Live data from Hacker News

Twitter said to be testing two-step security in wake of AP hack

crave.cnet.co.uk

21–27 of 27 posts

Re: Twitter said to be testing two-step security in wake of AP hack

#21
post #5

Two factor authentication is a funny thing in 2013. All computer users understand passwords (and the basics of password complexity/secrecy) at this point. That covers the "something you know" factor. Many users conceptually understand a "something you have/are" factor in the form of biometric scans or smartcards. Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting. On t…

How are smartcards not practical outside of a controlled enterprise? The biggest issue I see is that most people do not have smartcard readers, but that could be fixed pretty quickly.

Re: Twitter said to be testing two-step security in wake of AP hack

#22
post #5

Two factor authentication is a funny thing in 2013. All computer users understand passwords (and the basics of password complexity/secrecy) at this point. That covers the "something you know" factor. Many users conceptually understand a "something you have/are" factor in the form of biometric scans or smartcards. Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting. On t…

> Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting.

In what way? Bloomberg uses custom hardware developed in-house (the "B-unit") for four-factor authentication (password, biometric, visual sync, token). These devices are sent to customers all over the world where there is no control over them. All of the device and biometric enrollment is done through the software remotely when the device is received by the end user. So in my experience it is definitely possible to do this outside of the typical employee/enterprise scenario.

Re: Twitter said to be testing two-step security in wake of AP hack

#24
post #5

Two factor authentication is a funny thing in 2013. All computer users understand passwords (and the basics of password complexity/secrecy) at this point. That covers the "something you know" factor. Many users conceptually understand a "something you have/are" factor in the form of biometric scans or smartcards. Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting. On t…

> Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting. In what way? Bloomberg uses custom hardware developed in-house (the "B-unit") for four-factor authentication (password, biometric, visual sync, token). These devices are sent to customers all over the world where there is no control over them. All of the device and biometric enrollment is done through the software r…

I haven't seen the B-unit before, but that is an interesting device.

Re: Twitter said to be testing two-step security in wake of AP hack

#25
post #5

Two factor authentication is a funny thing in 2013. All computer users understand passwords (and the basics of password complexity/secrecy) at this point. That covers the "something you know" factor. Many users conceptually understand a "something you have/are" factor in the form of biometric scans or smartcards. Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting. On t…

How are smartcards not practical outside of a controlled enterprise? The biggest issue I see is that most people do not have smartcard readers, but that could be fixed pretty quickly.

In finland there was an serious attempt to use smart cards for general populace. It didn't pan out mostly because nobody had card readers and it had to compete with OTP based solutions which didn't require extra hardware.

Re: Twitter said to be testing two-step security in wake of AP hack

#26
post #5

Two factor authentication is a funny thing in 2013. All computer users understand passwords (and the basics of password complexity/secrecy) at this point. That covers the "something you know" factor. Many users conceptually understand a "something you have/are" factor in the form of biometric scans or smartcards. Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting. On t…

> Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting. In what way? Bloomberg uses custom hardware developed in-house (the "B-unit") for four-factor authentication (password, biometric, visual sync, token). These devices are sent to customers all over the world where there is no control over them. All of the device and biometric enrollment is done through the software r…

Background on the B-Unit: http://www.bloomberg.com/bunit/Overview_Features.pdf

Definitely an interesting device.

Re: Twitter said to be testing two-step security in wake of AP hack

#27

A few years ago there was a strange byline on a few tweets from @spam, it said "by {username}" indicating that there was some sort of system allowing specific users to send tweets from a different account, here is a screenshot from January 2010: http://i.imgur.com/o0iVS.png Does anyone have any insight on why Twitter haven't implemented that sort of system (nominated accounts able to tweet from a corporate account) a…

This is the "Contributors" feature, which has been tested internally and with a few partners, but has never been widely enabled. It's in the public API, but still disabled for all but internal accounts and those few partners. https://dev.twitter.com/docs/api/1/get/users/contributors

I don't have any current insight into the status of Contributors, and won't speculate, but the feature has been stagnant for almost 3 years now (just like Lists).

Post reply on HN