Live data from Hacker News

Two million Facebook, Gmail and Twitter passwords stolen

money.cnn.com

21–30 of 107 posts

Re: Two million Facebook, Gmail and Twitter passwords stolen

#24
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

Yup, exactly why I made https://GAuthify.com, keep it standard via Google Authenticator and allow other options like SMS, Voice and Email. If you want to add it to your app and can't afford it, shoot support and email and I'll try to set you up with a discount/free-er account.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#26
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)

When you are activating 2-factor authentication it gives you around 10 codes that you need to write down or print, to a wallet or under your freezer ets. However in university when I sit to a computer everytime I have to open a new clean Windows session, it leads me to enter 2-factor 4-5 a day. Thus I don't use it.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#27

Earlier quoted context omitted.

What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)

Authentication apps like Google Authenticator or Authy work without any data service of any kind. Most services provide backup codes you can print out and keep in your wallet or another safe spot in case you lose or destroy your device.

You can print two copies of your backup codes, keep one in your wallet and one at home. You don't have to worry too much about them getting stolen because they are useless without your password. You can also generate a new set of backup codes at any time, which invalidates the old ones.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#28
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I had twitter's 2 factor auth set up. Guess what? I was once logged out and couldn't login again. It just stopped working. I enter the code I receive over SMS and I go back to the login screen. I tweeted to @twitter from a signed in device and tried to get help for days. No response. Finally ended up dis-associating my phone number from twitter via an SMS and haven't gone back to 2-factor auth again.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#30
post #20

Earlier quoted context omitted.

What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)

As far as I know's Google's authenticator app works by using a PRNG being seeded with a unique code for your account that's transferred when you first setup the authenticator and the current time. The app certainly works without a network connection. AS for theft, you have backup codes which you should store securely (in a Truecrypt file with multiple backups or something), which allow you to log into your account on…

Why not print them out and put them in your wallet, like Google suggests. It's probably safer.
Post reply on HN