Earlier quoted context omitted.
It's per-device, not per account (I know the guy who developed it for Google; one of the smarter people in the industry). It uses protected storage for the credential so it isn't backed up to iCloud, either. Sadly on Android they don't have the same security features available, due to limitations in the OS; it would be fun to talk to Samsung and make a "actually secure Google Authenticator" specific to the S3/S4 sinc…
The Duo-Security people, who have an Android Token claim to use the secure element in NFC enabled phones. It is a TOTP token and can be used just like the Google Authenticator. You don't have to use Duo-Security's system to use it (though there system is worth looking at if you are rolling out your own authentication system).
Linode Manager Two-Step Authentication
61–70 of 87 posts
Re: Linode Manager Two-Step Authentication
#62Earlier quoted context omitted.
They admitted that the encrypted CC numbers were leaked, they didn't mention if the encryption keys were stored on the same machine. The alleged hacker said that the encryption keys were stored on the same machine, making the encryption useless.
It was also made clear that the encryption key was protected by a passphrase which was not stored on the machine.
Re: Linode Manager Two-Step Authentication
#63Earlier quoted context omitted.
It was also made clear that the encryption key was protected by a passphrase which was not stored on the machine.
"which was not stored on the machine", like they should be commended ( Reminds me of exams where you received some credit for including your name... ). I am sorry, them confirming this fact, and even if I recall adding a smiley in the tweet they did it, just cemented that they do not understand their business. They clearly wish to give the impression that they are "secure". They need more lock icons...they are almost…
There should be several classes of certification, from "I want to sell a few pet rocks" to "I'm Apple with 150,000,000 credit cards on file". Right now there's basically two.
Re: Linode Manager Two-Step Authentication
#64Not everybody owns or wants a smartphone. Linode needs to extend this to some non-smartphone device, like YubiKey, or offer SMS codes, like Google Authenticator. This is a step in the right direction, but is ultimately disappointing for me.
Re: Linode Manager Two-Step Authentication
#65Earlier quoted context omitted.
How about for those that just want a small instance system. I just do the smallest linode setup for some personal projects. From my understanding, AWS is expensive for that type of use case?
AWS Free Tier is...free. I'd probably go with http://prgmr.com/xen/ for low end above that.
Re: Linode Manager Two-Step Authentication
#66Re: Linode Manager Two-Step Authentication
#67Re: Linode Manager Two-Step Authentication
#68Or is this just a show? Either way, this question itself reflects the fact that they refuse to give proper information and postmortems.
Re: Linode Manager Two-Step Authentication
#69After being bitten the first time with Linode I don't care what technical measures they are taking. I want to know what process and policy changes have been made. Do they still store public/private keys on the same server ? How often are they doing security audits (which clearly never happened before) ? Are they still going to be dodgy and withhold key information from their users ? Are users still going to find out…
Sure Linode sucked at security and probably still sucks. But what makes you think its competitors are any better?
Re: Linode Manager Two-Step Authentication
#70Not everybody owns or wants a smartphone. Linode needs to extend this to some non-smartphone device, like YubiKey, or offer SMS codes, like Google Authenticator. This is a step in the right direction, but is ultimately disappointing for me.
How many of linode's subscribers do you think not own a smartphone? I mean, outside of your enclave?
I've had my non-smartphone for six years now. It still works, and while I'm sure I'll upgrade to a smartphone one day, I have no urgent desire to do so.
Is it really that hard to set up an SMS system as a fallback? I'm still able to use two-factor on my Google account because they offer this solution.