Live data from Hacker News

Thoughts on Twitter's new Two-Factor Authentication

blog.authy.com

11–20 of 35 posts

Re: Thoughts on Twitter's new Two-Factor Authentication

#11
post #9

Earlier quoted context omitted.

Maybe they are trying to tell you to stop tweeting about it, put down your phone and enjoy your vacation?

I appreciate the sentiment but let's be real, what problem did they solve exactly?

Twitter? They solved the insecurity and instability in using their previous SMS solution, and they don't hold the key to the second factor of authorization, in the event their systems leak.

Re: Thoughts on Twitter's new Two-Factor Authentication

#12
post #3
post #2

Not sure why there are complaints about it only working when the phone is online. Twitter will only work with a phone online anyway.

It's possible to have computer Internet connectivity in an area with no cell phone reception. I go to a place like that about once a year at least, or so.

Once a year? Store your backup S/KEY under your favorite keyring.

Re: Thoughts on Twitter's new Two-Factor Authentication

#13
post #8

Neither TOTP (Google Authenticator) or Twitter factor in how easy it is to malware/root Android phones these days. I still prefer Yubikey or other opensource cards until the state of mobile security improves (for ex SEAndroid).

This is something I was thinking as well. I've got a Yubikey, and felt like there is a really good use case for a 'trusted' off phone device. I've pitched it a couple of times and the story gets either diverted into the "You can't solve the 'Identity' problem, it's the security equivalent of the halting problem." rat hole or the "Why would anyone care something around in addition to their phone?"

I explain the phone 'rooting' problem and it isn't perceived as a real issue yet (although perhaps it is getting there). In the mean time I have it on my shelf of "things I could build that at least 10 people I know would buy one of." :-)

Re: Thoughts on Twitter's new Two-Factor Authentication

#16
post #8

Neither TOTP (Google Authenticator) or Twitter factor in how easy it is to malware/root Android phones these days. I still prefer Yubikey or other opensource cards until the state of mobile security improves (for ex SEAndroid).

But TOTP != Google Authenticator. The advantage of TOTP is that, as an open standard, it can be implemented by anyone.

For example, here's an hardware token implementing the protocol: https://www.safenet-inc.com/products/data-protection/two-fac...

Re: Thoughts on Twitter's new Two-Factor Authentication

#17
My first experience with the new two-factor auth has been poor.

1. I sign into Twitter with my browser

2. My phone receives a push notification saying that I have a pending auth request.

3. So I click it and load the Twitter iOS app, and I see "You have no login requests" for that account, no matter how much I refresh it (it has been 10 minutes now).

4. Now I can't get into my Twitter account on the browser.

The urge to disable it is certainly strong..

Re: Thoughts on Twitter's new Two-Factor Authentication

#18
post #17

My first experience with the new two-factor auth has been poor. 1. I sign into Twitter with my browser 2. My phone receives a push notification saying that I have a pending auth request. 3. So I click it and load the Twitter iOS app, and I see "You have no login requests" for that account, no matter how much I refresh it (it has been 10 minutes now). 4. Now I can't get into my Twitter account on the browser. The urge…

Did you update to version 5.9 of Twitter for iOS, released 8/6, featuring support for login verification? Maybe the notification should mention that requirement.

Re: Thoughts on Twitter's new Two-Factor Authentication

#19
post #3
post #2

Not sure why there are complaints about it only working when the phone is online. Twitter will only work with a phone online anyway.

It's possible to have computer Internet connectivity in an area with no cell phone reception. I go to a place like that about once a year at least, or so.

I thought his is one of the reasons they have backup keys which you can use when your phone is not reachable. I haven't actually tested the new system though.

Re: Thoughts on Twitter's new Two-Factor Authentication

#20
post #2

Not sure why there are complaints about it only working when the phone is online. Twitter will only work with a phone online anyway.

Not sure why there are complaints about it only working when the phone is online, since you can generate a backup code offline and use that. Your phone does not need internet access once you have set it up.
Post reply on HN