Live data from Hacker News

When two-factor authentication is not enough

blog.fastmail.fm

1–10 of 57 posts

Re: When two-factor authentication is not enough

#5
It's interesting how there are people who think spending $100/year/domain is a lot of money - but when your entire company's business/value is on the line, I would think that spending $1,000/year/domain, to make absolutely sure nothing goes wrong, would be a bargain.

It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything is done correctly, with lots of extra human review (in addition to all of the automated safety checks, not instead of)

I've heard good things about https://www.markmonitor.com/ when it comes to managing domains (among other things)

Re: When two-factor authentication is not enough

#6

It's interesting how there are people who think spending $100/year/domain is a lot of money - but when your entire company's business/value is on the line, I would think that spending $1,000/year/domain, to make absolutely sure nothing goes wrong, would be a bargain. It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything…

I've heard this claim made repeatedly on this site, but I've not heard any details as to what specifically MarkMonitor does to protect domains above and beyond other registrars. Anyone care to chime in?

Re: When two-factor authentication is not enough

#7
post #3

This article really should have been called "Security hole in Gandi's processes". Why would they change the account email address if you didn't reply to a single email within 24 hours? Who thought that was a good solution?

A possible reason was called out in the article:

"Gandi’s paper 'email reset' form makes a lot of sense in the world where most of their customers are individuals or small businesses with one or two domains, and using addresses that they may lose access to. With no other factors, if they lose access to the email address and forget their password, there needs to be a process to regain access."

If a customer loses access to the one e-mail registered with GANDI (a small business signs up with their Earthlink.net address, moves, and now only has a Comcast.com address), there needs to be a way that allows an e-mail change without requiring positive confirmation from the old address. Having GANDI change process to disallow this when an account is 2FA-enabled is, to me, a reasonable compromise.

Re: When two-factor authentication is not enough

#8
post #3

This article really should have been called "Security hole in Gandi's processes". Why would they change the account email address if you didn't reply to a single email within 24 hours? Who thought that was a good solution?

Hence the "bolting a new security item onto an existing process" part. Without 2FA, the common case is that you've lost the password and access to the listed email address... so waiting any longer would just mean more time without access.

Re: When two-factor authentication is not enough

#9

It's interesting how there are people who think spending $100/year/domain is a lot of money - but when your entire company's business/value is on the line, I would think that spending $1,000/year/domain, to make absolutely sure nothing goes wrong, would be a bargain. It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything…

Well, we are paying for Gandi's corporate level of support.

Funnily enough, we feel the same way about people who don't want to pay $20/year for their email address, given that it's the primary method of identifying yourself online.

As with any business expense though, you only want to pay for value - if you spend $1000/year for exactly what you could have got for $100 year, that's wasting money.

And we're satisfied that Gandi know us now! Overall they've been really good - they just missed this one thing when they added 2FA. I bet they're not the only site.

Re: When two-factor authentication is not enough

#10

It's interesting how there are people who think spending $100/year/domain is a lot of money - but when your entire company's business/value is on the line, I would think that spending $1,000/year/domain, to make absolutely sure nothing goes wrong, would be a bargain. It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything…

I've heard this claim made repeatedly on this site, but I've not heard any details as to what specifically MarkMonitor does to protect domains above and beyond other registrars. Anyone care to chime in?

I realize it's an appeal to authority, but if there is one company that would have a lot to lose if its domain was ever exploited, it's google.

http://reports.internic.net/cgi/whois?whois_nic=google.com&t...

Post reply on HN