Live data from Hacker News

Make Your Email Hacker Proof

codinghorror.com

131–140 of 161 posts

Re: Make Your Email Hacker Proof

#131
post #96
post #71

While I like 2 step authentication I wish Google would get rid of SMS password reset. With this enabled all a person needs is your phone to gain access to your account. Given that police can grab you phone whenever you are stopped this means they can "hack" your account at the same time. Another example could be a cleaning person at a hotel finding your phone. Just two examples off the top of my head. Basically, SMS…

As long as you have a pin lock on your phone, the cleaning person nor the police will be able to do anything with your phone.

What about if the phone can be rooted?

Re: Make Your Email Hacker Proof

#132
post #120

Earlier quoted context omitted.

I have three accounts and five computers and I don't find the once-a-month 6-digit number to be a big deal. PayPal does annoy me with their policy of requring an OTP seemingly every time you visit a page, but it's worth it because I know that I don't have to have a super-amazing password to stay safe. Ultimately, the work required to recover from a compromised account is much higher than it is to type a 6-digit numbe…

In my case, the number always seems to expire when my token is far away. So another way of alleviating this would be to have a three day grace period where you're prompted with the option of refreshing your credentials, but you don't have to .

Theoretically, the printed numbers you keep in your wallet can be used until you get your phone back.

Re: Make Your Email Hacker Proof

#133
The article sounds like this requires you to sumbmit a cell number to Gmail. (In fact, I think merely registering an account nowadays requires a number, but I'm not sure about that.)

If you think that's the only way to get 2-factor authentication working, you're wrong. If you think there is nothing wrong with your email provider demanding info like cell phone numbers, you're wrong again.

Re: Make Your Email Hacker Proof

#134
post #99

Earlier quoted context omitted.

Do you really think your shared host drops blocks when you delete them from your virtual disk, and do you really think that requests to mlock memory with crypto keys are really honored? Maybe if you have a dedicated box, but not if you are using a virutal host. (Have you ever physically seen "your own" mail server? If not, why do you trust it?) Also consider what happens to unencrypted email you send or receive: any…

Yow! The ONLY secure server for TOTAL EMAIL SAFETY is an obsolete LAPTOP running in your mother's LIVING ROOM! (Not kidding, I really do that.)

Points for Zippy caps :)

Re: Make Your Email Hacker Proof

#135
post #7

This worry seems a bit overblown to me. If your email is that important to you, you should follow these steps: 1. Use a unique , long, random, secure password. 2. Don't tell it to anyone. 3. Use an email service that stores passwords hashed with a salt and a secure hash algorithm. And you will have nothing to worry about. If you are very paranoid or traveling a lot, you can add: 4. Don't log in from insecure devices.…

You forgot: make sure you can trust every admin who has access to read your mail, and trust that they won't have weak passwords. And all that still won't help you if someone in the federal government want to read your email, because that's literally a one-page request and they'll have it.

Re: Make Your Email Hacker Proof

#136

The article sounds like this requires you to sumbmit a cell number to Gmail. (In fact, I think merely registering an account nowadays requires a number, but I'm not sure about that.) If you think that's the only way to get 2-factor authentication working, you're wrong. If you think there is nothing wrong with your email provider demanding info like cell phone numbers, you're wrong again.

I don't think there is anything wrong with an email provider asking me for my cell number to send me text messages, how else would they send them?

In addition, a cell phone number is NOT required to create a Google account. Sure they ask (and gender is apparently required, I just made an account), but if you leave it blank, they won't complain.

Re: Make Your Email Hacker Proof

#137
post #96
post #71

While I like 2 step authentication I wish Google would get rid of SMS password reset. With this enabled all a person needs is your phone to gain access to your account. Given that police can grab you phone whenever you are stopped this means they can "hack" your account at the same time. Another example could be a cleaning person at a hotel finding your phone. Just two examples off the top of my head. Basically, SMS…

As long as you have a pin lock on your phone, the cleaning person nor the police will be able to do anything with your phone.

It's not that hard for law enforcement to get your PIN. e.g. http://blog.agilebits.com/2012/03/30/the-abcs-of-xry-not-so-...

Re: Make Your Email Hacker Proof

#138
post #55

"print the recovery codes and keep them with you at all times" Wrong. Terribly wrong. Do not do that. You'll have your phone with you AND the codes. So, imagine that day, you get your stuff stolen from your person. Laptop, phone, codes, gone. Bad. That day you were on a boat and you fall in the water. Phone, codes, gone. Bad. Instead store the codes in your own safe, a secret location, or a safe deposit box.

If you can access your email account with only the backup code and no password, Google is doing it wrong.

Re: Make Your Email Hacker Proof

#139
post #2

What happens when you travel abroad and your phone does not work? I am wondering if Gmail could implement security questions to avoid cases where the 2-step verification works against the user

Generally SMS are free to receive even while roaming (for countries where SMS are free to receive, i.e. places that aren't North America)

Re: Make Your Email Hacker Proof

#140
post #120

Earlier quoted context omitted.

In my case, the number always seems to expire when my token is far away. So another way of alleviating this would be to have a three day grace period where you're prompted with the option of refreshing your credentials, but you don't have to .

Theoretically, the printed numbers you keep in your wallet can be used until you get your phone back.

I'm thinking more like, I wake up and want to check my mail from bed, but -- surprise! -- it's expiration day, and my OTP token is downstairs. And using a single recovery code immeditalely invalidates your electronic token, logging you out everywhere and forcing you to go through the activation process all over again before you can log back in.
Post reply on HN