6 ms·
Two Factor Authentication. Please, all companies that have any of my data, don't just give me the ability to use 2FA, please force all of your employees to use
by nwenzel 11y ago
Two Factor Authentication. Please, all companies that have any of my data, don't just give me the ability to use 2FA, please force all of your employees to use it on their email, GitHub repos, everything. It should be a requirent right alongside https.
My personal favorite service is Authy, now part of Twilio.
- shard972 11y ago> Two Factor Authentication. Please My understanding is that Sendgrid isn't too keen on dongles.
- deleted 11y ago[deleted]
- hueving 11y agotoo soon :)
- vidarh 11y agoBeen long enough that it took me a while to get it...
- mtrimpe 11y agoMaybe they should just publicly fire someone to make this all go away.
- BhavdeepSethi 11y agoHow will that solve anything? The damage is already done. No point someone losing their job over this.
- cheshire137 11y agoIt was a reference to this drama from a couple years back: http://arstechnica.com/tech-policy/2013/03/21/how-dongle-jokes-got-two-people-fired-and-led-to-ddos-attacks/ http://arstechnica.com/tech-policy/2013/03/21/how-dongle-jok...
- troycarlson 11y agoThis. It's not unreasonable to flat-out require 2FA.
- atmosx 11y ago2-factor auth might be good for SendGrid but depending on another device (be it your phone or a token-device) sucks big time in the real world.
- jsmthrowaway 11y agoYour data growing legs also sucks big time in the real world.
- troycarlson 11y agoExactly. If I'm trusting a company with a core component of my business/livelihood (code repositories, email marketing campaigns, etc.), phrases like "it's a minor inconvenience" are unacceptable excuses for lax security.
- dublinben 11y agoEnterprises that are serious about security have been requiring their employees to use security tokens for years. It's not an unreasonable burden to maintain control over account access.
- toomuchtodo 11y agoSeriously? People can't be bothered to take the extra 45 seconds to open an Authenticator app and type in the current 6 digit code?
- Karunamon 11y agoSeriously, because getting into the website is one thing, getting into anything that uses an API is something else altogether. Google and Github both require the use of app specific passwords if you have 2FA on. Which means that accessing anything that uses the API is no longer a matter of username+password+token, it means username+password+log into site+generate huge and ridiculous password that is only shown once+save that into the app. It's a pain in the ass. Massively.
- toomuchtodo 11y agohttps://twofactorauth.org/ https://twofactorauth.org/
- tomjen3 11y agoYou should never use an external 2 factor app, use the Google app since it implements a standard and works offline. You will want this eventually.
- jsmthrowaway 11y agoTOTP is fairly weak. Convenient, but weak, due to the shared secret. I've seen proofs of concept that trivially lift the secrets from Google Authenticator. On the server side, the service is probably storing your TOTP secret one column adjacent to your hashed password. When done poorly (and most are), TOTP is basically no additional factor. Also backup codes, app specific passwords, etc, etc. Certain classes of non-shared-secret hardware token are waaaaaaaaay better. Just less convenient. You should look into DoD CAC, for example. Google Authenticator is nice but will never protect Secret information. I know this sounds way out of startup league, but it shouldn't; we should instead study what we can learn from such things instead of blanket advice like yours. Reiterating: none = bad, TOTP = better, strong tokens/biometric/etc = best.
- StavrosK 11y agoThe thread model TOTP addresses is someone having your password and being able to log in with just that. It's not to protect against people stealing the database, it's not to protect against people having root access to your phone, or anything like that. Which of the solutions you mention works even if an attacker has actual physical access to the two-factor device?
- elliotanderson 11y ago> I've seen proofs of concept that trivially lift the secrets from Google Authenticator. Android specific?
- ak217 11y ago> When done poorly (and most are), TOTP is basically no additional factor TOTP protects against the most common threats, and is trivial to implement compared to other solutions you refer to. Most of your complaints about TOTP security don't make sense under its threat model. Yes, if your phone is rooted, the TOTP secrets can be stolen. The point is that it's unlikely that both your phone and your laptop/point of access device both get compromised.
- biafra 11y agoA service for 2FA? I prefer a stand alone app or device for that. Why would Authy demand that I give them a phone number and an email address if not for monetizing (as in selling to anyone) my personal information?
- tracker1 11y agoSecondary factor for authenticating your authy account? In addition to your own data key. 2FA for your 2FA.
- biafra 11y agoAre you serious? This makes no sense. Does that mean Authy won't work if it has no internet connection? That would be an important limitation. I hear they do backup the seeds for 2FA. But why is that not optional?
- tracker1 11y agoIt is optional... but by validating your phone number, when you install the app, on for instance your tablet, you can authenticate the device. Backup is optional, with a client-side passphrase for encryption. It's not like it's the only app for this, 2FA/OTP is well documented with libraries in a number of languages. Is far as invasive goes, given what it is for, it's a pretty decent application.
- famousactress 11y agoYes please. One of the thing that annoys me about these notices is that they all recommend that we turn on 2FA, when the fucking root cause was that THEY DIDN'T.