Just answer me this: why does Google insist on using a phone for this? Really: the company's got far too much personal information on me. Pick something else I can use. An OTPG (similar to the RSA keyfob), say. Added bonus: this gives a pathway for other services to also offer 2-factor auth.
Please turn on two-factor authentication
241–250 of 262 posts
Re: Please turn on two-factor authentication
#242I was worried this would be a major pain when I enabled it, but I have to say, it has been much more painless than I thought it would be. Most of the time, I don't even think about it. Most of my consumption of google mail is through clients on my laptops, iPhone, or iPad. So in that sense, it's not much different from a regular password. The difference is that someone else has a much harder time cracking my account.…
I finally gave up and turned off 2-factor auth. I'm guessing this is a limitation in 4.1.1, but it really, really sucks.
Re: Please turn on two-factor authentication
#243Earlier quoted context omitted.
It will remember that it's authorized across multiple logins/logouts as long as you don't delete the cookie.
So it's basically the same security as adaptive authentication (aka challenge questions) but with the added annoyance and security flaws of using either SMS or an app. With adaptive authentication, you basically add a series of heuristics based on the browser's request to calculate a number. A ratio applied to that number determines the likelihood that a user is the same as the one who has logged in before. If the ra…
Re: Please turn on two-factor authentication
#244I was worried this would be a major pain when I enabled it, but I have to say, it has been much more painless than I thought it would be. Most of the time, I don't even think about it. Most of my consumption of google mail is through clients on my laptops, iPhone, or iPad. So in that sense, it's not much different from a regular password. The difference is that someone else has a much harder time cracking my account.…
I literally could not enter the 2-factor code into my Galaxy Nexus running 4.1.1. The process asked for my password, then redirected to Chrome to finish the process, which asked me for a code. I then switched to the Authenticator app to get the code, but then I couldn't switch back to the place to enter it. Whhaaaaa??? I tried this 3 times looking everywhere. I finally gave up and turned off 2-factor auth. I'm guessi…
Re: Please turn on two-factor authentication
#245Earlier quoted context omitted.
I literally could not enter the 2-factor code into my Galaxy Nexus running 4.1.1. The process asked for my password, then redirected to Chrome to finish the process, which asked me for a code. I then switched to the Authenticator app to get the code, but then I couldn't switch back to the place to enter it. Whhaaaaa??? I tried this 3 times looking everywhere. I finally gave up and turned off 2-factor auth. I'm guessi…
Several google tools don't have support for the standard 2-factor auth. Instead, you have to create a single use password for those devices. Watch the video on Cutts blog for info on how it works.
I used 2-factor auth before on my phone (a much earlier version of android) and didn't have this problem. It's the typical thing with google: being on the bleed edge is just that, a pretty unsatisfying experience. I think next time a new android version comes out, I may wait a few months before I update.
Re: Please turn on two-factor authentication
#246Earlier quoted context omitted.
> It's a good idea, but it's not the weakest link in user security right now I suspect Google is in a better position to judge how widespread account compromises are than you are. From my perspective, it definitely seems like security people are all saying that account compromises (keyloggers, phishing) have been the predominant threat for several years now because they're suitable for bulk attacks whereas social-eng…
>I suspect Google is in a better position to judge how widespread account compromises are than you are. There are a couple of problems with that reasoning. First off, I don't see where anything Google has said contradicts my point. Yes, MFA is a good idea. But that doesn't mean it's enough to prevent attacks like the one in question. Secondly, Google is not an unbiased source on this matter. For cloud services to suc…
> Yes, MFA is a good idea. But that doesn't mean it's enough to prevent attacks like the one in question.
It would have stopped this one, in several ways: according to Honan's writeup, it would have halted things at a key point in the chain of account compromises. Yes, it's true that you have to trust companies - but that's always been true, even 100% off-line, as any victim of identity theft could tell you. The key point is that having any sort of MFA schema would have contained the damage to one company, halting the cascade.
Re: Please turn on two-factor authentication
#247Re: Please turn on two-factor authentication
#248Earlier quoted context omitted.
You can run the Authenticator app on an iPod. But 2-factor does mean there in an expectation you will have to carry some kind of token device.
You shouldn't have to carry an electronic device, though: a list of codes on paper can work fine. That's how the NemID system works, for example ( http://en.wikipedia.org/wiki/NemID ): I have a big list of challenge/response codes that I carry in my wallet, and each is used once. I use that one successfully to log into my bank with two-factor authentication, but since I have no cell phone, iPod, iPad, or Android devi…
I'm not sure about this (it was a while ago when I installed it), but I know you can install it on a new device after previously having it installed on another device (which disables it on the first device) without an SMS.
Re: Please turn on two-factor authentication
#249Earlier quoted context omitted.
The app-specific passwords are a feature and if you prefer the extra security over being able to use apps that don't support 2-factor, then you can choose not to use them, and get the full security benefits of 2-factor. It's just that, short of expecting every single third-party client app to implement 2-factor authentication or not allowing access to any that don't, there's no alternative to the app-specific passwor…
Non-web apps don't have a UI for two-factor. App-specific password is a compromise, which is vulnerable if someone steals your local installation of the client to get its keys.
I suppose there is one possible negative consequence to users who opt not to use app-specific passwords: their existence alone removes some of the incentive for client applications to implement 2-factor themselves (which I don't know if Google even has an API for). And sure, it would be nice to have features like access control on a per password basis (e.g., so I could allow Pidgin to access only gchat, but no other part of my account). But the implication that the mere existence of application-specific passwords somehow makes Google's 2 factor auth useless is just wrong.
Re: Please turn on two-factor authentication
#250Earlier quoted context omitted.
AFAIK it is still against Google's policies to have more than one gmail-account? That doesn't mean it won't work, of course, but you might end up with Google turning off all your accounts, with no real recourse to fix the situation. Why do you need access to your google account to send email from github? From:-headers are designed to be readily "forged" (or rather, set to whatever you want). Just send email through w…
Just checked the TOS...it doesn't appear that it's an outright violation to have multiple GMail accounts: https://mail.google.com/mail/help/intl/en/program_policies.h... >> Create multiple user accounts in connection with any violation of the Agreement or create user accounts by automated means or under false or fraudulent pretenses Also, Google gives you the option of managing multiple Google identities from one acc…
But, after a few minutes of searching, I can't find any actual promises that google will keep neither your logins, nor your services (eg: gmail) operating -- for any reason.
I guess this is worse if you actually pay them money (did they finally come up with a QOS-statement for paid accounts?)...