Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

41–50 of 262 posts

Re: Please turn on two-factor authentication

#41
post #29
post #17

Two-factor auth gets old really fast when you have to use public computers in a setting like a college library. I had turned it on for a while, but turned it off when I had 5 minutes to print out a paper that I had emailed myself (yes, I still do that) and was fiddling with my phone to get the damn PIN. Never again.

Well, is that 5-minutes-to-print an edge case or a more than occasional situation? If the latter, how hard is it to create an alternate email account in which you send non-confidential emails/docs on the spur of a moment? If it's an edge case, it seems like a trivial one for reducing your security so much. As your documented online data grows, the chance of being hacked only grows. And once you've been hacked, there'…

Yeah, yeah, I should probably turn it on. And while I'm at it, I should probably eat more vegetables, less red meat and go to the gym. But I don't see those happening either ;).

Seriously though, when you have to enter the PIN multiple times a day, it gets annoying.

Re: Please turn on two-factor authentication

#42
I'm always dumbfounded when these topics come up and a lot of people start saying how inconvenient it is, that it is all wrong. But these are probably the same people which later accuse Google that they didn't do enough to protect their accounts!

Yes, two factor authentication is a small hassle. Yes, two factor authentication requires a bit to set up. But do you realize how much actually depends on your email account being safe?

For one, how many times did you use Googles OpenID provider? Yes, that's your Gmail account! Or for how many services did you use your Gmail account as the email address? You know that password resets go to that account, right?

Don't do that? Maybe you use Google Calendar, then. So yes, there is actually a lot of sensitive data in there. If you don't believe me, try to get a hold of a friends calendar, and see what you can guess about that person just from the calendar.

Or should someone just post some slander about you on you G+ profile? Or buy some apps from the Android Market? Of course this things never happen to you...

So just take the time to, besides looking at the time or the latest message on your phone, open that stupid app and type that stupid code in! It's not THAT much work!

Re: Please turn on two-factor authentication

#43
post #33
post #18

Something Google could to do drastically improve the security of their two-factor authentication system is to add the ability to give more granular permissions with the application-specific passwords. I have an application that only needs to send E-Mail through my GMail account (git-send-email), another that only needs to write to one specific GMail label (Android SMS Backup), and Google Chrome surely doesn't need ac…

I didn't think Chrome any longer required an ASP?

It still does; I had to go through this yesterday. I don't mind Chrome so much per se, but this also means you need an application-specific password for Chrome OS, at least for he initial sign-on, which I find oddly frustrating.

Re: Please turn on two-factor authentication

#45
post #37

I've been avoiding doing this, and I'm not certain the reason is valid - I don't want Google to have my mobile phone number. Perhaps I'm being overly cautious, but the fact Google already collects such a huge amount of data on me, coupled with the increasing insistent requests to enable two-factor with my mobile phone number, has made me not do it. I got so sick of being pestered about it that I stopped using Gmail a…

You don't need to enter your phone number to use Google's two factor. You can use their smartphone application to generate codes. If you don't want to do that, the algorithm is free and open-source so you can probably find an alternate implementation that works fine.

Re: Please turn on two-factor authentication

#46
post #11

Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."

You can run the Authenticator app on an iPod. But 2-factor does mean there in an expectation you will have to carry some kind of token device.

You shouldn't have to carry an electronic device, though: a list of codes on paper can work fine. That's how the NemID system works, for example (http://en.wikipedia.org/wiki/NemID): I have a big list of challenge/response codes that I carry in my wallet, and each is used once. I use that one successfully to log into my bank with two-factor authentication, but since I have no cell phone, iPod, iPad, or Android device, I can't use Google's version.

What's weird is that Google even sort of supports the numbers-on-paper approach, but for some reason they limit it to 10 numbers.

edit: Hmm actually thought of a possible solution. Looking into how hard it'd be to port the Google Authenticator to a non-mobile platform so I can run it on my laptop.

edit2: Although it looks like you can't enable the Google Authenticator method without first enabling the SMS method...

Re: Please turn on two-factor authentication

#47
post #14

Earlier quoted context omitted.

Still, if I plan to use Google Authenticator, I don't want to give Google my phone number at all. When they insist to get the phone number from me, I don't like it.

I don't think you need to get them a phone number. I use Google Authenticator app on my iPhone, and didn't give them anything. It just scanned a barcode on a webpage IIRC.

The bar code was actually just a code to initialize the code generation (I think it is based on that randomly generated seed and the time, so that then server and client generate the same keys). You could have also typed in the code by hand.

Re: Please turn on two-factor authentication

#48
post #17

Two-factor auth gets old really fast when you have to use public computers in a setting like a college library. I had turned it on for a while, but turned it off when I had 5 minutes to print out a paper that I had emailed myself (yes, I still do that) and was fiddling with my phone to get the damn PIN. Never again.

How much "fiddling" do you have to do to get your PIN? Unlock code or symbol, select authenticator app, read PIN? On top of loading Gmail and entering your user/pass?

Re: Please turn on two-factor authentication

#49
post #21

I really hope other services start offering it as a feature. Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector. Also, RE the Google one time use passwords for POP/IMAP. They are all lower case, alpha/numeric, and 8 chars long. How secure are they against brute force? Why wouldn't Google offer 16 char options, or even longer? Is 8 good enough?

> Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector. The least they could do if offer IP whitelisting like Linode does.

Doesn't help if they target your provider:

  http://slashdot.org/story/12/03/02/0059202/linode-exploit-caused-theft-of-thousands-of-bitcoins

Re: Please turn on two-factor authentication

#50
post #15
post #6

I did this a few months ago, but I'm thinking of turning it off. I know it's trivial, but there's something deeply annoying about being dinged $0.20 a pop for the SMS message to get the code. I'll have to see if I can set up the Google Authenticator; I hadn't heard of that before.

Even without GA (which, if you have an Android or iPhone, I don't see why you'd have to be without) $0.20 a month seems an incredibly small price to pay for the benefit of 2-factor auth.

I know, it's irrational, but it adds an extra annoyance factor, far more than it should. I mean, I spend far more every time I take the subway somewhere. Driving across the GW bridge costs $12, and I don't worry myself about that.

It turns into four or five SMS every month, when I usually average zero (various computers, various browsers, etc.) So suddenly, there's this line item where there used to be none. I can't explain quite why it bugs me.

In any case, I hadn't heard of GA before. I've installed it and life is good.

Post reply on HN