Live data from Hacker News

Two million Facebook, Gmail and Twitter passwords stolen

money.cnn.com

91–100 of 107 posts

Re: Two million Facebook, Gmail and Twitter passwords stolen

#91
post #62

Earlier quoted context omitted.

But I heard FTP was declared harmful and phased out in 1970?

Tell that to my wordpress projects....

You can. Put this line in the config file:

define( 'FS_METHOD', 'direct');

Re: Two million Facebook, Gmail and Twitter passwords stolen

#92
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I enabled 2 Factor Authentication some time ago and know I am much more secure now.

As for password managers, I think it would be cool if the browser &/or websites could figure out a way to launch a default password manager installed on the computer (or in the cloud?) and auto-populate a strong password and enter it into the manger. Way more people would use best practices if they were virtually automatic.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#96
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I don't care for two-factor authentication because I use a password manager. What I'd like is the option to use a one-time-password when I'm sitting at a computer I don't trust.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#97
post #96
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I don't care for two-factor authentication because I use a password manager. What I'd like is the option to use a one-time-password when I'm sitting at a computer I don't trust.

Two-factor authentication might partially be the answer to that. You still provide your own password, except that a second password is generated when you request to be logged in. At least that how I think it works.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#98
post #96
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I don't care for two-factor authentication because I use a password manager. What I'd like is the option to use a one-time-password when I'm sitting at a computer I don't trust.

That would be much more useful. My password is strong enough, but I would never use an computer other than my own to log into Gmail or any other important account. One-time passwords would be a good thing to have.

Maybe possible with 2-factor-auth, but it would still require me to input my password on an untrusted device. No.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#100
post #96
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I don't care for two-factor authentication because I use a password manager. What I'd like is the option to use a one-time-password when I'm sitting at a computer I don't trust.

So if I understand this, this is how it would work.

At any time you'd have two passwords: one regular, which you use every day; and one for one-time-use only, which you keep around in case of need.

When sitting at an untrusted computer, you use your one-time-use password. This proves your identity, but also immediately expires your one-time-use password. Next time you want to generate a usable one-time-password you'll have to login with your regular password again.

Is that it?

Post reply on HN