5 ms·
I think there are two lessons: 1) Use Incognito when using other machines, or 2) Don't trust Google with precious things.
by damncabbage 13y ago
I think there are two lessons:
1) Use Incognito when using other machines, or
2) Don't trust Google with precious things.
- trumbitta2 13y agoUse Incognito is definetely the way to go when you borrow someone else computer
- StavrosK 13y agoI'm always paranoid that they'll have keyloggers/malware installed. I only log in to things from my phone, otherwise I don't log in.
- frankblizzard 13y agonothing beats a good old paranoia
- Achshar 13y agoTwo factor authentication can easily solve that problem. I used to feel uneasy about logging in on other systems, but now I don't mind using incognito and google authenticator.
- StavrosK 13y agoThat's true, I have two-factor auth enabled, but I still don't like how other computers can easily steal my password. Besides, between my laptop and phone, I haven't had to log in on another computer in a long time.
- umsm 13y agoMy biggest concern is not that they will get your email credentials, but the fact that they may have your email and a password to start tinkering with on banking sites, social media, etc.
- Dylan16807 13y agoHow does it solve anything when there's a checkbox right there to permanently authorize the computer to not need the second factor?
- 5h 13y agos/permanently/trust for 30 days/ Still not great, but it's not permanent. You can also log out other sessions in google apps, not sure if that resets the dont-do-2factor-auth bit though.
- Dylan16807 13y agoYou have to reenter the password in thirty days but you never need the second factor ever again (at least in some cases, which in security terms might as well be all cases). The important part is in fact permanent. I'm rather skeptical on the security offered. Edit: I'm still looking for some kind of documentation for it, but I know this firsthand. I set up two factor authentication several months ago and chrome has not asked for anything other than the password since. I can even go into the two factor settings with only my password, which gives me complete control to make unlimited single-use codes, or authenticate a different phone, or turn the whole thing off.
- Achshar 13y agoThere is no way for you to read the one time passwords. You can only disable them from dashboard or make new ones. The parent comment was about keyloggers, and the don't-require-two-factor-auth checkbox is for browser cookie session only. So there is no way for a keylogger to exploit the checkbox. The attacker can only know your email and password, not your browser's cookie data.
- Dylan16807 13y agoI was not talking about application-specific passwords. I was talking about the ability to make 'backup verification codes' which can be used anywhere a second factor is needed. Once they have your first login they have a permanent all-powerful backdoor to your account unless you go in and hit the button that resets all logins. But more importantly, your threat model is rather urealistic. Why would you trust an infected and keylogged computer to not be able to steal something as unprotected as cookies? You're right that in some kind of situation with a 'pure' keylogger you're safe, but you could get the same level of safety by doing something silly like log in with an on-screen keyboard. I think such a narrow threat model is misleading.
- Trufa 13y ago2 Step Authentication is your friend! http://www.google.com/landing/2step/ http://www.google.com/landing/2step/
- StavrosK 13y agoThanks, but I already have that. Still paranoid :P
- Apreche 13y agoAlso, LOG OUT.
- JonnieCache 13y agoIf you're using incognito mode, your session is gone when you close the window anyway.
- AlisdairSH 13y ago3) Don't let friends log into your laptop on your account. That's why guest accounts exist.