6 ms·
I was hoping for Yubikey support. But I'll take this for now. I'll have to see if the Google Authenticator app shows up on all of my iDevices linked to my Appl
by luser001 13y ago
I was hoping for Yubikey support. But I'll take this for now.
I'll have to see if the Google Authenticator app shows up on all of my iDevices linked to my Apple account and whether the code from any of them will work (from the setup process, I don't see why not). Does anybody know?
If the app will work from any of iDevices, it would not be secure enough for a service storing bitcoins :) because the second factor should be hard to copy (which a real hardware token is, while a software token isn't).
- rdl 13y agoIt's per-device, not per account (I know the guy who developed it for Google; one of the smarter people in the industry). It uses protected storage for the credential so it isn't backed up to iCloud, either. Sadly on Android they don't have the same security features available, due to limitations in the OS; it would be fun to talk to Samsung and make a "actually secure Google Authenticator" specific to the S3/S4 since they have a security element. If you do want it on multiple iDevices, you need to do that at setup time, by copying the secret manually.
- jis 13y agoThe Duo-Security people, who have an Android Token claim to use the secure element in NFC enabled phones. It is a TOTP token and can be used just like the Google Authenticator. You don't have to use Duo-Security's system to use it (though there system is worth looking at if you are rolling out your own authentication system).
- rdl 13y agoURL? I don't see anything about their android "duo push" or "duo mobile" client supporting the secure element, but their website is designed around the kind of people who buy $3/mo authentication systems (enterprise, not saas developers).
- threeseed 13y agoit would not be secure enough for a service storing bitcoins Linode was hacked twice (once where Bitcoins were stolen) in recent times and was shown to have the worst security practices I've ever seen. They have never been secure enough for storing Bitcoins.
- chc 13y agoIn fairness, I don't think that is an appreciably worse record for security than most Bitcoin exchanges.
- sithlord2 13y agoAre you serious?? What you were doing is the equivalent of living your wallet in a public place unattended, and then shouting and screaming it got stolen. You are putting your bitcoin wallet on a public accessible server, you should know the risks of this by now. Don't leave your wallet in a public place unattended, that includes your bitcoin wallet. Let me guess, you didn't bother to encrypt your wallet either, didn't you? Don't blame others for lack of security, if you can't even figure out your own security best practices...
- threeseed 13y agoAre you replying to the right person ? I don't own Bitcoins. And if I did I would never, ever host them on a Linode server.
- DigitalJack 13y agoEach copy of the software needs to be initialized with a token. Google tries to limit you to have one copy initialized at a time, but I'm not too sure how effective they are.
- devicenull 13y agoIs this an iDevice limitation? The android version doesn't connect to Google's servers at all, so there would be no way for them to know you've setup multiple copies.
- rdl 13y agoGenerally it is because sites only show you the seed once; you can't get them to give you the seed again. You can just write down the seed or enter it into multiple devices if you know this when you set it up initially, though.