6 ms·
"I use a secure password algorthym." Maybe my notion of secure is wrong, but I didn't find it particularly secure ("Ensure your system always gives you a passwo
by markcerqueira 10y ago
"I use a secure password algorthym." Maybe my notion of secure is wrong, but I didn't find it particularly secure ("Ensure your system always gives you a password between 8 and 9 characters long") or even convenient (absolutely no mention of password managers, system is based on memorization).
And then moments later: "I currently don’t have two factor authentication."
Just seems like there's two people behind this post: one who is concerned about security and one who doesn't fully leverage tools to enhance their security.
Not ragging on the author. This just stuck out at me. I'm genuinely curious and would love a follow-up if author can discover what happened.
- ap22213 10y agoQuantitatively, how much more secure would using two factor authentication be over what the author is doing? Edit: Assuming that someone only crafts 9-plus-character passwords that don't show up in dictionary attacks and aren't reused across sites, is 2FA going to secure that person much more? I'm not challenging 2FA. Actually, I'm just trying to motivate myself to use it.
- shaftway 10y agoIf done properly, immensely. Sites can log invalid password attempts, and unscrupulous sites could include attempted usernames and passwords. That basically gives them a dictionary of accounts to try, because let's face it, most people use the same password for multiple services. Sometimes people's muscle memory kicks in and they accidentally type their password into the wrong site, or the wrong field. With Google's 2FA, you need access to either a pre-printed list of emergency codes, or the ability to see the person's incoming texts. That's where the "if done properly" caveat comes in. Google Voice is generally a bad idea. If someone accidentally gets into your email because you left it open, they also have access to your incoming texts.
- newjersey 10y agoI'd like to respectfully disagree. When done correctly, Google Voice can be as good as if not better than a traditional cell phone. I treat my email with more care than I treat my bank accounts. However, Google Voice is probably not as good as the app on your phone though.
- shaftway 10y agohttps://support.google.com/accounts/answer/185834?hl=en#gvoice https://support.google.com/accounts/answer/185834?hl=en#gvoi... I remembered the advice, but not the reason. It's because you can easily lock yourself out of any way to get your otp. So maybe it's too secure?
- newjersey 10y agoAh. I have an app for my main Google account but for other Google accounts, I have them sent to my Google Voice number. (: Mostly because I'm lazy and want to copy paste from hangouts on the computer.
- kennydude 10y agoUsing Google Authenticator app (or any TOTP app, I use 1password), you skip the need for access to incoming SMS
- CydeWeys 10y agoThere are entire classes of attack that 2FA protects against that you are completely screwed without. Some examples: You use a computer that has a key logger, or you get infected with a key logger, or a hardware key logger is installed inline with your keyboard cable. Someone shoulder surfs you while you log in. Someone points a video camera at your keyboard while you log in. Someone uses an RF vulnerability to wirelessly snoop the RF signals as you log in on a keyboard. You get phished (a good phishing page, not a pathetic one). You get tricked into entering your password into a popup dialog box that appears to be a "Log in with your Google account" dialog, but isn't.
- uxp 10y agoThe author reads like they have a pretty high sense of self worth, which rubbed me the wrong way. Your comments which I noticed myself, and the other post they linked to about moving off of Gmail and onto a postfix/dovecot self-hosted stack and the drivel about Gmail and Facebook having a long history of unfederated services and then at the very last paragraph almost casually mentioning that Outlook.com, Gmail and Yahoo seem to consistently flag mail coming from their server as spam. I've run my own postfix/dovecot stack since 2004 and have never had the same problems, but a sample size of two is a poor pool to derive results out of. I wouldn't be surprised if their email server might have been configured as an open relay accidentally at one point, or even a neighbor on the same or near the same subnet been a flagrant source of spam. Coming from nothing, mail servers are somewhat hard to get running correctly and securely. Much more so than standing up Apache. I would also like a follow up, as there seems to be a very skewed story, or some kind of information is missing about both of these situations.