Earlier quoted context omitted.
* Edit: Ah, technically they did break into the email account. The first time I read this I thought that they just had access to the account info page (doing things, such as purchasing or accessing account settings, requires password-entry by Amazon) No, they did not have to break into the Amazon account. http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-hona... > First you call Amazon and tell them you are the…
But, as we know, Apple only needs those last four digits. We asked Amazon to comment on its security policy, but didn’t have anything to share by press time. Wow. That's really bad. I mean, it's stupid that Amazon allows that sort of thing (and it sounds like they may be working to fix it). But Apple going off just the last four digits? That's straight up retarded . Why isn't anyone asking about Apple's security poli…
Please turn on two-factor authentication
221–230 of 262 posts
Re: Please turn on two-factor authentication
#222I did this a few months ago, but I'm thinking of turning it off. I know it's trivial, but there's something deeply annoying about being dinged $0.20 a pop for the SMS message to get the code. I'll have to see if I can set up the Google Authenticator; I hadn't heard of that before.
Re: Please turn on two-factor authentication
#223Really: the company's got far too much personal information on me. Pick something else I can use. An OTPG (similar to the RSA keyfob), say.
Added bonus: this gives a pathway for other services to also offer 2-factor auth.
Re: Please turn on two-factor authentication
#224Earlier quoted context omitted.
Agreed, I missed that tidbit. I guess I was focusing on the idea that someone can wipe your iPhone, iPad, and Mac without ever touching your gmail account. As a father of two year old and 4 month old girls, the photos are the part that of the story that I find the most distressing. Everything else is upsetting, but you can rebuild contact lists and things. Those pictures are completely irreplaceable and it is just gu…
That is terrible. Though, I don't understand why anyone would turn on a "find my Mac" feature that has the potential to wipe your entire hard drive remotely unless you have thorough backups. Time machine is dead easy to use; try pluging in a usb hard drive and it will ask you if you want to use this as a backup drive. Arc is something that anyone on the mac should use as well for backing up priceless pictures and fil…
Re: Please turn on two-factor authentication
#225Earlier quoted context omitted.
That's true only to some extent: people keep on their keyring only those keys they need for daily use. Less frequently used keys (e.g., keys to a safety deposit box at the bank, keys to a home safe, keys to a second home) are typically stored in a drawer, a closet, or a safe. Also, note that having different keys means one can give copies of different keys to different persons for different purposes -- e.g., copy of…
On the other hand, typical house locks are (apparently) only locks by way of cultural convention. (I say apparently because the ease of using things like bump keys is pretty widely publicized but I have never actually tried it myself)
That said, your house isn't directly connected to 2.26 billion people who can make hundreds (or thousands or billions) of bump-key attempts per second.
Re: Please turn on two-factor authentication
#226Earlier quoted context omitted.
Still, if I plan to use Google Authenticator, I don't want to give Google my phone number at all. When they insist to get the phone number from me, I don't like it.
Buy a $20 used phone and get the cheapest pay-as-you-go plan you can find (you'll only be using the phone to receive text messages, so it should be really cheap) and consider it a somewhat impractical Google Authenticator hardware dongle.
Re: Please turn on two-factor authentication
#227It's a good idea, but it's not the weakest link in user security right now. It does very little to solve problems like Apple positively identifying people based on totally insufficient and publicly available information.
> It's a good idea, but it's not the weakest link in user security right now I suspect Google is in a better position to judge how widespread account compromises are than you are. From my perspective, it definitely seems like security people are all saying that account compromises (keyloggers, phishing) have been the predominant threat for several years now because they're suitable for bulk attacks whereas social-eng…
There are a couple of problems with that reasoning. First off, I don't see where anything Google has said contradicts my point. Yes, MFA is a good idea. But that doesn't mean it's enough to prevent attacks like the one in question.
Secondly, Google is not an unbiased source on this matter. For cloud services to succeed (which Google is banking on), it is very important that people perceive that they (the people) have some kind of control over their own security. It is reassuring to hear "here are some steps you can take to make yourself safer". It is terrifying to hear "your security ultimately hinges on the competence of some of the lowest-paid employees of the faceless corporations you rely on".
Both of those statements are true, but you're never going to hear the latter emphasized by Google or any other company heavily invested in the continued success of cloud based services. (Which is not to imply that they are dishonest; bias is usually as more about delusion than deception)
Re: Please turn on two-factor authentication
#228Re: Please turn on two-factor authentication
#229Earlier quoted context omitted.
You couldn't use a USB key instead?
Sure I could. Not denying that there are other ways to get access to the files I need, just that this has become a part of my workflow that two-factor auth disrupts.
Don't underestimate how vulnerable you are when your email gets hacked - virtually every service you use can be accessed by the forgotten password mechanism when your email is breached. I'm pretty lazy and have procrastinated for a long time, but with the recent attacks and realizing what a mess I could face if hacked I finally implemented two factor auth and I have no regrets yet.
Re: Please turn on two-factor authentication
#230Earlier quoted context omitted.
Why is it stupid for Amazon to show the last 4 digits? Let's say I have 3 cards on file. If I want to modify card #2 for some reason (billing address, expiry date) what do I do? Sure, I can look at the other details and take a guess, but we're on HN. On an average, the normal customer would get frustrated.
> Why is it stupid for Amazon to show the last 4 digits? I think npsimons was saying that it is stupid for Amazon to let you add a fake cc number and than take over an account using that same fake number. Not that they show the last 4 digits.
For the second question, I'd say Amazon should wait until the user "confirms" the credit card. That is to say, send the user an email stating "Hi! New credit card added to your account. Click here to verify".