4 ms·
The biggest weakness's to 2 factor auth are: 1: You can remove 2 factor auth without having to enter the auth code. So if your computer gets a virus, someone c
by sauteedbiscuits 14y ago
The biggest weakness's to 2 factor auth are:
1: You can remove 2 factor auth without having to enter the auth code. So if your computer gets a virus, someone can just remove 2 factor auth via your browser
2: The "app specific passwords" are full on backdoors. If one of your app specific passwords gets hijacked, someone can login to your gmail with it and then remove the 2 factor auth pass (See above)
* http://productforums.google.com/forum/#!category-topic/mobile/apple-devices/w65ikaERDgw http://productforums.google.com/forum/#!category-topic/mobil...
- reedlaw 14y agoAren't app specific passwords simply single-factor auth tokens, thus defeating the purpose of using two factor auth? Wouldn't a sufficiently complex pass-phrase be just as secure?
- aristidb 14y agoNo, because each app has a different token and you can revoke them individually. Google does want people to use OAuth instead of app-specific passwords as much as possible, but sometimes that's not possible or just isn't done. Then you at least get some security from not posting the same password to a million places.
- yock 14y agoGoogle's own products don't even conform to this. My Galaxy Nexus and Chrome browser requires app-specific passwords.
- kolev 14y agoThe latest version of Chrome dev (21.0.1155.2 dev-m) does not require an app-specific password - it works with the OTP if you have it enabled, but at least for me the sync is broken at this point.