4 ms·
I really hope other services start offering it as a feature. Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector. Also, RE the Googl
by coffeecheque 14y ago
I really hope other services start offering it as a feature.
Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector.
Also, RE the Google one time use passwords for POP/IMAP. They are all lower case, alpha/numeric, and 8 chars long.
How secure are they against brute force? Why wouldn't Google offer 16 char options, or even longer? Is 8 good enough?
- scraplab 14y agoI make it 4 blocks of 4 random alphanumerics each, which is a pretty big search space.
- nodata 14y ago> Is 8 good enough? Depends on how good their intrusion detection is.
- zapman449 14y agothe application specific passwords are 16 characters long. Four blocks of four lowercase characters. I too would rather them be longer, and involve at least some numbers if not specials... but they're not THAT short.
- coffeecheque 14y agoReally? I was sure it was only 8 when I went through the process 2 weeks ago. 2 lots of 4. Time to go and generate some new passwords!
- pooriaazimi 14y agoHmmm... I generated a batch about 2 months ago and another batch last week. In both cases, they were of the form llll llll llll llll (l: [a-z])
- coffeecheque 14y agoHappy to stand corrected. My apologies all round. Thanks everyone!
- zwily 14y agoThey've been 16 chars for at least several months.
- slig 14y ago> Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector. The least they could do if offer IP whitelisting like Linode does.
- alfiejohn_ 14y agoDoesn't help if they target your provider: http://slashdot.org/story/12/03/02/0059202/linode-exploit-caused-theft-of-thousands-of-bitcoins
- drcongo 14y agoI'm getting 16 character app specific passwords having just turned it on on one of my Google Accounts (all lowercase alpha though).