Google Apps adds two-factor authentication via SMS
googleenterprise.blogspot.com
googleenterprise.blogspot.com
Wouldn't it make a lot of sense for Google (et al) to have this sort of authentication every time you want to change your Google Accounts password? Isn't this a pretty safe way to prevent being locked out should someone gain access to your account?
You may be thinking about costs, but this could easily be a premium service I would gladly pay for! For instance, I could charge $10 to my account, which should allow me plenty of password changes in the future. An intruder may "waste" at most one SMS, since he would not have it and until then Google should not send you any additional SMSs. Does it make sense? If it does, you Googlers in here, please pass it on!
While we're at it... how about extending this to domain registrars? This would be even more critical. I must say it, I'm pretty paranoid and by now it clearly shows. I don't know how you guys have launched successful websites and cope with this lack of safety features. I know I'm rambling, but please speak your mind on this issue.
PS: I realize things are not so bad as they could be, that probably keyloggers are rather hard to plant, etc. But it wouldn't hurt to have these features, and the companies involved would only profit, both financially and in terms of reliability.
Some people would just use OpenID to their email provider, others could pick providers who use two-factor auth of various kinds (and pay for the extra SMS costs there, without the site themselves having to support it). The really paranoid could have SecurID-style keyfobs for every site if they wanted to.
It seems it's a bit like a RSA fob as an app.. Very cool, and a concept that could be expanded. Basically, you could sell whitelabel apps and the backend service to websites that wants two-factor.
(Disclaimer: This was my project at Google.)
Deleted comment
I agree about bad password resets though. Developers need to consider a password reset mechanism as an alternative login method, and make it at least as secure.
(disclaimer: I work on the project.)
Keyloggers and password reuse are a real-world security issue. Two-factor authentication provides an extra level of protection against them.
> being locked out of your account/domain .... for most small players/home users?
The final step of configuring two-factor verification provides you with a list of one-time codes you can print. This provides a back-up way of having codes in case your phone is lost. You can keep these printed codes some place safe like your wallet or safety deposit box.
http://www.google.com/support/accounts/bin/answer.py?answer=...