Live data from Hacker News

Make Your Email Hacker Proof

codinghorror.com

71–80 of 161 posts

Re: Make Your Email Hacker Proof

#71
While I like 2 step authentication I wish Google would get rid of SMS password reset. With this enabled all a person needs is your phone to gain access to your account. Given that police can grab you phone whenever you are stopped this means they can "hack" your account at the same time. Another example could be a cleaning person at a hotel finding your phone. Just two examples off the top of my head. Basically, SMS password reset makes your phone the golden key.

http://support.google.com/accounts/bin/answer.py?hl=en&a...

Re: Make Your Email Hacker Proof

#72

(You can check the "remember me for 30 days on this device" checkbox so you don't have to do this every time.) No thanks. Google remembers a lot more than "this device," more like everything I do within that device thanks Search cookies, Adsense, Analytics on millions of sites and who knows what else

You don't need to be authenticated for Google to know who you are.

Re: Make Your Email Hacker Proof

#73
post #42

so now it is only a matter of time until the keylogging software that everyone is so terrified of is modified to also take the session cookie from your browser that authenticates you to gmail. you know, the thing that makes it okay for you to click "remember this computer for 30 days" ...

Like FireSheep already did?

Re: Make Your Email Hacker Proof

#74
post #64

I have two-way enabled, but when logging in via Google Talk (windows app) it seems to bypass it. If I go straight to gmail.com and login I'm asked for the second auth, but clicking via Google Talk (already signed in) it logges me in to GMail directly. Anybody know if this is normal / expected?

It's because Google Talk is permanently authorized via it's application-specific password.

Re: Make Your Email Hacker Proof

#75
post #2

What happens when you travel abroad and your phone does not work? I am wondering if Gmail could implement security questions to avoid cases where the 2-step verification works against the user

That's exactly what I've been wondering about enabling two factor authentication for something I use as often as email. Apparently you can print a series of one-time use verification codes that work any time to sign into your two-factor account. Stick a few on a card in your wallet and don't forget to generate more before you're out! https://support.google.com/accounts/bin/answer.py?hl=en&...

See http://news.ycombinator.com/item?id=3855880

Re: Make Your Email Hacker Proof

#77

I think this is great, but it doesnt appear to be enabled for the freebie google apps for domains service.

I was wrong - the domain administrator can enable this feature in the settings. I apologize for the noise.

Not noise at all. It took me ten minutes to find this option. Turns out it's buried under "Advanced Tools" -> Authentication

Re: Make Your Email Hacker Proof

#78
post #40

Is it really that easy to hack someones gmail account? I realize phishing and key loggers are easy ways to grab a password, but if you avoid typing your gmail password at public internet kiosks and the like, is it really that easy for someone to get at? Assuming you use a reasonably long and impossible to guess password, the captchas would prevent brute forcing. An attack targeted specifically at you will inevitably…

A _startlingly_ large number of people are (still) re-using passwords across multiple sites. The Gawker/Sony(/PerlMonks for me) compromises revealed a _lot_ of email addresses and passwords, some significant portion of which almost certainly allowed attackers access not only to the specific website that was attacked, but also to the email service of the exposed user.

I'm pretty sure none of Jeff's advice helps you against a government-agency level attack agains you specifically, but following it _will_ protect your email even if some other random website you once registered for exposes the login details you used there. I _hope_ that's not a problem for any HN readers (any more), but what about your partner/children/parents/coworkers? I'd bet good money that _someone_ you know and care about is reusing their email account password on random website signup forms.

Re: Make Your Email Hacker Proof

#79
post #55

"print the recovery codes and keep them with you at all times" Wrong. Terribly wrong. Do not do that. You'll have your phone with you AND the codes. So, imagine that day, you get your stuff stolen from your person. Laptop, phone, codes, gone. Bad. That day you were on a boat and you fall in the water. Phone, codes, gone. Bad. Instead store the codes in your own safe, a secret location, or a safe deposit box.

No, it's exactly right. Having the codes with you is not a security risk because they're useless without your password. You can keep a second copy of the codes at home if you're worried about losing them.

Re: Make Your Email Hacker Proof

#80
post #4

What I really want is for the second factor to kick on only in suspicious situations, e.g.: * I'm logging in from a computer that I've never logged in from before * I'm searching my mail history for terms like "password" * I'm opening an email that appears to contain a password-reset link * I'm messing with my mail-forwarding options * I'm accessing messages in bulk But I do not want to have to do second factor just…

Typing a six digit number every 31 days is too much work to add a significant layer of security to a very important account?

Times two accounts, times four devices, multiple browsers... pretty soon it's a once-a-week frustration.
Post reply on HN