Live data from Hacker News

Make Your Email Hacker Proof

codinghorror.com

51–60 of 161 posts

Re: Make Your Email Hacker Proof

#51
post #4

What I really want is for the second factor to kick on only in suspicious situations, e.g.: * I'm logging in from a computer that I've never logged in from before * I'm searching my mail history for terms like "password" * I'm opening an email that appears to contain a password-reset link * I'm messing with my mail-forwarding options * I'm accessing messages in bulk But I do not want to have to do second factor just…

Typing a six digit number every 31 days is too much work to add a significant layer of security to a very important account?

It's extra work.

Does this expiration after 31 days add any extra protection?

Re: Make Your Email Hacker Proof

#52
post #7

This worry seems a bit overblown to me. If your email is that important to you, you should follow these steps: 1. Use a unique , long, random, secure password. 2. Don't tell it to anyone. 3. Use an email service that stores passwords hashed with a salt and a secure hash algorithm. And you will have nothing to worry about. If you are very paranoid or traveling a lot, you can add: 4. Don't log in from insecure devices.…

>5. Make sure nobody's filming your fingers when you type your password. Many moons ago I read the table of contents of Silence on the Wire .[0] One chapter that particularly caught my eye was "I can hear you type.". (Which for some reason was stored in my memory as "I can hear your keystrokes." Which sounds more stalkerish IMO.) Just because of how creepy it sounded. Later I was talking to someone I knew over the ph…

We're already there: "Three students at UC-Berkley used a 10 minute recording of a keyboard to recover 96% of the characters typed during the session."

https://freedom-to-tinker.com/blog/felten/acoustic-snooping-...

Re: Make Your Email Hacker Proof

#53
post #4

What I really want is for the second factor to kick on only in suspicious situations, e.g.: * I'm logging in from a computer that I've never logged in from before * I'm searching my mail history for terms like "password" * I'm opening an email that appears to contain a password-reset link * I'm messing with my mail-forwarding options * I'm accessing messages in bulk But I do not want to have to do second factor just…

Typing a six digit number every 31 days is too much work to add a significant layer of security to a very important account?

It would be nice to choose the level of security you think you can afford on the security-inconvenience tradeoff curve. Especially since it is likely to increase the takeup rate.

Re: Make Your Email Hacker Proof

#54

(You can check the "remember me for 30 days on this device" checkbox so you don't have to do this every time.) No thanks. Google remembers a lot more than "this device," more like everything I do within that device thanks Search cookies, Adsense, Analytics on millions of sites and who knows what else

I always have my gmail logged-in in a separate browser and I don't use that for any other browsing.

Re: Make Your Email Hacker Proof

#55
"print the recovery codes and keep them with you at all times"

Wrong. Terribly wrong. Do not do that.

You'll have your phone with you AND the codes.

So, imagine that day, you get your stuff stolen from your person. Laptop, phone, codes, gone. Bad.

That day you were on a boat and you fall in the water. Phone, codes, gone. Bad.

Instead store the codes in your own safe, a secret location, or a safe deposit box.

Re: Make Your Email Hacker Proof

#56
There's a very "simple" way to steal stuff via email.

Find the relevant service. Spoof DNS. Get emails.

Alternative. MITM the SMTP (thanks anonymous SSL, no certificate errors!).

And that's scary, since 2 factor auth, nor anything, can really save you from that.

Re: Make Your Email Hacker Proof

#57
post #7

This worry seems a bit overblown to me. If your email is that important to you, you should follow these steps: 1. Use a unique , long, random, secure password. 2. Don't tell it to anyone. 3. Use an email service that stores passwords hashed with a salt and a secure hash algorithm. And you will have nothing to worry about. If you are very paranoid or traveling a lot, you can add: 4. Don't log in from insecure devices.…

>5. Make sure nobody's filming your fingers when you type your password. Many moons ago I read the table of contents of Silence on the Wire .[0] One chapter that particularly caught my eye was "I can hear you type.". (Which for some reason was stored in my memory as "I can hear your keystrokes." Which sounds more stalkerish IMO.) Just because of how creepy it sounded. Later I was talking to someone I knew over the ph…

It's been done already!

http://www.berkeley.edu/news/media/releases/2005/09/14_key.s...

Re: Make Your Email Hacker Proof

#58
post #23
post #7

This worry seems a bit overblown to me. If your email is that important to you, you should follow these steps: 1. Use a unique , long, random, secure password. 2. Don't tell it to anyone. 3. Use an email service that stores passwords hashed with a salt and a secure hash algorithm. And you will have nothing to worry about. If you are very paranoid or traveling a lot, you can add: 4. Don't log in from insecure devices.…

6. Cross your fingers and hope that you'll never use a machine afflicted with a keylogging trojan.

See #4.

Re: Make Your Email Hacker Proof

#59
post #27

The thing I hate about Google Authenticator is when you use a google authenticator protected gmail account for other google services. Google has a bunch of things where they don't yet support 2fa, so sometimes you enter the wrong password. It would be good if you had a dedicated-to-email google account, definitely. As it is, I use it for a gmail account I use with all my google services, and it's a real pain -- espec…

Facebook handles apps that don't support 2factor pretty well. Your first login will be rejected but you'll be messaged the 6 digit code to login with as your "password".
Post reply on HN