Live data from Hacker News

Two million Facebook, Gmail and Twitter passwords stolen

money.cnn.com

41–50 of 107 posts

Re: Two million Facebook, Gmail and Twitter passwords stolen

#41
post #35

Earlier quoted context omitted.

The ADP -- a payroll service -- passwords (which, interestingly, aren't in the headline), are probably the ones that, despite being smallest in number, offer the most opportunity for direct financial disruption.

ADP is horrible, but their website can't change financial details (it only shows paystubs and tax forms). You can kinda change things through ADP FlexDirect, but all direct deposit enrollment is done elsewhere. The ADP employee site hasn't changed in the past ten years and still uses basic auth. It's horrible. And freaky. When you login to your new company account, it shows all paystubs from your past employers too.…

Does anyone know if this is actually the case? I have noticed something similar and I am curious about it. My new employer uses ADP for payroll, but does not use the online system. However I can still log in to the ADP online system using my account credentials from my old employer and get electronic copies of my new paystubs. I would like to know if my old employer has access to these paystubs.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#42
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I'm with you on 2 factor auth, but I'm not sure about the password manager.

I've always felt like putting all your passwords in one place defeats the purpose of memorizing separate, secure passwords (or, better yet, pass phrases).

Re: Two million Facebook, Gmail and Twitter passwords stolen

#43

Earlier quoted context omitted.

Authentication apps like Google Authenticator or Authy work without any data service of any kind. Most services provide backup codes you can print out and keep in your wallet or another safe spot in case you lose or destroy your device.

You can print two copies of your backup codes, keep one in your wallet and one at home. You don't have to worry too much about them getting stolen because they are useless without your password. You can also generate a new set of backup codes at any time, which invalidates the old ones.

[deleted]

Re: Two million Facebook, Gmail and Twitter passwords stolen

#44
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I'm with you on 2 factor auth, but I'm not sure about the password manager. I've always felt like putting all your passwords in one place defeats the purpose of memorizing separate, secure passwords (or, better yet, pass phrases).

The purpose of separate, secure passwords is because otherwise all it takes is 1 website out there to be insecure to compromise all your logins. If your computer is compromised you already lost, regardless of whether you use a password manager or not.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#46
Not as safe as other solutions, but I can remember all my passwords by choosing passwords by website category (6 for example): one low-security sites, one for sites that have your CC #, one for social networking, one for email, one for work, and one for your banking sites. keep a copy in your wallet. Sleep better.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#47
post #20

Earlier quoted context omitted.

As far as I know's Google's authenticator app works by using a PRNG being seeded with a unique code for your account that's transferred when you first setup the authenticator and the current time. The app certainly works without a network connection. AS for theft, you have backup codes which you should store securely (in a Truecrypt file with multiple backups or something), which allow you to log into your account on…

Why not print them out and put them in your wallet, like Google suggests. It's probably safer.

my solution is to have them in an encrypted evernote note

Re: Two million Facebook, Gmail and Twitter passwords stolen

#48
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

For those who are curious, information for Google's 2-step verification process can be found here:

http://www.google.com/landing/2step

Re: Two million Facebook, Gmail and Twitter passwords stolen

#49
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

Does anyone maintain a list of sites/services that support two factor auth? I'd like to be able to go through a list and make sure I have it enabled for all services where I have an account.

All the articles I've found are at least a couple months old.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#50

Earlier quoted context omitted.

What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)

2-factor authentication does not require the second factor every time. It typically only asks for the second factor if the device is unrecognized, or the usage pattern is unfamiliar. So, your laptop that's logged into GMail will stay logged in when you're out of the country. Unless you explicitly log out, it will stay this way. I enter maybe one two-factor auth code a week, if that. So: i) Prepare ahead and log into…

This advice isn't incorrect, but it isn't entirely accurate either.

The Google Authenticator mobile app doesn't require data, so that meets the OP's requirements perfectly (ie, no SMS or data).

Use that, print out the one-time use codes and keep them in your wallet.

Post reply on HN