Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

181–190 of 262 posts

Re: Please turn on two-factor authentication

#181

Earlier quoted context omitted.

I used two-factor authentication for about a year, and I just got so sick of it. I had no issue with the whole logging in and using the time-sensitive code from my Android phone. It was the support for all the other Google apps that drove me crazy. I got really tired of needing to generate new temporary passwords for access through iCal, Mail, and I think even sites like StackOverflow. Perhaps I was at a point in lif…

Plus, don't the special passwords for specific apps (that don't use 2-factor auth) violate the whole point of 2-factor in the first place? Now, you've got several passwords that work, instead of 1 and a keyfob. Ugh. Edit: Apparently, you can't log into the web interface with those passwords. That's a step in the right direction, but still not fully secure.

The app-specific passwords are a feature and if you prefer the extra security over being able to use apps that don't support 2-factor, then you can choose not to use them, and get the full security benefits of 2-factor. It's just that, short of expecting every single third-party client app to implement 2-factor authentication or not allowing access to any that don't, there's no alternative to the app-specific passwords.

They are strictly better than using a single password for everything though, in that they are unique and strong (due to being automatically generated and 16 characters long), and easily revocable.

Re: Please turn on two-factor authentication

#183
I use 2FA, but it's an absolutely frustrating experience. Most apps just don't support it. Google Music Manager requires a trip to accounts.google.com for a new App Specific Password every time I restart my computer, whereas Swiftkey just loses its ability to offer suggestions until I manually re-authenticate, which takes several minutes every time it happens, while I wait for an SMS and switch between apps.

Re: Please turn on two-factor authentication

#184
post #18

Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…

I totally agree with this. I have to be careful where I use app-specific passwords. Currently, I only trust the keychain on my Apple devices, and would never store one of these passwords in plaintext.

Re: Please turn on two-factor authentication

#185
post #85

Earlier quoted context omitted.

Yes, can someone explain why Google Chrome doesn't support 2FA on the desktop or iOS? It's bizarre. (Well, I suppose it's tragically normal. I'm sure there is a corporate directive that says every Google service must support 2FA, but Chrome has an exception so they don't need to do it yet.)

Dunno about iOS, but Chrome does on the desktop; it asks you for an application-specific password when you turn on sync.

OK, but it should be asking your for an authenticator code instead. It uses this bizarre "normal password + app specific password" requirement that isn't used anywhere else.

Re: Please turn on two-factor authentication

#186
post #37

I've been avoiding doing this, and I'm not certain the reason is valid - I don't want Google to have my mobile phone number. Perhaps I'm being overly cautious, but the fact Google already collects such a huge amount of data on me, coupled with the increasing insistent requests to enable two-factor with my mobile phone number, has made me not do it. I got so sick of being pestered about it that I stopped using Gmail a…

It's more than a little likely that they already have your number. They have your email address, and chances are that more than a few of your friends have a contact in their google contacts that has that same address alongside your phone number. You could argue that they can't be certain, but aggregated across however many of your friends have those same details stored for you they can make some pretty safe assumptions.

Re: Please turn on two-factor authentication

#187
post #90
post #31

I was worried this would be a major pain when I enabled it, but I have to say, it has been much more painless than I thought it would be. Most of the time, I don't even think about it. Most of my consumption of google mail is through clients on my laptops, iPhone, or iPad. So in that sense, it's not much different from a regular password. The difference is that someone else has a much harder time cracking my account.…

According to Matt (and, apparently, his hacker) you're wrong; two-factor would have saved him in this particular instance: "If I had some other account aside from an Apple e-mail address, or had used two-factor authentication for Gmail, everything would have stopped here." ( http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-hona... ) Naturally, it's not a panacea, but I think a lot of people allow perfect to be…

Agreed, I missed that tidbit. I guess I was focusing on the idea that someone can wipe your iPhone, iPad, and Mac without ever touching your gmail account. As a father of two year old and 4 month old girls, the photos are the part that of the story that I find the most distressing. Everything else is upsetting, but you can rebuild contact lists and things. Those pictures are completely irreplaceable and it is just gut-wrenching for me to think about that.

Re: Please turn on two-factor authentication

#188
post #11

Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."

You can run the Authenticator app on an iPod. But 2-factor does mean there in an expectation you will have to carry some kind of token device.

Yes, but you can only do that _after_ you've set up two factor authentication using SMS.

Re: Please turn on two-factor authentication

#189

I'm really frustrated with Google and this 2-factor authentication. They are in such a great position to really change the way in which people secure themselves and they've completely missed the trick [edit: FOR THE AVERAGE USER]. Google 2-step auth is very hard to use and for how hard it is to use it doesn't provide all that much protection. It protects against phishing (mostly) but not against someone who has your…

I feel your pain, slightly, but isn't the majority of this list caused by the fact that Apple's software stinks? There's no way for apps on iOS to share the account details. You don't need to do any of that junk on Android. And you wouldn't have to do any of it on a Chromebook, either.

You don't have to do it on ios either (assuming your using the built-in mail/calendar/contacts). Ignoring that that OP was setting up multiple unique gmail logins (personal and work), the scenario he outlines requires entering exactly 1 app specific password per gmail account in the "mail, calendar and contacts". I have no idea why he's talking about using them in the browser, normal 2FA works fine there.

Re: Please turn on two-factor authentication

#190

Earlier quoted context omitted.

Standard American mobile billing is to bill both parties, both caller and callee, for both voice and SMS. Contrary to the European practice where caller/sender pays everything. Mostly it's a downside for Americans, but one plus is that it means the caller's fee doesn't vary based on callee: unlike in some European countries (or Skype), calling a landline vs. a mobile phone doesn't charge the caller different rates.

> Standard American mobile billing is to bill both parties That's the most bizarre thing I've heard in weeks. Honestly, I'm still laughing. BOTH for SMS and voice ?!! God, that's just crazy. No wonder you Americans hate telco companies so much. And I though 0.25 cents (only for outgoing SMSs) that we pay here is absurd.

You pay a different price for calling a landline vs a cellphone? I'm still laughing. That's just crazy.
Post reply on HN