Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

151–160 of 262 posts

Re: Please turn on two-factor authentication

#151
post #31

I was worried this would be a major pain when I enabled it, but I have to say, it has been much more painless than I thought it would be. Most of the time, I don't even think about it. Most of my consumption of google mail is through clients on my laptops, iPhone, or iPad. So in that sense, it's not much different from a regular password. The difference is that someone else has a much harder time cracking my account.…

I used two-factor authentication for about a year, and I just got so sick of it. I had no issue with the whole logging in and using the time-sensitive code from my Android phone. It was the support for all the other Google apps that drove me crazy. I got really tired of needing to generate new temporary passwords for access through iCal, Mail, and I think even sites like StackOverflow. Perhaps I was at a point in life where I had too many new devices and changes going on.

It's the typical security vs accessibility trade-offs. Accessibility won.

Re: Please turn on two-factor authentication

#152

Earlier quoted context omitted.

You pay for incoming SMS? How does that even work?

Standard American mobile billing is to bill both parties, both caller and callee, for both voice and SMS. Contrary to the European practice where caller/sender pays everything. Mostly it's a downside for Americans, but one plus is that it means the caller's fee doesn't vary based on callee: unlike in some European countries (or Skype), calling a landline vs. a mobile phone doesn't charge the caller different rates.

> Standard American mobile billing is to bill both parties

That's the most bizarre thing I've heard in weeks. Honestly, I'm still laughing. BOTH for SMS and voice?!! God, that's just crazy. No wonder you Americans hate telco companies so much. And I though 0.25 cents (only for outgoing SMSs) that we pay here is absurd.

Re: Please turn on two-factor authentication

#153
post #109
post #107

Earlier quoted context omitted.

FTA: You can install a standalone app called Google Authenticator (it’s also available in the App Store), so your cell phone doesn’t need a signal. Also: You can print out a small piece of paper with 10 one-time rescue codes and put that in your wallet. Use those one-time codes to log in even without your phone.

Hm, can you generate new codes whenever you need to? It might be cool to use these 10 at a time as a one-time pad.

You can create a new set whenever you want. However, generating a new set invalidates the previous set (so you can revoke access with those tokens if they are lost.

Re: Please turn on two-factor authentication

#154
post #54

really surprised so many people that post here refuse to use google authenticator because its "annoying." is it a hassle? yes, but if you have ever had your email (and other accounts) compromised you understand why it is worth that small 5 second hassle when you login. one feature that i cannot understand why it hasnt been implemented though is protecting the app itself with a password or pin. some people say to just…

> but not if the person that finds it opens up google authenticator (which shows the account the id is used for) and logs in to change the password before i have a chance to.

The person finding your phone would have to either have access to your password, your backup email address or the answer to your security question (which you can write yourself).

Re: Please turn on two-factor authentication

#155

Earlier quoted context omitted.

Standard American mobile billing is to bill both parties, both caller and callee, for both voice and SMS. Contrary to the European practice where caller/sender pays everything. Mostly it's a downside for Americans, but one plus is that it means the caller's fee doesn't vary based on callee: unlike in some European countries (or Skype), calling a landline vs. a mobile phone doesn't charge the caller different rates.

> Standard American mobile billing is to bill both parties That's the most bizarre thing I've heard in weeks. Honestly, I'm still laughing. BOTH for SMS and voice ?!! God, that's just crazy. No wonder you Americans hate telco companies so much. And I though 0.25 cents (only for outgoing SMSs) that we pay here is absurd.

For voice I actually like it somewhat better: I hate the European system where the caller can be charged extra because the recipient happens to be on a mobile phone, which you can't always even know before calling. In some cases it can be large; I've been charged $0.30/minute calling a Greek mobile phone in the past, as the caller, when I didn't know I was calling a mobile phone (if it were a landline I would've been charged Paying both ways for SMS is a bit silly, though.

Re: Please turn on two-factor authentication

#157
post #140

Quick question for all you security experts: Which is more secure: LastPass with 2factor, or a gpg encrypted password safe on my home server accessed by a passphrase-locked rsa-encrypted key? I've been trying to decide for the past few weeks. Copying and pasting passwords isn't as annoying as I thought it would be, and it seems like keeping my pwsafe locally reduces the attack vector of the LastPass servers. Then aga…

At the absolute best, I'd say using an app like Pocket (on Android) on a non-network connected device is probably the safest setup. Granted you'd have to type the passwords in manually, but nothing beats air-gap security, and you'd need to remember just one password.

Also, if you lose your device, you're screwed, unless you've dropbox synced it of course. In which case, you lose the air-gap.

Re: Please turn on two-factor authentication

#158
post #15
post #6

I did this a few months ago, but I'm thinking of turning it off. I know it's trivial, but there's something deeply annoying about being dinged $0.20 a pop for the SMS message to get the code. I'll have to see if I can set up the Google Authenticator; I hadn't heard of that before.

Even without GA (which, if you have an Android or iPhone, I don't see why you'd have to be without) $0.20 a month seems an incredibly small price to pay for the benefit of 2-factor auth.

which, if you have an Android or iPhone, I don't see why you'd have to be without

You don't even need one of those, there are implementations of the same algorithm for other systems. I use my Nokia S60 with a J2ME application: http://ds3global.com/index.php/en/news-a-events/news/97-secu...

Re: Please turn on two-factor authentication

#159
post #147
post #137

Earlier quoted context omitted.

Please, please, please, please RTFA before ranting. SMS is not required (you can use the google Authenticator App). The Authenticator app works just like a "plain old token". Separation of accounts means squat if your passwords are intercepted. 2 factor auth requires physical access and reduces the possible pool of attackers from billions to hundreds.

You still need to hunt for phone (on top of that you must have one) to log in...

That, and I don't trust "an app." The whole reason I want a second factor is to get away from computers as primary authentication mediums, and a smart phone is a computer.

I don't think anyone realizes how much malware is in the Android marketplace. And that's beside the malware that vendors and carriers install on there by default. Do not trust your phone.

Re: Please turn on two-factor authentication

#160
post #14

Earlier quoted context omitted.

Still, if I plan to use Google Authenticator, I don't want to give Google my phone number at all. When they insist to get the phone number from me, I don't like it.

Sorry, a bit off-topic, but that reminded me of one fun fact. In Russia, most social networks these days require that you sign up with a mobile number. You cannot start using your account without receiving an SMS verification code.

Iirc, even facebook nowadays (at least in India) requires you to complete SMS verification during account creation.
Post reply on HN