Google Rolls Out Two-Factor Authentication For Everyone.
techcrunch.com
techcrunch.com
Each re-auth requires a fresh code from the app.
I access google apps via Safari because Apple's mail app has no real search function. Since the codes expire in 60 seconds, I'm on a timer for writing it down, launching safari, refreshing to get the "login failed" screen, entering in my username and password without errors and then entering in my code. Totally doable, but irritating. Imagine you're in a hurry, and checking your email as you walk down the street. You open your client and instead of your email you get an error. The error doesn't tell you what's wrong, it just says there's a problem with your login. Hopefully you remember that 30 days ago you reset your token, and that's the problem. Now you can pause everything else, and setup your email.
Don't have a pen to write down your code while you switch apps? How's your memory?
I totally get that good security involves expiration dates, but I want things that "just work", not that "usually work".
In principle it's a great idea, and if I could choose how often it expires I'd be a happy camper.
</rant>
In the Android app you can long-press the generated code to open a context menu to copy the code into the clipboard. I'm not sure if the iPhone can support something similar, but I'll ask the developer.
Does anyone know what Google's plan is for lost/broken authenticators?
1) When you activate the service, you get a list of ten OTP codes that you should print and store in a safe place.
2) You can set up a backup phone in case your primary is lost/stolen/fails. There is a voice option, so this number does not have to accept SMS.
If you don't have the OTP codes and didn't set up a backup, and can't access any computer/device where you have access from logging in during the past 30 days:
3) You'll need to fill out an account recovery form to verify ownership of the account. Take time to answer each question to the best of your ability. The form was designed to ensure that no one can gain access to your account except you. Since Google doesn't collect a lot of information about you when you sign up for an account, we will ask you questions like when you created your account, what Google services you use, and who you email frequently (if you use Gmail) to make certain you are authorized to access your account.
I really don't trust it.
The main problem with having a list of randomly generated OTP codes is, it very obviously looks like a list of randomly generated OTP codes!
A far better approach is to use the lines of a poem, prayer or even a list of motivational slogans or a grocery shopping list. You can even get more tricky with things like not using the first character or word of the lines. You always need to assume your list of OTP's will fall into the wrong hands, so your list should be protected by at least obfuscation and plausible deniability.
You'll get a lot more bang for your buck defending against the high-probability attacks then being concerned about the theoretical, but highly unlikely vectors.
Definitely a good idea, though. Losing control of your email is the first step towards losing control of all your other online accounts.
Surprisingly it hasn't been a hassle at all-- anyone who uses their Gmail for "everything" should start using it.
It takes 15 minutes to set up (you have to / should generate tokens for each of your mobile and desktop apps, e.g. Apple Mail, iCal, Adium, Meebo, Voice, Latitude) but after that, it's super easy as long as you always have your smartphone+authenticator with you.
Spending 30 seconds extra/month/device to enter a 6-digit keycode isn't a huge price to pay for better security (at least for me-- I have one phone and one computer.)
https://cms.paypal.com/cgi-bin/marketingweb?cmd=_render-cont...
Or is there a free one available by other means?
Instead of a fake login page with 2 boxes, a phisher could just create a fake login page with 3 boxes and pass the keycode along with everything else.
The only increased difficulty in phishing, is if the user notes they're seeing a keycode prompt, decides that they probably shouldn't have to enter that again and doesn't just key it in anyway.
When we're talking about people who fall for phishing scams, does that sound all that likely? I mean, these people have a history of ignoring red flags and being blissfully ignorant to what should even raise a red flag.
Now, what two-factor will help mitigate, is casual sniffing, keylogging, shoulder-surfing and saved password cracking.
If it is only a moment in time, I assume the phishing script could simply log in at the same time and hope the user has the "once per computer" setting enabled. Though this seems like too big of something to miss. Can anyone offer some clarification?
Of course, paypal's "I lost my authenticator, log me in anyways" button is kind of defeating the purpose...
Unless I'm missing something, RFC 4226 sounds like the RSA SecurID system I've worked with before; which is essentially equivalent to Blizzard's system for World of Warcraft.
In which case, my criticism stands. It's trivially more difficult to phish a keycode and the limited window of opportunity is simply a non-issue.[1]
Unless Google is calculating a one-time pad based on the individual login attempt and sending it along a second channel to the registered user, there'll be almost no reduction in phishing.
[1] The tens of seconds a keycode is valid are more than enough to establish a connection.
Which in turn means you're more likely to get detected. It's not full protection - you'd still need a second channel for that - but it's better than nothing.
It does many good things. That is not one of them.
You can download the Google Authenticator app.
These algorithms are known. You can implement it yourself if you wanted to.
Phishing won't work if the user does not have to enter the key again. It requires a clean (no keylogger etc) initial setup. Once installed if someone phishes the end user wouldn't need to re-enter a key, thus defeating the phishing scheme.
The verification code generated is valid only for a very short time - so unless the hacker phishes the code, and uses it within 10s of seconds, the code is not valid.
And you get a lot more seconds if you log in within those 10 seconds.
Now I wish my bank would do this.
However, if you go into "Authorizing applications & sites" it has a warning box which says "An application-specific password can only be created when you are signed up for 2-step verification.", with no mention of where or how that can be done.
It'd be nice if this feature allowed me to have secondary passwords for eg google talk. I don't much care for having to hand out my full credentials just to use things like bitlbee/meebo.
http://googleblog.blogspot.com/2011/02/advanced-sign-in-secu...
>Update: Google is actually rolling this out over the next few days, so you may not see it quite yet.
If I were to lose the little thingy that lets me into my bank account, I can walk into a bank, verify myself, and get another one sent out. Simple and effective.
Can you imagine the process that you'll have to go through to get back into your GMail account after losing your phone?
Considering that you can be an AdWords customer giving them ten thousand dollars a year and still receive nothing but computer-generated form letters in response to questions about your account, I think I'll pass on this one.
If we can't simplify our users lives, we have failed. Is security hard? Hell it is. But we can do better and we MUST do better, for the love of science.
Second, can you really think of a better option? Two factor authentication like this has been used by high security institutions for years and it works quite well. Personally, it has bothered me for years that my bank does not use 2-factor identification to log in... I am certain there is plenty of room for improvement, but it is certainly non-trivial.
I did finally give in the other day and got a Nexus S. I've even talked on it a few times.
Because if not, this is pretty awesome.
(Disclaimer: I worked on the Android app.)
If you suspect your device password is compromised, you can revoke it from your Google account settings in a regular browser.
>Over the next few days, you'll see a new link on your Account Settings page that looks like this:
Yes, it's not available yet. And the second password page is very clear about what it's used for. Reading people, it helps a lot.
>But today, Google is making things much, much better for those who want it. Update: Google is actually rolling this out over the next few days, so you may not see it quite yet.
And I don't know where to find this "second password page" you speak of. There's no link in my Google account, if that's what you are referring to. How am I to read it?
Do you mean it's built into something like the Camera app?
Not sure how to make that sentence more straight forward.
I suppose this is what I get for being both a hacker and a luddite.
But this definitely will NOT work for me.
This is a good answer to those who were recently moaning that "anybody who hacks my google account can now push apps to my phone with out a confirmation!"
Quite frankly, I worry quite a bit less about hackers pushing malware to my phone than I do to people hacking into my e-mail.
I'm going to let this shake out for a while and then enable it.
In countries(China) where you need your id to get even a prepay phone there will no longer be any anominity.
Top this off with the fact that google doesn't say how often or if at all whether they give information to the chinese government because its against the law in China for them to say so.
State secrecy and all.
I personally think this should be optional and not mandatory. Otherwise I will stop using all of googles account services.
Not to mention the whole MAC address collection they did with the Streetview cams as well (allowing them to tie a MAC address and/or IP with a GPS coordinate)
I'm prepared for the down-votes on this one, but it's something to think about.
I went to set up a gmail account the other day for testing out an online game for one of my kids. It wanted to "verify" me with a real-life phone call.
So I just went over to hotmail and set up an account there instead. Sort of a blast from the past, but it was relatively painless.