>Reality: You can tell Google to trust your computer for 30 days and sometimes even longer. How is that "even longer" part supposed to work? I have a desktop Mac that prompt me every 30 days to re-logon to GMail in Safari. Is there a way to add it to the trusted computer list?
Please turn on two-factor authentication
201–210 of 262 posts
Re: Please turn on two-factor authentication
#202I was worried this would be a major pain when I enabled it, but I have to say, it has been much more painless than I thought it would be. Most of the time, I don't even think about it. Most of my consumption of google mail is through clients on my laptops, iPhone, or iPad. So in that sense, it's not much different from a regular password. The difference is that someone else has a much harder time cracking my account.…
I used two-factor authentication for about a year, and I just got so sick of it. I had no issue with the whole logging in and using the time-sensitive code from my Android phone. It was the support for all the other Google apps that drove me crazy. I got really tired of needing to generate new temporary passwords for access through iCal, Mail, and I think even sites like StackOverflow. Perhaps I was at a point in lif…
Two-factor is a pain on iOS devices where every Google app needs it's own unique password and frequently need a new one for every update. Android is a completely different story though and adds almost zero overhead.
Re: Please turn on two-factor authentication
#203Earlier quoted context omitted.
What do you mean you only need it every 30 days? You keep the same session active for 30 days?! (And yes, I don't keep my phone next to me when i'm at home. Half the time i'm trying to figure out where the hell I left it)
It will remember that it's authorized across multiple logins/logouts as long as you don't delete the cookie.
With adaptive authentication, you basically add a series of heuristics based on the browser's request to calculate a number. A ratio applied to that number determines the likelihood that a user is the same as the one who has logged in before. If the ratio is not close enough, challenge questions are asked of the user to verify they are the real user.
The number is cached both on the server side and in the browser. As long as the number stays the same, and the heuristics of the browser's request stay the same, no additional challenge questions are asked upon logging in again. This also times out after a period of time, so eventually the user must be challenged again.
The difference between that and Google's method is the idea that the SMS and/or App are "something you have" instead of an additional "something you know". But since the challenge questions can be anything (including made-up information that is fake and nobody would ever guess - like a second password), there isn't the same risk as with losing a traditional password, and it isn't something an attacker can find out by social engineering or research.
As we've seen before, you can intercept SMS/voice two-factor auth, and Android malware is rampant. But the only way to get a challenge answer is to use lead pipe cryptography or intercept it at the computer - and once they have your computer it's game over. How secure your authentication is comes down to how you implement it.
I will stick with my trusty dumb physical token and challenge questions as that is the most difficult method to attack.
Re: Please turn on two-factor authentication
#204Two-factor authentication improves security, but cannot solve the online security problem for most people, because the vulnerabilities are primarily CULTURAL: the average person does not understand the risks nor what they could do to ameliorate them. Compare the attitude towards security that people have in the physical world with their attitude online. No sane person would ever want to use the same exact key to open…
That said, physical keys are different enough that an analogy breaks down. They're much easier to circumvent (break a window), while their use by a thief is much more impractical (finding the lock and avoiding detection at the location). Criminals in possession of your physical keys will be local (or irrelevant) and limited in numbers. It's easy to get back in your house after a criminal has entered.
Re: Please turn on two-factor authentication
#205Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…
I didn't think Chrome any longer required an ASP?
Re: Please turn on two-factor authentication
#206Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."
Re: Please turn on two-factor authentication
#207Earlier quoted context omitted.
Dunno about iOS, but Chrome does on the desktop; it asks you for an application-specific password when you turn on sync.
OK, but it should be asking your for an authenticator code instead. It uses this bizarre "normal password + app specific password" requirement that isn't used anywhere else.
Re: Please turn on two-factor authentication
#208Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…
> I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup) Maybe you should use throwaway accounts for these purposes? That is, have a gmail account for github to send your patches through, and have that forward to your main email account? In the SMS-backup case...how important is it that you acces…
However, some type of SMS backup is required: if the Android SMS SQLite db is ever even slightly corrupted (power loss/program crash [usually when db is large]/etc.), Android will silently delete it: http://code.google.com/p/android/issues/detail?id=10127
Re: Please turn on two-factor authentication
#209Earlier quoted context omitted.
But, as we know, Apple only needs those last four digits. We asked Amazon to comment on its security policy, but didn’t have anything to share by press time. Wow. That's really bad. I mean, it's stupid that Amazon allows that sort of thing (and it sounds like they may be working to fix it). But Apple going off just the last four digits? That's straight up retarded . Why isn't anyone asking about Apple's security poli…
Why is it stupid for Amazon to show the last 4 digits? Let's say I have 3 cards on file. If I want to modify card #2 for some reason (billing address, expiry date) what do I do? Sure, I can look at the other details and take a guess, but we're on HN. On an average, the normal customer would get frustrated.
I think npsimons was saying that it is stupid for Amazon to let you add a fake cc number and than take over an account using that same fake number. Not that they show the last 4 digits.
Re: Please turn on two-factor authentication
#210Earlier quoted context omitted.
You pay a different price for calling a landline vs a cellphone? I'm still laughing. That's just crazy.
The reason I find it absolutely crazy is that you can't stop people from sending you messages. You can blacklist them (or use a whitelist) of course, but that's still "after" the offense. What happens if a millionaire prankster sends you 20 messages some day? You have t cough up something because of his prank? I find it unreasonable. But I don't find paying more for calling a cellphone objectionable. A wireless call…
I did. I grew weary of paying for text messages that I have no interest in receiving, so I simply called AT&T and told them to turn off SMS entirely. Since 95% of my phone messaging is via iMessage, and the other 5% is via free Google Voice SMS, I'm not giving up anything at all by turning off my carrier's SMS. I'm not interested in giving a single SMS-related penny to the telecom oligopoly.