Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

191–200 of 262 posts

Re: Please turn on two-factor authentication

#191
post #168

Earlier quoted context omitted.

Not everything supports the 2-factor auth. And of course you have to set up specific passwords for those. ONCE! You wont have to do that again. What did you expect? That it magically made everything work? Some people -.- And I have no clue how you managed to mess up your phone… By entering new passwords??

Why can't they just use my "old" password? I don't want to set up 10 new passwords. And yes, I was expecting it to magically work by just enabling it and enter the SMS code. This is too much hassle for something I don't really care about (I don't keep anything of value anywhere online or in my computer/phone).

Why? Maybe because that would defeat the whole purpose?

And why use a (relatively, before someone calls me out) high security measure for something unimportant in the first place? You wouldn't use a full biometric security scanner setup for your pantry either, would you?

Re: Please turn on two-factor authentication

#192

Earlier quoted context omitted.

Be honest. When was the last time you were sitting at your (or any other) machine while away from your mobile phone? Also, you only need the authenticator revolving token every 30 days.

What do you mean you only need it every 30 days? You keep the same session active for 30 days?! (And yes, I don't keep my phone next to me when i'm at home. Half the time i'm trying to figure out where the hell I left it)

It will remember that it's authorized across multiple logins/logouts as long as you don't delete the cookie.

Re: Please turn on two-factor authentication

#193

Earlier quoted context omitted.

> Standard American mobile billing is to bill both parties That's the most bizarre thing I've heard in weeks. Honestly, I'm still laughing. BOTH for SMS and voice ?!! God, that's just crazy. No wonder you Americans hate telco companies so much. And I though 0.25 cents (only for outgoing SMSs) that we pay here is absurd.

You pay a different price for calling a landline vs a cellphone? I'm still laughing. That's just crazy.

The reason I find it absolutely crazy is that you can't stop people from sending you messages. You can blacklist them (or use a whitelist) of course, but that's still "after" the offense. What happens if a millionaire prankster sends you 20 messages some day? You have t cough up something because of his prank? I find it unreasonable.

But I don't find paying more for calling a cellphone objectionable. A wireless call requires more resources and money for telco company than a wired one (they put wires in houses decades ago and have forgot about it (the maintenance cost is not huge), but they have to actively setup new towers for different locations in cities and change the old ones). It costs them more, so they charge more and I pay more.

Re: Please turn on two-factor authentication

#194
post #148

Earlier quoted context omitted.

A little less. They can't be combined with the 2nd step verification to make changes to settings that require 2 step verification. So instead of losing access to your account, you just lose all your email (yay!).

This has always been the part I don't like about Google's 2-factor auth. Right now, I have one strong password that would have to be compromised to access my email. If I enable 2-factor, suddenly I have (last time I tried it) about 20 new passwords, any one of which could yield access to my email. That does not really seem more secure.

I think the more important question is whether it is less secure. It does make it harder to seize control of the account (which might be a lame consolation, but backups are a good idea either way), and it is (potentially) more convenient in the event that one device is lost or misplaced.

Someone who previously always logged out might be exposing themselves to more risk by storing the app passwords, but I think that's about the only case where it is worse.

Re: Please turn on two-factor authentication

#195
post #139
post #13

Earlier quoted context omitted.

Buy a cheap used phone and a prepaid card, you should be able to get by just "recharging" 20$ of credit every 6 months or so.

I'm more curious about someone being on Hacker News who doesn't have a cell phone.

Doesn't want a cell phone.

Re: Please turn on two-factor authentication

#196

Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."

I also don't carry a phone, and feel the same way as you about this

Re: Please turn on two-factor authentication

#197
post #149

Earlier quoted context omitted.

I do agree with you on the key analogy but there's a security breach there as well. Most of the keys are generally found on the same keyring. So, in effect it's identical to using a single password.

That's true only to some extent: people keep on their keyring only those keys they need for daily use. Less frequently used keys (e.g., keys to a safety deposit box at the bank, keys to a home safe, keys to a second home) are typically stored in a drawer, a closet, or a safe. Also, note that having different keys means one can give copies of different keys to different persons for different purposes -- e.g., copy of…

On the other hand, typical house locks are (apparently) only locks by way of cultural convention.

(I say apparently because the ease of using things like bump keys is pretty widely publicized but I have never actually tried it myself)

Re: Please turn on two-factor authentication

#198
post #148

Earlier quoted context omitted.

This has always been the part I don't like about Google's 2-factor auth. Right now, I have one strong password that would have to be compromised to access my email. If I enable 2-factor, suddenly I have (last time I tried it) about 20 new passwords, any one of which could yield access to my email. That does not really seem more secure.

I think the more important question is whether it is less secure. It does make it harder to seize control of the account (which might be a lame consolation, but backups are a good idea either way), and it is (potentially) more convenient in the event that one device is lost or misplaced. Someone who previously always logged out might be exposing themselves to more risk by storing the app passwords, but I think that's…

It decreases the severity of a breach but increases the likelihood. Per-app passwords can't be used to take over an account. But they can be used to read my email. I think just shifting the permissions a little so that I can "authenticate" without also giving out the creds to my email would be acceptable.

Re: Please turn on two-factor authentication

#199

Earlier quoted context omitted.

Plus, don't the special passwords for specific apps (that don't use 2-factor auth) violate the whole point of 2-factor in the first place? Now, you've got several passwords that work, instead of 1 and a keyfob. Ugh. Edit: Apparently, you can't log into the web interface with those passwords. That's a step in the right direction, but still not fully secure.

The app-specific passwords are a feature and if you prefer the extra security over being able to use apps that don't support 2-factor, then you can choose not to use them, and get the full security benefits of 2-factor. It's just that, short of expecting every single third-party client app to implement 2-factor authentication or not allowing access to any that don't, there's no alternative to the app-specific passwor…

Non-web apps don't have a UI for two-factor. App-specific password is a compromise, which is vulnerable if someone steals your local installation of the client to get its keys.

Re: Please turn on two-factor authentication

#200
post #76
post #31

I was worried this would be a major pain when I enabled it, but I have to say, it has been much more painless than I thought it would be. Most of the time, I don't even think about it. Most of my consumption of google mail is through clients on my laptops, iPhone, or iPad. So in that sense, it's not much different from a regular password. The difference is that someone else has a much harder time cracking my account.…

If you've spent your career with RSA SecurIDs hanging from your keys, this isn't much of a hassle. I didn't realize that LastPass and others can use the Google Authenticator.

I was just thinking that Google should open their service to others... Makes me think about switching from 1Password to Lastpass...
Post reply on HN