little) brevity]
EDIT BELOW: for folks who feel this account is unfair:
I realise that if you keep a PGP encrypted file on another device that is necessary to do your password reset then yes, Google 2-factor auth is very strong indeed.
I also realise that you shouldn't tell someone your password. The point is though that resetting your password is something that only really needs your phone. The key elements to resetting your password usually involve sending a password or an out-of-channel token to another acccount. For most people that other account is their work mail or Facebook, both of which are usually accessible via their phone.
I'm not talking about the absolute strength of Google 2-factor authentication. I'm talking about how that type of process applies to the type of internet user who tries to log into Facebook through ReadWriteWeb:
http://www.readwriteweb.com/archives/facebook_wants_to_be_yo...
Re: Please turn on two-factor authentication
#118OK, so I turn on two-factor authentication for GMail, but... 1) I immediately have to create a application specific password to actually read my mail on my iPhone. 2) If anyone ever gets access to that secret password, or any of the others I create, they have full access to my email and any password resets they generate. 3) I will have no idea this is happening since I would expect my mail to access that app password…
Yes: that email password cannot be used to change your password, cancel your account, etc. and can be revoked easily without breaking anything else. This also means that you're not entering the password which can do all of those things on a daily basis, further reducing the odds of someone else being able to capture it even if they do manage the total local compromise or strong SSL MITM needed to get your ASP.
Security is all about incremental improvements, not silver bullets.
Re: Please turn on two-factor authentication
#119I'm really frustrated with Google and this 2-factor authentication. They are in such a great position to really change the way in which people secure themselves and they've completely missed the trick [edit: FOR THE AVERAGE USER]. Google 2-step auth is very hard to use and for how hard it is to use it doesn't provide all that much protection. It protects against phishing (mostly) but not against someone who has your…
I completely agree that the overall UX needs serious improvement but … doesn't your mobile device support copy and paste? I do this from time to time and while it's a bit clunky it's a lot easier than typing the password in by hand.
Re: Please turn on two-factor authentication
#120I'm really frustrated with Google and this 2-factor authentication. They are in such a great position to really change the way in which people secure themselves and they've completely missed the trick [edit: FOR THE AVERAGE USER]. Google 2-step auth is very hard to use and for how hard it is to use it doesn't provide all that much protection. It protects against phishing (mostly) but not against someone who has your…
Why do they (and your malicious ex) know the other half needed to login - your password?