3 ms·
There are a lot of posts blaming GoDaddy. Did anyone read the post by David Airey, linked in the article? The reason for his lost domain was that his Gmail acco
by whileonebegin 15y ago
There are a lot of posts blaming GoDaddy. Did anyone read the post by David Airey, linked in the article? The reason for his lost domain was that his Gmail account was hacked. The attacker performed a "legit" domain transfer through his registrar. It wasn't the registrar's fault, in this case. The only blame you could place was that perhaps the registrar didn't have enough security check points.
GoDaddy is certainly annoying with their obnoxious web site and sometimes, their tactics, but this could be another email-hijack attack.
- paul9290 15y agoYeah i am thinking this too. I mean a day or two ago Gmail was showing and promoting users to enable 2 step verification because thousands and thousands of gmail accounts are stolen everyday (something to that extent). Big fish are big targets and gmail like godaddy and bank of america may no longer be safe and or wise to maintain your business with!?! I have had issues with all 3 mentioned.
- paul9290 15y agoYeah i am thinking this too. I mean a day or two ago Gmail was showing and promoting users to enable 2 step verification because thousands and thousands of gmail accounts are stolen everyday (something to that extent). Big fish are big targets and gmail like godaddy and bank of america may no longer be safe and or wise to maintain your businesses with!?! I have had issues with all 3 mentioned.
- calvin 15y agoOne more great reason to set up two-step verification for your Gmail and Google Apps accounts. http://googleblog.blogspot.com/2011/02/advanced-sign-in-security-for-your.html http://googleblog.blogspot.com/2011/02/advanced-sign-in-secu...
- brador 15y agoI've yet to do this. Reason being I wonder what will happen if I lose my phone... Is there a way to set up two-step without a phone?
- cube13 15y agoGoogle provides a set of numerical codes for you to print out and store in case you lose your phone. They're all one-time use, and allow you to get in and change the settings.
- pavel_lishin 15y agoDoes that mean that if ANY of them are used, the rest are invalidated? Or just that any one of them may be used once?
- cube13 15y agoYou get 10 codes per generation(and can regenerate them whenever you want), and each code can be used once.
- zecho 15y agoYou can use an alternate number to have a text message sent to you and there are printable one-time pads. The one-time pads have come in handy for me, because I always let the battery on my phone die.
- bjcubsfan 15y agoIn addition to the one time pad, you can specify other phone numbers. The system will call these phones and read the code aloud.
- JBiserkov 15y agoThe recommended way is to use the Google Authenticator app - available on Android, iOS, and BlackBerry devices - doesn't require an Internet connection, mobile service, or a data plan to generate verification codes. http://www.google.com/support/accounts/bin/answer.py?answer=1066447 http://www.google.com/support/accounts/bin/answer.py?answer=... I'm using it on my iPod.
- Natsu 15y agoAlso, you should NOT have Gmail open while surfing the web. I won't even visit a link emailed to me directly. I'm either reading email or surfing, but never both; all private data gets wiped between sessions. Sure, it's a bit paranoid, but it eliminates quite a few attacks and opportunities for social engineering.
- Matt_Cutts 15y agoI came here to say this, so thanks for saying it for me, calvin. Anyone reading on HN should probably set up two-step verification on their Google accounts.
- teyc 15y agoPerhaps it is domain registrars that need to implement two-step verification before transfers. It would be such a labour-saving move, and potentially safe so much time resolving disputes. Just offer people to "lock" their domains to be unlocked with a mobile phone number. It would be a simple twillio app.