Live data from Hacker News

Two million Facebook, Gmail and Twitter passwords stolen

money.cnn.com

11–20 of 107 posts

Re: Two million Facebook, Gmail and Twitter passwords stolen

#11
> Facebook, LinkedIn and Twitter told CNNMoney they have notified and reset passwords for compromised users.

> The hackers set up the keylogging software to rout information through a proxy server, so it's impossible to track down which computers are infected.

Have I missed something or are these statements contradictory?

Re: Two million Facebook, Gmail and Twitter passwords stolen

#14
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)

Authentication apps like Google Authenticator or Authy work without any data service of any kind. Most services provide backup codes you can print out and keep in your wallet or another safe spot in case you lose or destroy your device.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#15
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)

With google's 2FA, you can print out codes ahead of time that can each be used once in place of the SMS'd code. Bring some of those with you, perhaps...

Re: Two million Facebook, Gmail and Twitter passwords stolen

#16
post #11

> Facebook, LinkedIn and Twitter told CNNMoney they have notified and reset passwords for compromised users. > The hackers set up the keylogging software to rout information through a proxy server, so it's impossible to track down which computers are infected. Have I missed something or are these statements contradictory?

Nothing contradictory about it. First statement is about accounts on services, second is about finding the machines used to log into said accounts.

The sad part is that many people with this keylogger may react to the password change before/without removing the logger, which would entirely defeat the point.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#17
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)

In google's case, you can print out a set of auth codes for times when you don't have your phone.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#18
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)

2-factor authentication does not require the second factor every time. It typically only asks for the second factor if the device is unrecognized, or the usage pattern is unfamiliar.

So, your laptop that's logged into GMail will stay logged in when you're out of the country. Unless you explicitly log out, it will stay this way.

I enter maybe one two-factor auth code a week, if that.

So:

i) Prepare ahead and log into your services.

ii) Walk to the nearest window, get the code, and go back to your desk.

iii) Replace your phone - you keep your number - request the auth key again.

None of these are completely seamless of course, but the idea is that all of the above happen rarely enough, and are mitigable enough, that it's far better than the alternative: getting pwned.

There are also second factors in the form of mobile apps, which eliminate the need for SMS, so as long as you have data/WiFi you're set. There are also ones that don't need data at all (see: the Battle.net Authenticator, which is basically a RSA key on your phone), but require more substantial initial setup.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#19
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)

With gmail, you get 10 one-time use codes, which you can keep on a small slip of paper. So if you need to register on someone else's computer, you can use one of the codes and cross it off. If you lose the codes but not your device, you can print out new ones.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#20
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)

As far as I know's Google's authenticator app works by using a PRNG being seeded with a unique code for your account that's transferred when you first setup the authenticator and the current time. The app certainly works without a network connection.

AS for theft, you have backup codes which you should store securely (in a Truecrypt file with multiple backups or something), which allow you to log into your account once per code.

Post reply on HN