Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

161–170 of 262 posts

Re: Please turn on two-factor authentication

#161
post #111
post #45

Earlier quoted context omitted.

You don't need to enter your phone number to use Google's two factor. You can use their smartphone application to generate codes. If you don't want to do that, the algorithm is free and open-source so you can probably find an alternate implementation that works fine.

As far as I'm aware, it's not available on Windows Phone 7.

Not GA itself, but there are compatible implementations: http://www.windowsphone.com/en-US/apps/021dd79f-0598-e011-98...

Re: Please turn on two-factor authentication

#162
>Reality: You can tell Google to trust your computer for 30 days and sometimes even longer.

How is that "even longer" part supposed to work? I have a desktop Mac that prompt me every 30 days to re-logon to GMail in Safari. Is there a way to add it to the trusted computer list?

Re: Please turn on two-factor authentication

#163

Earlier quoted context omitted.

You shouldn't have to carry an electronic device, though: a list of codes on paper can work fine. That's how the NemID system works, for example ( http://en.wikipedia.org/wiki/NemID ): I have a big list of challenge/response codes that I carry in my wallet, and each is used once. I use that one successfully to log into my bank with two-factor authentication, but since I have no cell phone, iPod, iPad, or Android devi…

>edit: Hmm actually thought of a possible solution. Looking into how hard it'd be to port the Google Authenticator to a non-mobile platform so I can run it on my laptop. Just install an android emulator, e.g. YouWave, and use that virtual android device to run GA.

Google Authenticator uses the standard OATH protocol (note, this is not OAuth): http://www.openauthentication.org/specifications

Re: Please turn on two-factor authentication

#164
post #147

Earlier quoted context omitted.

You still need to hunt for phone (on top of that you must have one) to log in...

That, and I don't trust "an app." The whole reason I want a second factor is to get away from computers as primary authentication mediums, and a smart phone is a computer. I don't think anyone realizes how much malware is in the Android marketplace. And that's beside the malware that vendors and carriers install on there by default. Do not trust your phone.

The Authenticator app is open-source [1] and extremely minimal. It doesn't run with permissions to access any data on the phone, or even communicate over the network; all it does is read the system clock every 30 seconds and compute an HMAC.

[1] http://code.google.com/p/google-authenticator/

Re: Please turn on two-factor authentication

#165
post #147
post #137

Earlier quoted context omitted.

Please, please, please, please RTFA before ranting. SMS is not required (you can use the google Authenticator App). The Authenticator app works just like a "plain old token". Separation of accounts means squat if your passwords are intercepted. 2 factor auth requires physical access and reduces the possible pool of attackers from billions to hundreds.

You still need to hunt for phone (on top of that you must have one) to log in...

Be honest. When was the last time you were sitting at your (or any other) machine while away from your mobile phone?

Also, you only need the authenticator revolving token every 30 days.

Re: Please turn on two-factor authentication

#166
post #14
post #8

Earlier quoted context omitted.

Yes you are, and I suspect you know this. Even in most third world countries cell-phones are common.

Still, if I plan to use Google Authenticator, I don't want to give Google my phone number at all. When they insist to get the phone number from me, I don't like it.

Buy a $20 used phone and get the cheapest pay-as-you-go plan you can find (you'll only be using the phone to receive text messages, so it should be really cheap) and consider it a somewhat impractical Google Authenticator hardware dongle.

Re: Please turn on two-factor authentication

#167
post #37

I've been avoiding doing this, and I'm not certain the reason is valid - I don't want Google to have my mobile phone number. Perhaps I'm being overly cautious, but the fact Google already collects such a huge amount of data on me, coupled with the increasing insistent requests to enable two-factor with my mobile phone number, has made me not do it. I got so sick of being pestered about it that I stopped using Gmail a…

I can guarantee you that google knows your mobile number already. Do you have friends? do they know your number? do they have you saved as a google contact? game over.

If you are sufficiently paranoid there are probably call/sms-forwarding services available for a reasonable cost.

Re: Please turn on two-factor authentication

#168
post #44

I just turned two-factor authentication on and it forced me to set "program specific" passwords for like 10 different apps and seriously messed up my phone. I had to deactivate it. What's with the hassle?

Not everything supports the 2-factor auth. And of course you have to set up specific passwords for those. ONCE! You wont have to do that again. What did you expect? That it magically made everything work? Some people -.- And I have no clue how you managed to mess up your phone… By entering new passwords??

Why can't they just use my "old" password? I don't want to set up 10 new passwords. And yes, I was expecting it to magically work by just enabling it and enter the SMS code. This is too much hassle for something I don't really care about (I don't keep anything of value anywhere online or in my computer/phone).

Re: Please turn on two-factor authentication

#169

Earlier quoted context omitted.

Unless I am mistaken, they won't let you do two-factor auth at all unless you put a phone number first.

I don't think they need a phone number if you use the Google Authenticator app on your phone. The pin for that is generated based on an initial random seed and the current date/time, not your cell number.

They do require it. If you remove it 2-factor-authentication is disabled.

Nothing says that number needs to be your mobile (or one that you have regular access to) but you do need to provide one.

Re: Please turn on two-factor authentication

#170
post #96

Earlier quoted context omitted.

* Edit: Ah, technically they did break into the email account. The first time I read this I thought that they just had access to the account info page (doing things, such as purchasing or accessing account settings, requires password-entry by Amazon) No, they did not have to break into the Amazon account. http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-hona... > First you call Amazon and tell them you are the…

But, as we know, Apple only needs those last four digits. We asked Amazon to comment on its security policy, but didn’t have anything to share by press time. Wow. That's really bad. I mean, it's stupid that Amazon allows that sort of thing (and it sounds like they may be working to fix it). But Apple going off just the last four digits? That's straight up retarded . Why isn't anyone asking about Apple's security poli…

Why is it stupid for Amazon to show the last 4 digits? Let's say I have 3 cards on file. If I want to modify card #2 for some reason (billing address, expiry date) what do I do? Sure, I can look at the other details and take a guess, but we're on HN. On an average, the normal customer would get frustrated.
Post reply on HN