Earlier quoted context omitted.
The ADP -- a payroll service -- passwords (which, interestingly, aren't in the headline), are probably the ones that, despite being smallest in number, offer the most opportunity for direct financial disruption.
ADP is horrible, but their website can't change financial details (it only shows paystubs and tax forms). You can kinda change things through ADP FlexDirect, but all direct deposit enrollment is done elsewhere. The ADP employee site hasn't changed in the past ten years and still uses basic auth. It's horrible. And freaky. When you login to your new company account, it shows all paystubs from your past employers too.…
Two million Facebook, Gmail and Twitter passwords stolen
41–50 of 107 posts
Re: Two million Facebook, Gmail and Twitter passwords stolen
#422 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...
I've always felt like putting all your passwords in one place defeats the purpose of memorizing separate, secure passwords (or, better yet, pass phrases).
Re: Two million Facebook, Gmail and Twitter passwords stolen
#43Earlier quoted context omitted.
Authentication apps like Google Authenticator or Authy work without any data service of any kind. Most services provide backup codes you can print out and keep in your wallet or another safe spot in case you lose or destroy your device.
You can print two copies of your backup codes, keep one in your wallet and one at home. You don't have to worry too much about them getting stolen because they are useless without your password. You can also generate a new set of backup codes at any time, which invalidates the old ones.
Re: Two million Facebook, Gmail and Twitter passwords stolen
#442 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...
I'm with you on 2 factor auth, but I'm not sure about the password manager. I've always felt like putting all your passwords in one place defeats the purpose of memorizing separate, secure passwords (or, better yet, pass phrases).
Re: Two million Facebook, Gmail and Twitter passwords stolen
#45So no details on how to detect if this virus is on your computer?
Re: Two million Facebook, Gmail and Twitter passwords stolen
#46Re: Two million Facebook, Gmail and Twitter passwords stolen
#47Earlier quoted context omitted.
As far as I know's Google's authenticator app works by using a PRNG being seeded with a unique code for your account that's transferred when you first setup the authenticator and the current time. The app certainly works without a network connection. AS for theft, you have backup codes which you should store securely (in a Truecrypt file with multiple backups or something), which allow you to log into your account on…
Why not print them out and put them in your wallet, like Google suggests. It's probably safer.
Re: Two million Facebook, Gmail and Twitter passwords stolen
#482 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...
Re: Two million Facebook, Gmail and Twitter passwords stolen
#492 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...
All the articles I've found are at least a couple months old.
Re: Two million Facebook, Gmail and Twitter passwords stolen
#50Earlier quoted context omitted.
What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)
2-factor authentication does not require the second factor every time. It typically only asks for the second factor if the device is unrecognized, or the usage pattern is unfamiliar. So, your laptop that's logged into GMail will stay logged in when you're out of the country. Unless you explicitly log out, it will stay this way. I enter maybe one two-factor auth code a week, if that. So: i) Prepare ahead and log into…
The Google Authenticator mobile app doesn't require data, so that meets the OP's requirements perfectly (ie, no SMS or data).
Use that, print out the one-time use codes and keep them in your wallet.