Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

211–220 of 262 posts

Re: Please turn on two-factor authentication

#211
post #169

Earlier quoted context omitted.

I don't think they need a phone number if you use the Google Authenticator app on your phone. The pin for that is generated based on an initial random seed and the current date/time, not your cell number.

They do require it. If you remove it 2-factor-authentication is disabled. Nothing says that number needs to be your mobile (or one that you have regular access to) but you do need to provide one.

Does that mean that you could use a Google Voice number? Presumably they already know that one, so "divulging" it shouldn't be an issue. ;^)

Re: Please turn on two-factor authentication

#212
post #183

I use 2FA, but it's an absolutely frustrating experience. Most apps just don't support it. Google Music Manager requires a trip to accounts.google.com for a new App Specific Password every time I restart my computer, whereas Swiftkey just loses its ability to offer suggestions until I manually re-authenticate, which takes several minutes every time it happens, while I wait for an SMS and switch between apps.

Sounds like something is wrong with your computer. I set up Music Manager months ago on two different computers and they have been humming along fine ever since.

Re: Please turn on two-factor authentication

#213
post #17

Two-factor auth gets old really fast when you have to use public computers in a setting like a college library. I had turned it on for a while, but turned it off when I had 5 minutes to print out a paper that I had emailed myself (yes, I still do that) and was fiddling with my phone to get the damn PIN. Never again.

Maybe it's just me but I only trust computers I control. If you don't have root on a box, consider it pwn3d with keyloggers listening to every juicy password you type. Take that as your friend's laptop, a library computer or even your parent's Windows XP box... Trust no one, Mr. Mulder. /tinfoilhat

You trust computers you control? That's so cute.

http://cm.bell-labs.com/who/ken/trust.html

Re: Please turn on two-factor authentication

#214
post #137

Here's why I don't use two-factor authentication for my Google accounts. It's not worth it. I don't run a business. I'm not a celebrity. I don't keep confidential information in my e-mail. And I don't register all of my various accounts at sites around the web to just one e-mail address. If someone got access to one of my e-mail accounts it would probably be a general-use one, and quite honestly it wouldn't affect me…

Please, please, please, please RTFA before ranting. SMS is not required (you can use the google Authenticator App). The Authenticator app works just like a "plain old token". Separation of accounts means squat if your passwords are intercepted. 2 factor auth requires physical access and reduces the possible pool of attackers from billions to hundreds.

Actually, neither of Google's methods require physical access, it's just easier if you have physical access.

SMS is just not secure. That's a general fact (it's not encrypted, it travels over many networks in the clear, phones can be cloned, google voice can be intercepted, and then there's alternative methods like this: http://williamedwardscoder.tumblr.com/post/24949768311/i-kno...). But then there's the App.

The App runs on a smartphone. Smartphones are computers. Computers run in software, and are subject to two flaws: network access and software bugs. Consequently, if you download the wrong app from the App Store, you could be installing a rootkit which can control your entire phone - including spying on your Authenticator App. Like i've mentioned elsewhere here, these rootkits have existed for years, and often it doesn't even take installing an App - plenty of exploits have been found in mobile browsers and other apps, not to mention the possibility of exploiting the OTA upgrade features many vendors and carriers build in.

A plain old hardware token is not vulnerable to network or software attacks. You have to physically steal it or read its display in a narrow window of time to circumvent it. The only ones for Google (that I know of) require a complicated tutorial set-up or a device plugged into the computer, and like I mentioned before, it's not worth it for me to do either.

Separation of accounts means squat if your passwords are intercepted

Uh, no. The whole point of separation of accounts is different passwords, so one intercepted doesn't compromise them all. Separation of accounts is incredibly important.

Re: Please turn on two-factor authentication

#215

Earlier quoted context omitted.

OK, but it should be asking your for an authenticator code instead. It uses this bizarre "normal password + app specific password" requirement that isn't used anywhere else.

Your data is encrypted with the normal password, so it needs it to decrypt the sync data. The App-specific password is used to log in to the server to GET the sync data in the first place.

So again, why not have the authenticator instead of the app password?

Re: Please turn on two-factor authentication

#216
post #90

Earlier quoted context omitted.

According to Matt (and, apparently, his hacker) you're wrong; two-factor would have saved him in this particular instance: "If I had some other account aside from an Apple e-mail address, or had used two-factor authentication for Gmail, everything would have stopped here." ( http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-hona... ) Naturally, it's not a panacea, but I think a lot of people allow perfect to be…

Agreed, I missed that tidbit. I guess I was focusing on the idea that someone can wipe your iPhone, iPad, and Mac without ever touching your gmail account. As a father of two year old and 4 month old girls, the photos are the part that of the story that I find the most distressing. Everything else is upsetting, but you can rebuild contact lists and things. Those pictures are completely irreplaceable and it is just gu…

That is terrible. Though, I don't understand why anyone would turn on a "find my Mac" feature that has the potential to wipe your entire hard drive remotely unless you have thorough backups. Time machine is dead easy to use; try pluging in a usb hard drive and it will ask you if you want to use this as a backup drive. Arc is something that anyone on the mac should use as well for backing up priceless pictures and files. It encrypts the files locally and then sends them to your amazon S3 bucket as a backup. Easy and cheap too as you are only charged what you backup at the S3 rate(as of now it's ~0.125/GB/Month +a very small amount for put and get requests).

Re: Please turn on two-factor authentication

#217
post #118

Earlier quoted context omitted.

> So your fancy two factor authentication still ends up resting on one piece of secret info as the weak point. Am I missing something? Yes: that email password cannot be used to change your password, cancel your account, etc. and can be revoked easily without breaking anything else. This also means that you're not entering the password which can do all of those things on a daily basis, further reducing the odds of so…

>This also means that you're not entering the password which can do all of those things on a daily basis, Before two-factor, were you really typing in your GMail password on a daily basis? I mean, I certainly don't deny that two-factor is much safer if you can actually use it, like on the GMail site. I just worry about the big holes that application passwords punch in that wall. All it takes is one application sendin…

Exactly. Let me know if you find an answer to this.

I have a policy where I will only add a generated application-specific password to really trusted applications (internal OS apps mail, calendar etc), and have gone as far as to sniff all traffic for each of these apps.

Re: Please turn on two-factor authentication

#218

I hear a lot of people advising to turn on two factor auth on Google because of this incident, but I haven't heard anyone say that we should be deleting our card details from Amazon. Well, I have, and you should too. Lots of places use the last 4 digits of your card as "authentication", and Amazon happily displays those details in your account.

Deleting your card details from amazon does nothing since they happily display the last 4 digits in your invoice history anyways.

Re: Please turn on two-factor authentication

#219
is there an authenticator that can run on my computer? i see an android app - is there something similar that can run on linux?

or does that defeat the purpose because it's not going to be a push notification? (if so, anyway to fix that?).

i'm not normally mobile. if i am travelling and need gmail, i will have my laptop. i don't have a smartphone and my dumbphone won't work abroad.

EDIT2: oops. ignore previous edit. that was using Google to connect to linux. Not vice-versa.

Re: Please turn on two-factor authentication

#220
All this talk about security and multiple authentication levels yet, your browser --if you use Chrome-- is the worst security leak in a persons digital life. It would take almost anyone a minute in front of a computer to fire-up Chrome and have every single login and password available in plain text.

I've written about this before and so have countless of other techies. A non-techie has not a single clue, making them perfect victims. Any number of scenarios can be imagined: From taking your laptop in for repairs/upgrades to someone gaining physical access to your machine for just a few minutes. And, just like that, your digital life is turned upside-down.

Post reply on HN