Live data from Hacker News

Please turn on two-factor authentication

mattcutts.com

1–10 of 262 posts

Re: Please turn on two-factor authentication

#3
I really hope other services start offering it as a feature.

Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector.

Also, RE the Google one time use passwords for POP/IMAP. They are all lower case, alpha/numeric, and 8 chars long.

How secure are they against brute force? Why wouldn't Google offer 16 char options, or even longer? Is 8 good enough?

Re: Please turn on two-factor authentication

#6
I did this a few months ago, but I'm thinking of turning it off. I know it's trivial, but there's something deeply annoying about being dinged $0.20 a pop for the SMS message to get the code.

I'll have to see if I can set up the Google Authenticator; I hadn't heard of that before.

Re: Please turn on two-factor authentication

#8

Am I the only person in the world who doesn't have a cell phone? It annoys me that the two-factor auth setups at sites (like Google) assume I have one and don't even have an option for "I don't have a cell phone, please stop nagging me about this."

Yes you are, and I suspect you know this. Even in most third world countries cell-phones are common.

Re: Please turn on two-factor authentication

#9

I really hope other services start offering it as a feature. Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector. Also, RE the Google one time use passwords for POP/IMAP. They are all lower case, alpha/numeric, and 8 chars long. How secure are they against brute force? Why wouldn't Google offer 16 char options, or even longer? Is 8 good enough?

I make it 4 blocks of 4 random alphanumerics each, which is a pretty big search space.

Re: Please turn on two-factor authentication

#10
I did this but was expecting more from Google. As an example, it was easier to add two factor auth to my Blizzard account (and install their authenticator) than it was for Google. These are the steps for Google: - Add mobile phone to account - Enter code from SMS - Generate random passwords for multiple apps which don't support two factor auth (this took awhile). - I wasn't given any instructions on how to switch from SMS to Google Authenticator app so I had to search for those instructions and then set that up.

Granted Blizzard controls the entire experience, they're not dealing with 3rd party apps, but it seems like Google could make this easier. And once it's trivially easy to setup, then it can be made the default.

Post reply on HN