Live data from Hacker News

Dropbox Introduces 2-Factor Authentication

dropbox.com

61–70 of 78 posts

Re: Dropbox Introduces 2-Factor Authentication

#61
post #7

I'm glad they didn't invent their own mechanism but used standard OTP tokens, so you can just add them to apps like Google Authenticator.

This is very convenient, Google Accounts, Amazon AWS[1], SSH[2], and Dropbox, all from one simple app. If Google Authenticator allowed to change the order of accounts without removing and readding them, I would have absolutely nothing to complain about. [1] https://aws.amazon.com/mfa/faqs/ [2] http://askubuntu.com/questions/159727/how-can-i-use-a-passco...

In the iOS app, you can change the order by tapping 'edit' and then by drag and drop. The 'edit' button usually works if you tap and cancel the '+' button first.

Re: Dropbox Introduces 2-Factor Authentication

#63
Carrying a set of backup codes when travelling, generating a code for each app that is linked to your account...these things make two way authentication seem very inconvenient. I went with converting my gmail account to use two way authentication but after being informed to remember to carry a set of 10 backup codes when I am going to be without my phone, was a turn off and I reverted to my old settings.

Re: Dropbox Introduces 2-Factor Authentication

#64
post #62
post #60

My security codes aren't working (invalid). Using Google Authenticator. Anyone else have this issue?

Yup, have the same issue, went with sms-version because of this ;(. Google Authenticator on HTC Desire HD with custom ROM

When I first used Authenticator I had this problem, because the clock on my phone was a couple of minutes out of sync.

There is room for some error but it is worth making sure the time on your phone is correct.

Re: Dropbox Introduces 2-Factor Authentication

#65
post #18

Earlier quoted context omitted.

How entering 6 digits hard for users?

You have to log in with your username and password first and then you have to enter another password (those digits that you're talking about). With Rublon you just scan a Rublon Code and that's it.

But in another post, you say that you are planning to add a second factor to Rublon, so that the user must enter a PIN when scanning the Rublon code. So it doesn't appear to be any more convenient that Google Authenticator, which is widely-supported, produced by someone I trust, and open source.

The idea of using QR codes for authentication is interesting, but I would be very careful in selling this as a highly-secure system that is capable of replacing two-factor auth.

To me, this appears no more secure than leaving a copy of your password in plain text on the phone - if someone gets access to your phone, they have access to all of your Rublon accounts. Compare this to Google Authenticator - in the same scenario, the attacker would still need to know my password as well as the token.

Re: Dropbox Introduces 2-Factor Authentication

#66
post #20

Earlier quoted context omitted.

If Dropbox were designed to handle sequentially-numbered blobs of encrypted data, changing one file would require your other devices to download only that file (an encrypted blob of roughly the same size). With a TrueCrypt volume or other encrypted file solution on top of Dropbox, you have to resync the entire multi-GB volume any time a single file in there changes, since to Dropbox it's just one big file. (Another o…

If you only have Macs, using an encrypted sparse bundle disk image is pretty simple, and changed files result in a small delta for dropbox to sync. It's built in and you'll be up and running in a couple minutes: http://matthew.mceachen.us/blog/free-easy-encrypted-storage-...

it is only simple if you always manage not to open such a sparse bundle on another Mac before it has been fully synced after being used on another Mac. Otherwise, you will mess up your sparse bundle sooner or later.

A service for syncing and sharing with built-in encryption might therefore me more convenient for most users. Spideroak and Wuala are two examples.

Re: Dropbox Introduces 2-Factor Authentication

#67
post #19

Earlier quoted context omitted.

Put a truecrypt volume in your DropBox. Why rely on someone else to do the encryption?

Consider what your goals are with respect to encryption -- allowing the deltas generated by modifying your TrueCrypt volume will almost certainly make it easier for an adversary to break into your encrypted volume.

Are the algorithms used weak to that? I know that deltas will reveal the locations of changes and also let you detect whenever the same sector has the same bytes written to it. What else might be revealed?

Re: Dropbox Introduces 2-Factor Authentication

#68
post #53
post #4

Try this: https://www.dropbox.com/try_twofactor Although tray login still logs you in without the need to enter password or the code.

Not working for Martinique (FWI), country code 596. Still waiting for a SMS to come. Asked twice 5 and 10 minutes ago. Maybe the country list should be edited to only list countries where SMS can be sent? (I have no problem with other 2-ways services I use)

Lack of SMS shouldn't be a problem. You can use two factor authentication with the app version.It's on that same page.

Re: Dropbox Introduces 2-Factor Authentication

#69
post #12

Two-Factor authentication sucks. It's too hard for users. Most people will never us it. Dropbox should consider using Rublon (yes, that's my startup): https://rublon.com 7 reasons why you should add Rublon to your website: http://blog.rublon.com/2012/why-add-rublon/

Thanks for your opinion guys. Looks like we'll have to invest much more time in creating a new website that will explain Rublon more precisely. I can see that there is way too much confusion and misunderstanding about the product.

Re: Dropbox Introduces 2-Factor Authentication

#70
post #12

Two-Factor authentication sucks. It's too hard for users. Most people will never us it. Dropbox should consider using Rublon (yes, that's my startup): https://rublon.com 7 reasons why you should add Rublon to your website: http://blog.rublon.com/2012/why-add-rublon/

How about this for a novel idea. Stop inventing new mechanisms for autentication, and let ME choose how I authenticate myself to your service (to gain access to MY data). http://ragmondocom.appspot.com/2012/03/My-Stuff-My-Lock
Post reply on HN