Earlier quoted context omitted.
I don't think they need a phone number if you use the Google Authenticator app on your phone. The pin for that is generated based on an initial random seed and the current date/time, not your cell number.
They do require it. If you remove it 2-factor-authentication is disabled. Nothing says that number needs to be your mobile (or one that you have regular access to) but you do need to provide one.
Please turn on two-factor authentication
211–220 of 262 posts
Re: Please turn on two-factor authentication
#212I use 2FA, but it's an absolutely frustrating experience. Most apps just don't support it. Google Music Manager requires a trip to accounts.google.com for a new App Specific Password every time I restart my computer, whereas Swiftkey just loses its ability to offer suggestions until I manually re-authenticate, which takes several minutes every time it happens, while I wait for an SMS and switch between apps.
Re: Please turn on two-factor authentication
#213Two-factor auth gets old really fast when you have to use public computers in a setting like a college library. I had turned it on for a while, but turned it off when I had 5 minutes to print out a paper that I had emailed myself (yes, I still do that) and was fiddling with my phone to get the damn PIN. Never again.
Maybe it's just me but I only trust computers I control. If you don't have root on a box, consider it pwn3d with keyloggers listening to every juicy password you type. Take that as your friend's laptop, a library computer or even your parent's Windows XP box... Trust no one, Mr. Mulder. /tinfoilhat
Re: Please turn on two-factor authentication
#214Here's why I don't use two-factor authentication for my Google accounts. It's not worth it. I don't run a business. I'm not a celebrity. I don't keep confidential information in my e-mail. And I don't register all of my various accounts at sites around the web to just one e-mail address. If someone got access to one of my e-mail accounts it would probably be a general-use one, and quite honestly it wouldn't affect me…
Please, please, please, please RTFA before ranting. SMS is not required (you can use the google Authenticator App). The Authenticator app works just like a "plain old token". Separation of accounts means squat if your passwords are intercepted. 2 factor auth requires physical access and reduces the possible pool of attackers from billions to hundreds.
SMS is just not secure. That's a general fact (it's not encrypted, it travels over many networks in the clear, phones can be cloned, google voice can be intercepted, and then there's alternative methods like this: http://williamedwardscoder.tumblr.com/post/24949768311/i-kno...). But then there's the App.
The App runs on a smartphone. Smartphones are computers. Computers run in software, and are subject to two flaws: network access and software bugs. Consequently, if you download the wrong app from the App Store, you could be installing a rootkit which can control your entire phone - including spying on your Authenticator App. Like i've mentioned elsewhere here, these rootkits have existed for years, and often it doesn't even take installing an App - plenty of exploits have been found in mobile browsers and other apps, not to mention the possibility of exploiting the OTA upgrade features many vendors and carriers build in.
A plain old hardware token is not vulnerable to network or software attacks. You have to physically steal it or read its display in a narrow window of time to circumvent it. The only ones for Google (that I know of) require a complicated tutorial set-up or a device plugged into the computer, and like I mentioned before, it's not worth it for me to do either.
Separation of accounts means squat if your passwords are intercepted
Uh, no. The whole point of separation of accounts is different passwords, so one intercepted doesn't compromise them all. Separation of accounts is incredibly important.
Re: Please turn on two-factor authentication
#215Earlier quoted context omitted.
OK, but it should be asking your for an authenticator code instead. It uses this bizarre "normal password + app specific password" requirement that isn't used anywhere else.
Your data is encrypted with the normal password, so it needs it to decrypt the sync data. The App-specific password is used to log in to the server to GET the sync data in the first place.
Re: Please turn on two-factor authentication
#216Earlier quoted context omitted.
According to Matt (and, apparently, his hacker) you're wrong; two-factor would have saved him in this particular instance: "If I had some other account aside from an Apple e-mail address, or had used two-factor authentication for Gmail, everything would have stopped here." ( http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-hona... ) Naturally, it's not a panacea, but I think a lot of people allow perfect to be…
Agreed, I missed that tidbit. I guess I was focusing on the idea that someone can wipe your iPhone, iPad, and Mac without ever touching your gmail account. As a father of two year old and 4 month old girls, the photos are the part that of the story that I find the most distressing. Everything else is upsetting, but you can rebuild contact lists and things. Those pictures are completely irreplaceable and it is just gu…
Re: Please turn on two-factor authentication
#217Earlier quoted context omitted.
> So your fancy two factor authentication still ends up resting on one piece of secret info as the weak point. Am I missing something? Yes: that email password cannot be used to change your password, cancel your account, etc. and can be revoked easily without breaking anything else. This also means that you're not entering the password which can do all of those things on a daily basis, further reducing the odds of so…
>This also means that you're not entering the password which can do all of those things on a daily basis, Before two-factor, were you really typing in your GMail password on a daily basis? I mean, I certainly don't deny that two-factor is much safer if you can actually use it, like on the GMail site. I just worry about the big holes that application passwords punch in that wall. All it takes is one application sendin…
I have a policy where I will only add a generated application-specific password to really trusted applications (internal OS apps mail, calendar etc), and have gone as far as to sniff all traffic for each of these apps.
Re: Please turn on two-factor authentication
#218I hear a lot of people advising to turn on two factor auth on Google because of this incident, but I haven't heard anyone say that we should be deleting our card details from Amazon. Well, I have, and you should too. Lots of places use the last 4 digits of your card as "authentication", and Amazon happily displays those details in your account.
Re: Please turn on two-factor authentication
#219or does that defeat the purpose because it's not going to be a push notification? (if so, anyway to fix that?).
i'm not normally mobile. if i am travelling and need gmail, i will have my laptop. i don't have a smartphone and my dumbphone won't work abroad.
EDIT2: oops. ignore previous edit. that was using Google to connect to linux. Not vice-versa.
Re: Please turn on two-factor authentication
#220I've written about this before and so have countless of other techies. A non-techie has not a single clue, making them perfect victims. Any number of scenarios can be imagined: From taking your laptop in for repairs/upgrades to someone gaining physical access to your machine for just a few minutes. And, just like that, your digital life is turned upside-down.