Now is a good time to enable two-factor authentication on your accounts. Here is how to do so for some common services: - Google: https://www.google.com/landing/2step/ - Github: https://github.com/settings/security - AWS: http://aws.amazon.com/mfa/virtual_mfa_applications - Facebook: https://www.facebook.com/settings?tab=security - Twitter: https://twitter.com/settings/security - Dropbox: https://www.dropbox.com/acco…
With two-factor authentication you are happily providing gmail with your phone number. They say they need this to send you a verification code when you log into your gmail account. Then they say: "During sign-in, you can tell us not to ask for a code again on that particular computer." Well, if that's the trick, they don't need your phone nr at all, they can do ip and os check anyways..
Alleged leak of more than 5M Gmail accounts
61–70 of 141 posts
Re: Alleged leak of more than 5M Gmail accounts
#62Every time something like this is posted, where there is a site to check if your email address is in some leaked list, I really wish they'd just tell me how to get the list itself. Instead, they ask me to trust that they will not use my email address, and I have to hope that they won't leak it. I generally don't bother, because it's just more security risks.
It could be even more dangerous than you are imagining. If you check a username, then you would probably also be revealing the IP address range and browser referrer that is normally used to access your account. Google uses IP address and location to help detect illegal access. So giving away this information could make it easier for your account to be stolen.
Re: Alleged leak of more than 5M Gmail accounts
#63Re: Alleged leak of more than 5M Gmail accounts
#64Re: Alleged leak of more than 5M Gmail accounts
#65Now is a good time to enable two-factor authentication on your accounts. Here is how to do so for some common services: - Google: https://www.google.com/landing/2step/ - Github: https://github.com/settings/security - AWS: http://aws.amazon.com/mfa/virtual_mfa_applications - Facebook: https://www.facebook.com/settings?tab=security - Twitter: https://twitter.com/settings/security - Dropbox: https://www.dropbox.com/acco…
With two-factor authentication you are happily providing gmail with your phone number. They say they need this to send you a verification code when you log into your gmail account. Then they say: "During sign-in, you can tell us not to ask for a code again on that particular computer." Well, if that's the trick, they don't need your phone nr at all, they can do ip and os check anyways..
Also, according to the three biggest telcos where I live:
"SMS is not designed to be a secure communications channel and should not be used by banks for electronic funds transfer authentication," ( http://www.itnews.com.au/News/322194,telcos-declare-sms-unsa... )
Re: Alleged leak of more than 5M Gmail accounts
#66Earlier quoted context omitted.
With two-factor authentication you are happily providing gmail with your phone number. They say they need this to send you a verification code when you log into your gmail account. Then they say: "During sign-in, you can tell us not to ask for a code again on that particular computer." Well, if that's the trick, they don't need your phone nr at all, they can do ip and os check anyways..
I'm not sure exactly what point you're trying to make, but you seem confused about how 2FA works. The goal of 2FA/MFA is to make you demonstrate that you're in possession of two independent secrets (authentication factors). Once you've shown that, it's considered safe enough to replace the second secret (OTP sent to your phone or generated by your TOTP app like Google Authenticator) with a cookie (the check is not IP…
I'm under the impression that you need to provide Google your phone number before being allowed to enable TOTP.
Re: Alleged leak of more than 5M Gmail accounts
#67Earlier quoted context omitted.
It could be even more dangerous than you are imagining. If you check a username, then you would probably also be revealing the IP address range and browser referrer that is normally used to access your account. Google uses IP address and location to help detect illegal access. So giving away this information could make it easier for your account to be stolen.
How? Is the hacker going to buy a plane ticket, fly to my home and plug his laptop into my network?
He might even be able to use the same IP as you, if you happen to be using a gateway with many machines behind it, and one of them is compromised.
Re: Alleged leak of more than 5M Gmail accounts
#68Now is a good time to enable two-factor authentication on your accounts. Here is how to do so for some common services: - Google: https://www.google.com/landing/2step/ - Github: https://github.com/settings/security - AWS: http://aws.amazon.com/mfa/virtual_mfa_applications - Facebook: https://www.facebook.com/settings?tab=security - Twitter: https://twitter.com/settings/security - Dropbox: https://www.dropbox.com/acco…
Re: Alleged leak of more than 5M Gmail accounts
#69Now is a good time to enable two-factor authentication on your accounts. Here is how to do so for some common services: - Google: https://www.google.com/landing/2step/ - Github: https://github.com/settings/security - AWS: http://aws.amazon.com/mfa/virtual_mfa_applications - Facebook: https://www.facebook.com/settings?tab=security - Twitter: https://twitter.com/settings/security - Dropbox: https://www.dropbox.com/acco…
With two-factor authentication you are happily providing gmail with your phone number. They say they need this to send you a verification code when you log into your gmail account. Then they say: "During sign-in, you can tell us not to ask for a code again on that particular computer." Well, if that's the trick, they don't need your phone nr at all, they can do ip and os check anyways..
Although that wouldn't be 2FA, it's worth noting that Facebook, Hotmail and Flickr will ask for some extra verification if you connect from a different country that usual. So that's probably not a bad idea.