Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

141–150 of 262 posts

Re: Please turn on two-factor authentication

#141
post #109
post #107

Earlier quoted context omitted.

FTA: You can install a standalone app called Google Authenticator (it’s also available in the App Store), so your cell phone doesn’t need a signal. Also: You can print out a small piece of paper with 10 one-time rescue codes and put that in your wallet. Use those one-time codes to log in even without your phone.

Hm, can you generate new codes whenever you need to? It might be cool to use these 10 at a time as a one-time pad.

Yes, you can revoke those printed codes or issue more whenever you like.

Re: Please turn on two-factor authentication

#142
Well I turned on two-factor authentication and then updated Sparrow (iOS and OS X) with the new password and everything was fine... Until the iOS version constantly kept telling me I had an incorrect password. I tried various troubleshooting tips online but to no avail. Until I can use this with everything I can't use it at all.

Re: Please turn on two-factor authentication

#143

Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."

Did you know it can provide a one-time pad of ten verification codes to print out and store and it will provide another batch on request?

Re: Please turn on two-factor authentication

#144
Two-factor authentication improves security, but cannot solve the online security problem for most people, because the vulnerabilities are primarily CULTURAL: the average person does not understand the risks nor what they could do to ameliorate them.

Compare the attitude towards security that people have in the physical world with their attitude online. No sane person would ever want to use the same exact key to open their home, car, desk, safety deposit box, etc., because that would obviously be unsafe. Yet most people today will happily use the same easy-to-remember password for all online accounts without giving it a second thought.

Similarly, no sane person would ever lend their wallet and keys to a stranger, because that would obviously be unsafe. Yet most people today will happily walk into an Internet cafe or hotel business center and enter all their online credentials without giving it a second thought.

Providers of online services like Google, Amazon, Apple, etc. will find it difficult to solve the security problem until society has evolved its understanding of, and attitude towards, online security.

--

Edit: softened the tone of the last paragraph to make it more accurately reflects my views.

Re: Please turn on two-factor authentication

#145

Earlier quoted context omitted.

How would you reset your password on your Google account Parfe?

> A reset link that gets sent to a secondary account that my phone doesn't have access to with a > unique password stored in a PGP encrypted file with a nice long passphrase only known to me. > My security question has a gibberish answer. How do you think the average person resets their password? I'm not talking about 2-factor auth as it applies to someone who keeps a PGP encrypted file on their machine I'm talking a…

Next time you ask a question don't act like the answer doesn't count just because it doesn't fit your stupid narrative. If you wanted to talk about how you think average people are too stupid to use 2-factor auth then just say it.

Your post is buried and won't harm others. Move on.

Re: Please turn on two-factor authentication

#146
post #144

Two-factor authentication improves security, but cannot solve the online security problem for most people, because the vulnerabilities are primarily CULTURAL: the average person does not understand the risks nor what they could do to ameliorate them. Compare the attitude towards security that people have in the physical world with their attitude online. No sane person would ever want to use the same exact key to open…

I do agree with you on the key analogy but there's a security breach there as well. Most of the keys are generally found on the same keyring. So, in effect it's identical to using a single password.

Re: Please turn on two-factor authentication

#147
post #137

Here's why I don't use two-factor authentication for my Google accounts. It's not worth it. I don't run a business. I'm not a celebrity. I don't keep confidential information in my e-mail. And I don't register all of my various accounts at sites around the web to just one e-mail address. If someone got access to one of my e-mail accounts it would probably be a general-use one, and quite honestly it wouldn't affect me…

Please, please, please, please RTFA before ranting. SMS is not required (you can use the google Authenticator App). The Authenticator app works just like a "plain old token". Separation of accounts means squat if your passwords are intercepted. 2 factor auth requires physical access and reduces the possible pool of attackers from billions to hundreds.

You still need to hunt for phone (on top of that you must have one) to log in...

Re: Please turn on two-factor authentication

#148
post #95

Earlier quoted context omitted.

Do those passwords have less rights? I figured that if any of those passwords got compromised, you were screwed (until you found out which one and revoked it).

A little less. They can't be combined with the 2nd step verification to make changes to settings that require 2 step verification. So instead of losing access to your account, you just lose all your email (yay!).

This has always been the part I don't like about Google's 2-factor auth. Right now, I have one strong password that would have to be compromised to access my email. If I enable 2-factor, suddenly I have (last time I tried it) about 20 new passwords, any one of which could yield access to my email. That does not really seem more secure.

Re: Please turn on two-factor authentication

#149
post #144

Two-factor authentication improves security, but cannot solve the online security problem for most people, because the vulnerabilities are primarily CULTURAL: the average person does not understand the risks nor what they could do to ameliorate them. Compare the attitude towards security that people have in the physical world with their attitude online. No sane person would ever want to use the same exact key to open…

I do agree with you on the key analogy but there's a security breach there as well. Most of the keys are generally found on the same keyring. So, in effect it's identical to using a single password.

That's true only to some extent: people keep on their keyring only those keys they need for daily use. Less frequently used keys (e.g., keys to a safety deposit box at the bank, keys to a home safe, keys to a second home) are typically stored in a drawer, a closet, or a safe.

Also, note that having different keys means one can give copies of different keys to different persons for different purposes -- e.g., copy of the home key to a baby sitter, copy of the desk key to a co-worker, copy of the home key to trusted neighbors.

People today intrinsically understand that they have to be mindful about whom they lend their keys to, who gets copies of their keys, and where the keys are stored.

Re: Please turn on two-factor authentication

#150
post #8

Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."

Yes you are, and I suspect you know this. Even in most third world countries cell-phones are common.

No he isn't. Some people (like me or he) are just not stupid enough to buy a device, which would be used on average only once a month.
Post reply on HN