4 ms·
Be honest. When was the last time you were sitting at your (or any other) machine while away from your mobile phone? Also, you only need the authenticator revo
by staticfish 14y ago
Be honest. When was the last time you were sitting at your (or any other) machine while away from your mobile phone?
Also, you only need the authenticator revolving token every 30 days.
- peterwwillis 14y agoWhat do you mean you only need it every 30 days? You keep the same session active for 30 days?! (And yes, I don't keep my phone next to me when i'm at home. Half the time i'm trying to figure out where the hell I left it)
- paulgb 14y agoIt will remember that it's authorized across multiple logins/logouts as long as you don't delete the cookie.
- peterwwillis 14y agoSo it's basically the same security as adaptive authentication (aka challenge questions) but with the added annoyance and security flaws of using either SMS or an app. With adaptive authentication, you basically add a series of heuristics based on the browser's request to calculate a number. A ratio applied to that number determines the likelihood that a user is the same as the one who has logged in before. If the ratio is not close enough, challenge questions are asked of the user to verify they are the real user. The number is cached both on the server side and in the browser. As long as the number stays the same, and the heuristics of the browser's request stay the same, no additional challenge questions are asked upon logging in again. This also times out after a period of time, so eventually the user must be challenged again. The difference between that and Google's method is the idea that the SMS and/or App are "something you have" instead of an additional "something you know". But since the challenge questions can be anything (including made-up information that is fake and nobody would ever guess - like a second password), there isn't the same risk as with losing a traditional password, and it isn't something an attacker can find out by social engineering or research. As we've seen before, you can intercept SMS/voice two-factor auth, and Android malware is rampant. But the only way to get a challenge answer is to use lead pipe cryptography or intercept it at the computer - and once they have your computer it's game over. How secure your authentication is comes down to how you implement it. I will stick with my trusty dumb physical token and challenge questions as that is the most difficult method to attack.
- paulgb 14y agoI accept your criticisms of SMS for authentication (I recently switched from SMS to the Android app), but I like two factor better than the approach you describe. If I log on to GMail from a public computer at a library with a keylogger installed, they will obtain my password but not enough to log in as me after I have signed out. Under the scenario you describe, I'd also type the answer to a challenge question, and they'd have both the password and the answer to the challenge question. That would leave me in a significantly worse position.