7 ms·
I was worried this would be a major pain when I enabled it, but I have to say, it has been much more painless than I thought it would be. Most of the time, I do
by JunkDNA 14y ago
I was worried this would be a major pain when I enabled it, but I have to say, it has been much more painless than I thought it would be. Most of the time, I don't even think about it. Most of my consumption of google mail is through clients on my laptops, iPhone, or iPad. So in that sense, it's not much different from a regular password. The difference is that someone else has a much harder time cracking my account. It's actually much less obtrusive than using lastpass (also highly recommended, but not as transparently usable).
That being said, two factor google auth wasn't going to save Matt Honan here. Identity, trust, and authentication on the internet are all built on a foundation of sand. We need a new model.
- Xyzodiac 14y agoSame here, I just enabled it a few days back and it's much easier than I imagined it would be.
- ja27 14y agoIf you've spent your career with RSA SecurIDs hanging from your keys, this isn't much of a hassle. I didn't realize that LastPass and others can use the Google Authenticator.
- quinndupont 14y agoI was just thinking that Google should open their service to others... Makes me think about switching from 1Password to Lastpass...
- danso 14y agoWhy wouldn't two-factor authentication protected Mat from at least his GMail account being hacked? Even if password-resets were being sent to the .Me account, wouldn't the hackers still need to generate the authentication token?
- gilrain 14y agoAccording to Matt (and, apparently, his hacker) you're wrong; two-factor would have saved him in this particular instance: "If I had some other account aside from an Apple e-mail address, or had used two-factor authentication for Gmail, everything would have stopped here." (http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all/ http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-hona...) Naturally, it's not a panacea, but I think a lot of people allow perfect to be the enemy of quite good when it comes to two-factor auth.
- JunkDNA 14y agoAgreed, I missed that tidbit. I guess I was focusing on the idea that someone can wipe your iPhone, iPad, and Mac without ever touching your gmail account. As a father of two year old and 4 month old girls, the photos are the part that of the story that I find the most distressing. Everything else is upsetting, but you can rebuild contact lists and things. Those pictures are completely irreplaceable and it is just gut-wrenching for me to think about that.
- weaksauce 14y agoThat is terrible. Though, I don't understand why anyone would turn on a "find my Mac" feature that has the potential to wipe your entire hard drive remotely unless you have thorough backups. Time machine is dead easy to use; try pluging in a usb hard drive and it will ask you if you want to use this as a backup drive. Arc is something that anyone on the mac should use as well for backing up priceless pictures and files. It encrypts the files locally and then sends them to your amazon S3 bucket as a backup. Easy and cheap too as you are only charged what you backup at the S3 rate(as of now it's ~0.125/GB/Month +a very small amount for put and get requests).
- loeschg 14y agoI used two-factor authentication for about a year, and I just got so sick of it. I had no issue with the whole logging in and using the time-sensitive code from my Android phone. It was the support for all the other Google apps that drove me crazy. I got really tired of needing to generate new temporary passwords for access through iCal, Mail, and I think even sites like StackOverflow. Perhaps I was at a point in life where I had too many new devices and changes going on. It's the typical security vs accessibility trade-offs. Accessibility won.
- wccrawford 14y agoPlus, don't the special passwords for specific apps (that don't use 2-factor auth) violate the whole point of 2-factor in the first place? Now, you've got several passwords that work, instead of 1 and a keyfob. Ugh. Edit: Apparently, you can't log into the web interface with those passwords. That's a step in the right direction, but still not fully secure.
- FaceKicker 14y agoThe app-specific passwords are a feature and if you prefer the extra security over being able to use apps that don't support 2-factor, then you can choose not to use them, and get the full security benefits of 2-factor. It's just that, short of expecting every single third-party client app to implement 2-factor authentication or not allowing access to any that don't, there's no alternative to the app-specific passwords. They are strictly better than using a single password for everything though, in that they are unique and strong (due to being automatically generated and 16 characters long), and easily revocable.
- Evbn 14y agoNon-web apps don't have a UI for two-factor. App-specific password is a compromise, which is vulnerable if someone steals your local installation of the client to get its keys.
- 14y ago
- esolyt 14y agoYes, it would. The idea behind two factor authentication is that an attacker now needs two things to access your account: Your password and your phone. With two factor authentication, even if an attacker acquires or changes your password (which is what happened in Matt's case), they still won't be able to login to your account.
- e40 14y agoI literally could not enter the 2-factor code into my Galaxy Nexus running 4.1.1. The process asked for my password, then redirected to Chrome to finish the process, which asked me for a code. I then switched to the Authenticator app to get the code, but then I couldn't switch back to the place to enter it. Whhaaaaa??? I tried this 3 times looking everywhere. I finally gave up and turned off 2-factor auth. I'm guessing this is a limitation in 4.1.1, but it really, really sucks.
- dtrizzle 14y agoSeveral google tools don't have support for the standard 2-factor auth. Instead, you have to create a single use password for those devices. Watch the video on Cutts blog for info on how it works.
- e40 14y agoThis was my android phone I'm talking about. It's clearly a bug in something on the phone. This isn't some "google tool". I used 2-factor auth before on my phone (a much earlier version of android) and didn't have this problem. It's the typical thing with google: being on the bleed edge is just that, a pretty unsatisfying experience. I think next time a new android version comes out, I may wait a few months before I update.