Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

101–110 of 262 posts

Re: Please turn on two-factor authentication

#101
post #54

really surprised so many people that post here refuse to use google authenticator because its "annoying." is it a hassle? yes, but if you have ever had your email (and other accounts) compromised you understand why it is worth that small 5 second hassle when you login. one feature that i cannot understand why it hasnt been implemented though is protecting the app itself with a password or pin. some people say to just…

It's not a 5 second hassle. I don't get a cell signal in the steel gymnasium even though the wifi works fine. I physically have to go outside to get a code every time I want to log in. And then if my phone is not working, or I leave it at home, I'm screwed.

Re: Please turn on two-factor authentication

#102

Earlier quoted context omitted.

It is standard to pay for receiving as well as sending SMS in the US. Everybody knows this is insane.

It's not at all standard on smartphones though. Almost all data plans include at least several hundred texts per month.

Not on AT&T, as far as I can tell. It's either $20/month for unlimited messaging, or $0.20 each. So, unless you're sending or receiving more than 100 messages a month, you're better off without a plan.

Re: Please turn on two-factor authentication

#103
post #80

Earlier quoted context omitted.

> Why not Nigeria? Can Nigerians use the Google Authenticator app? If yes, then the answer is probably high SMS costs.

High SMS costs? It is exactly why I put the range of countries above. Can we be in a worse situation than them all?

Then why? Lack of demand? Market not interested? Support costs too high?

Re: Please turn on two-factor authentication

#104
post #95

Earlier quoted context omitted.

For the second factor to mean anything, all the apps that don't support it need a password that has less rights. Hopefully they figure out a nice way to make the rights more granular (so that a chat app can't mess with email or whatever).

Do those passwords have less rights? I figured that if any of those passwords got compromised, you were screwed (until you found out which one and revoked it).

A little less. They can't be combined with the 2nd step verification to make changes to settings that require 2 step verification.

So instead of losing access to your account, you just lose all your email (yay!).

Re: Please turn on two-factor authentication

#105
post #14

Earlier quoted context omitted.

Still, if I plan to use Google Authenticator, I don't want to give Google my phone number at all. When they insist to get the phone number from me, I don't like it.

I don't think you need to get them a phone number. I use Google Authenticator app on my iPhone, and didn't give them anything. It just scanned a barcode on a webpage IIRC.

How do you get 2-factor auth enabled at all without entering a phone number? Their help page says that you can switch from phone-based to Google-Authenticator-based authentication after enabling 2fa, but I can't find a way to skip the phone step for turning it on in the first place. This is the screen I get when I click to enable: http://i.imgur.com/cm6Km.png

Re: Please turn on two-factor authentication

#106
post #97

OK, so I turn on two-factor authentication for GMail, but... 1) I immediately have to create a application specific password to actually read my mail on my iPhone. 2) If anyone ever gets access to that secret password, or any of the others I create, they have full access to my email and any password resets they generate. 3) I will have no idea this is happening since I would expect my mail to access that app password…

You only type that application specific password once. You're not typing it to log in via wifi at coffee shops, airports, etc. You're not typing it every day for a keylogger to pick up, should your machine be compromised in the future. You're not typing it into borrowed machines or net cafe machines in some hotel business center.

So, no, it isn't perfect, but it's a heck of an improvement. That is, if you believe your machine to be reasonably secure on day 1.

Re: Please turn on two-factor authentication

#107
post #101
post #54

really surprised so many people that post here refuse to use google authenticator because its "annoying." is it a hassle? yes, but if you have ever had your email (and other accounts) compromised you understand why it is worth that small 5 second hassle when you login. one feature that i cannot understand why it hasnt been implemented though is protecting the app itself with a password or pin. some people say to just…

It's not a 5 second hassle. I don't get a cell signal in the steel gymnasium even though the wifi works fine. I physically have to go outside to get a code every time I want to log in. And then if my phone is not working, or I leave it at home, I'm screwed.

FTA:

You can install a standalone app called Google Authenticator (it’s also available in the App Store), so your cell phone doesn’t need a signal.

Also:

You can print out a small piece of paper with 10 one-time rescue codes and put that in your wallet. Use those one-time codes to log in even without your phone.

Re: Please turn on two-factor authentication

#108
post #97

OK, so I turn on two-factor authentication for GMail, but... 1) I immediately have to create a application specific password to actually read my mail on my iPhone. 2) If anyone ever gets access to that secret password, or any of the others I create, they have full access to my email and any password resets they generate. 3) I will have no idea this is happening since I would expect my mail to access that app password…

> So your fancy two factor authentication still ends up resting on one piece of secret info as the weak point. Am I missing something?

A vastly reduced, easily managed attack surface area that in practice results in overwhelmingly fewer account compromises.

Re: Please turn on two-factor authentication

#109
post #107
post #101

Earlier quoted context omitted.

It's not a 5 second hassle. I don't get a cell signal in the steel gymnasium even though the wifi works fine. I physically have to go outside to get a code every time I want to log in. And then if my phone is not working, or I leave it at home, I'm screwed.

FTA: You can install a standalone app called Google Authenticator (it’s also available in the App Store), so your cell phone doesn’t need a signal. Also: You can print out a small piece of paper with 10 one-time rescue codes and put that in your wallet. Use those one-time codes to log in even without your phone.

Hm, can you generate new codes whenever you need to? It might be cool to use these 10 at a time as a one-time pad.

Re: Please turn on two-factor authentication

#110
post #101
post #54

really surprised so many people that post here refuse to use google authenticator because its "annoying." is it a hassle? yes, but if you have ever had your email (and other accounts) compromised you understand why it is worth that small 5 second hassle when you login. one feature that i cannot understand why it hasnt been implemented though is protecting the app itself with a password or pin. some people say to just…

It's not a 5 second hassle. I don't get a cell signal in the steel gymnasium even though the wifi works fine. I physically have to go outside to get a code every time I want to log in. And then if my phone is not working, or I leave it at home, I'm screwed.

That's a fairly special case though right? The most common concern I hear (other than it's just too complicated) is privacy concerns. People are asking "why does Google want my cell"? What else is that number used for?
Post reply on HN