Live data from Hacker News

Thoughts on Twitter's new Two-Factor Authentication

blog.authy.com

21–30 of 35 posts

Re: Thoughts on Twitter's new Two-Factor Authentication

#21

For anyone who is interested in implementing two-factor authentication, Authy (company behind blog post) is quite easy to use. I recommend it.

They suffer from the "click company logo after reading their blog and it takes you to their blog" syndrome.

Re: Thoughts on Twitter's new Two-Factor Authentication

#22

For anyone who is interested in implementing two-factor authentication, Authy (company behind blog post) is quite easy to use. I recommend it.

They suffer from the "click company logo after reading their blog and it takes you to their blog" syndrome.

There appears to be a (badly titled) menu item that takes you to the company site, but it's hidden beneath the "hamburger" icon, which inexplicably appears even when the web page is full-screen on my laptop but is replaced by real menus at small screen sizes.

Puzzling.

Re: Thoughts on Twitter's new Two-Factor Authentication

#23
Not a tremendously compelling argument, and I think the company may come to regret the know-it-all tone of the post. Hubris is not what you want in a security platform company.

The author cites two "flaws":

1. Your phone is offline sometimes.

Twitter has a backup code mechanism that covers this case. They talk about it, right in the post.

2. An attacker can send verification requests that look exactly like yours.

The sole use case for this mechanism is to verify login attempts by the phone's owner in real-time. If a verification request comes in and you're not actually trying to log into Twitter, or if you see more than one, you know you're being attacked.

It's true if you share a login among multiple coworkers then you're vulnerable to being tricked. But that's a bad practice to begin with, and this 2-factor system is still a massive improvement in security even for that scenario.

Re: Thoughts on Twitter's new Two-Factor Authentication

#24
I know Twitter did this (primarily) in response to the AP hacking, but I fail to see how this change is going to help organizations (say...news) with multiple people sharing an account for business purposes.

We want to secure with 2 factor here in our offices, but it involves giving 10 people the app and possibly getting spammed every time someone logs in. I realize they went for this approach rather than have your average user type in numbers but I can't help but feel confused by this move.

Re: Thoughts on Twitter's new Two-Factor Authentication

#25
post #17

My first experience with the new two-factor auth has been poor. 1. I sign into Twitter with my browser 2. My phone receives a push notification saying that I have a pending auth request. 3. So I click it and load the Twitter iOS app, and I see "You have no login requests" for that account, no matter how much I refresh it (it has been 10 minutes now). 4. Now I can't get into my Twitter account on the browser. The urge…

Did you update to version 5.9 of Twitter for iOS, released 8/6, featuring support for login verification? Maybe the notification should mention that requirement.

Yep.. As I said, I can see the "Login Requests" page for that account and it says "No Pending Login Requests".. Plus I had to use the iOS app to set up and enable two-factor auth in the first place.

Re: Thoughts on Twitter's new Two-Factor Authentication

#27
post #8

Neither TOTP (Google Authenticator) or Twitter factor in how easy it is to malware/root Android phones these days. I still prefer Yubikey or other opensource cards until the state of mobile security improves (for ex SEAndroid).

Note that Auhty has the exact same issue.

Re: Thoughts on Twitter's new Two-Factor Authentication

#28
post #17

My first experience with the new two-factor auth has been poor. 1. I sign into Twitter with my browser 2. My phone receives a push notification saying that I have a pending auth request. 3. So I click it and load the Twitter iOS app, and I see "You have no login requests" for that account, no matter how much I refresh it (it has been 10 minutes now). 4. Now I can't get into my Twitter account on the browser. The urge…

I have the same problem with the Android version. I'm just waiting it out, and hoping my session doesn't expire. :)

Re: Thoughts on Twitter's new Two-Factor Authentication

#29
post #10

Earlier quoted context omitted.

Maybe they are trying to tell you to stop tweeting about it, put down your phone and enjoy your vacation?

I don't think they can be, as I don't have a Twitter account. Certainly I would be pissed beyond belief if I tried to login to my bank (assuming they ever pull their heads out of their asses to support 2FA) and couldn't because I don't have cellular service in addition to Internet.

I already have this problem; both my bank and my credit union introduced 2FA but only with SMS. Once enabled, any attempt to log in using a not-yet-authorized browser or app is stalled until I get that text message. Presumably a call to customer service would sort it out eventually, but that prospect isn't terribly pleasant.

Re: Thoughts on Twitter's new Two-Factor Authentication

#30
post #17

My first experience with the new two-factor auth has been poor. 1. I sign into Twitter with my browser 2. My phone receives a push notification saying that I have a pending auth request. 3. So I click it and load the Twitter iOS app, and I see "You have no login requests" for that account, no matter how much I refresh it (it has been 10 minutes now). 4. Now I can't get into my Twitter account on the browser. The urge…

Did you update to version 5.9 of Twitter for iOS, released 8/6, featuring support for login verification? Maybe the notification should mention that requirement.

Or don't send a notification to that deviceToken until the user has installed the new version of the app and sync'd at least once. (Letting the server know the deviceToken points at the newer version of the app.)
Post reply on HN