Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

121–130 of 262 posts

Re: Please turn on two-factor authentication

#121
I'll propose a sideways solution: implement an "Administrator" mode on these accounts that requires separate authentication--perhaps enforcing two-factor authentication there.

There are many complaints about how Microsoft didn't protect Windows users enough because everyone had administrator access as a default. But isn't that the same problem with these Google and Apple accounts? With your standard account, you can change your password, delete all data, and do many other damaging acts.

I don't really want to enter in multiple pins/passwords each time I read email. But I would be more than fine doing so before being given the ability to damage my account.

Re: Please turn on two-factor authentication

#122

It's a good idea, but it's not the weakest link in user security right now. It does very little to solve problems like Apple positively identifying people based on totally insufficient and publicly available information.

> It's a good idea, but it's not the weakest link in user security right now

I suspect Google is in a better position to judge how widespread account compromises are than you are. From my perspective, it definitely seems like security people are all saying that account compromises (keyloggers, phishing) have been the predominant threat for several years now because they're suitable for bulk attacks whereas social-engineering Apple is a more limited, if deeply disturbing, process.

Re: Please turn on two-factor authentication

#123
post #84
post #18

Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…

> I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup) Maybe you should use throwaway accounts for these purposes? That is, have a gmail account for github to send your patches through, and have that forward to your main email account? In the SMS-backup case...how important is it that you acces…

They should at least go as far as create/read/delete.

Then I can uncheck delete for my chat apps. Edit: And grandparent could uncheck read and delete for a couple of their use cases (which is a pretty big improvement).

Re: Please turn on two-factor authentication

#124

I'm really frustrated with Google and this 2-factor authentication. They are in such a great position to really change the way in which people secure themselves and they've completely missed the trick [edit: FOR THE AVERAGE USER]. Google 2-step auth is very hard to use and for how hard it is to use it doesn't provide all that much protection. It protects against phishing (mostly) but not against someone who has your…

I feel your pain, slightly, but isn't the majority of this list caused by the fact that Apple's software stinks? There's no way for apps on iOS to share the account details. You don't need to do any of that junk on Android. And you wouldn't have to do any of it on a Chromebook, either.

Re: Please turn on two-factor authentication

#125
post #119

I'm really frustrated with Google and this 2-factor authentication. They are in such a great position to really change the way in which people secure themselves and they've completely missed the trick [edit: FOR THE AVERAGE USER]. Google 2-step auth is very hard to use and for how hard it is to use it doesn't provide all that much protection. It protects against phishing (mostly) but not against someone who has your…

> 2. Application specific passwords are impossible to use on mobile apps I completely agree that the overall UX needs serious improvement but … doesn't your mobile device support copy and paste? I do this from time to time and while it's a bit clunky it's a lot easier than typing the password in by hand.

It does but it's almost impossible to access the Google auth page on the mobile and get the passwords.

Re: Please turn on two-factor authentication

#126

I'm really frustrated with Google and this 2-factor authentication. They are in such a great position to really change the way in which people secure themselves and they've completely missed the trick [edit: FOR THE AVERAGE USER]. Google 2-step auth is very hard to use and for how hard it is to use it doesn't provide all that much protection. It protects against phishing (mostly) but not against someone who has your…

> it won't protect you from someone stealing your phone and opening your authenticator to login to your account Why do they (and your malicious ex) know the other half needed to login - your password?

Yeah, I'm sorry...I understand the parent post's rants, but to even bring up this scenario is absurd. If your nemesis knows your password, then you've royally screwed up, nevermind the problem with her having your phone.

Also, does the parent-commenter mistakenly believe that the authenticator code is all that's needed to log into an account? But maybe that underscores his point that the whole system may be overwhelming to the average user.

Re: Please turn on two-factor authentication

#127

I'm really frustrated with Google and this 2-factor authentication. They are in such a great position to really change the way in which people secure themselves and they've completely missed the trick [edit: FOR THE AVERAGE USER]. Google 2-step auth is very hard to use and for how hard it is to use it doesn't provide all that much protection. It protects against phishing (mostly) but not against someone who has your…

>Google 2-step auth is way too hard to use and for how hard it is to use it doesn't provide all that much protection. It protects against phishing (mostly) but not against someone who has your phone. Malicious ex-girlfriend trying to do you harm? Google 2-factor won't help you a bit as long as at some point she had access to your phone.

Can we not upvote bullshit? He's vocally ignorant. The one time key generator is useless without the password. For his situation to be an issue he must have already have given her the password.

I don't think promoting security advice from someone who gives out his plaintext password is the least bit responsible.

Re: Please turn on two-factor authentication

#128
post #84
post #18

Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…

> I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup) Maybe you should use throwaway accounts for these purposes? That is, have a gmail account for github to send your patches through, and have that forward to your main email account? In the SMS-backup case...how important is it that you acces…

AFAIK it is still against Google's policies to have more than one gmail-account? That doesn't mean it won't work, of course, but you might end up with Google turning off all your accounts, with no real recourse to fix the situation.

Why do you need access to your google account to send email from github? From:-headers are designed to be readily "forged" (or rather, set to whatever you want). Just send email through wathever means you use, optionally adding a bcc to your own account, if you want a copy of the actual email in your gmail folder?

Re: Please turn on two-factor authentication

#129
post #18

Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…

Indeed. I have created a couple application passwords for "Verbs" IM on my iPad and my iPhone (though I rarely use chat, but added them just in case). I'd feel safer if I knew these guys can only see see my contacts and send/receive messages. Right now they can see all my emails and probably everything else that's on my google account.

Re: Please turn on two-factor authentication

#130
post #127

I'm really frustrated with Google and this 2-factor authentication. They are in such a great position to really change the way in which people secure themselves and they've completely missed the trick [edit: FOR THE AVERAGE USER]. Google 2-step auth is very hard to use and for how hard it is to use it doesn't provide all that much protection. It protects against phishing (mostly) but not against someone who has your…

> Google 2-step auth is way too hard to use and for how hard it is to use it doesn't provide all that much protection. It protects against phishing (mostly) but not against someone who has your phone. Malicious ex-girlfriend trying to do you harm? Google 2-factor won't help you a bit as long as at some point she had access to your phone. Can we not upvote bullshit? He's vocally ignorant. The one time key generator is…

How would you reset your password on your Google account Parfe?
Post reply on HN