Login to your Google account by scanning a QR code
accounts.google.com
accounts.google.com
https://plus.google.com/103943309878727777440/posts/DCdBqZX3...
====================
remember this url: https://accounts.google.com/sesame . next time you want to check your gmail on a public computer, don't trust even the incognito window because an installed keylogger can record your keystrokes, which unsurprisingly, include your password. use your phone to scan the qrcode on the sesame web page and hit the resultant url -- the desktop browser will automagically redirect to your logged-in gmail without entering your password. yes, i think you do need an android phone with a properly configure google account for this to work.
====================
Couldn't I just link someone to a copy of the QR code and be automagically logged in as them?
By proceeding, you give another computer access to the following accounts: * blah@gmail.com
STOP! Only proceed if you arrived at this page by scanning a login barcode at google.co. Otherwise, do not proceed!
(start with GMail) (start with iGoogle)
Will users read the warning? I would—and did—it really grabs your attention given the fact its background is yellow and takes up so much of the iPhone screen.
I suppose there are probably other safeguards as well, given that this is Google—maybe timed expiration?
[Alert] Login session has expired. Press Ok to reload.
The two step identification doesn't work if you don't have internet on your phone right?
You choose a "base password" (different from your master password) and it then generates 100 one-time passwords that you can print out and put in your wallet. So to login, the password you enter is "<base password><one-time password>". Works great. You can also make it restricted so that one-time logins can't delete anything, or change any options.
It works by requiring your normal password, plus a one time password that can either be SMS'd to your phone, generated by an Android app, or one on a list that you've pre-printed and keep in your wallet.
I don't want to deal with 2-step authentication on devices I trust (e.g., my encrypted laptop). I could switch it on and off every now and then, but with Google I'd always be typing my normal password (for me, generated by KeePassX and impossible to memorize) when doing the 2-step thing, right?
You get read only access with your OTP, and if you want to do something destructive or otherwise important, log in again with stricter authentication.
Making all of your account available all of the time from one basic login seems like quite a bad idea for a sensitive account.
The phone app could be also be used for your own projects. It supports multiple accounts and either manual or QR-code based configuration.
Google provides a PAM module so you can add 2-factor auth to ssh. And it is easy to implement the standard on the server side, if you want to add 2-factor auth to your web app.
For more info, see:
Works fine on my iPhone with RedLaser to scan the QR. It just redirects to Safari which "remembers" my login info.
That's not the case. Presumably accessing the QRCode generates a single use URL, which you can access in the computer browser. There is no client side logic.
(Also, Google generally ships stuff on both iOS and Android)
(Also, it goes against Google's interest to restrict Google account features to Android)
There have to be some though. I.e. you have to be logged in to Google on your phone.
My question is, what is http://goto.google.com anyway? It looks like a Google employee portal.
What happens if the computer has a hacker's self-signed certificate for https://accounts.google.com installed and the hacker sets up a man-in-the-middle style attack?
The hacker's browser asks Google for a QR code and it gets sent to your browser. When you scan the code and authorise from your phone, the hacker's browser would be logged into your Google account.
What it protects against is basic key logging attacks (software and hardware). These are the most likely attack you can expect to see, so protecting against them has real life value.
The safest thing you can do is never use an untrusted machine to access important accounts.
I can't see a compelling use case for this. It would be more useful to have my phone generate a one-time password without requiring to be connected.
Not enamored with QR codes as a solution, though; I still maintain that the vast majority of Americans have no idea what they are and find them, in general, to be a gimmicky pain in the rear. I agree that what you described would actually be more useful, but also probably harder to do (offline = native app).
If you are overseas, roaming costs are crazy. I'd consider paying them to download a single .png (QRCode) and then use an untrusted computer.
A logical next step would be an app that can streamline the auth a bit (have your username prefilled from the Android account) and send the auth to Google via SMS (often easier and cheaper than getting started with dataroaming).
They might not be able to change your password (if you have 2-factor auth), but they could read/forward all your mail, delete documents, etc.
This isn't enough to work on untrusted computers on untrusted networks (but it's still damn useful for fast-login).
You're then reading the QR code on what is assumed to be a trusted device on a trusted network (your mobile phone). The QR code would have to link to a bogus website mascarding as google in order to intercept your username & password. It requires a degree of vigilance on the part of the user at this point to ensure that the login page is genuinely google, but anyone using this auth mechanism must be reasonable security conscious to start with.
By your assertion, the only solution is to not use untrusted computers / networks at all. In the event that you have to this is one way to do so more securely.
If you're this distrustful, don't use the computer. This entry only seems to prevent keylogging attacks.
Visit the site and leave it open for a few minutes, and you'll get an expiration popup. So, people aren't going to be rummaging through the cache or snapping a screenshot at the cafe and going home and logging in as you.
Glad to see my concept isn't too off the wall
On iPhone, the process isn't as smooth. You'll be taken to a web-based login page to enter your account info. However, it seems to be buggy as if you're logged into one account on your desktop and another account on your mobile weird stuff happens.
Isn't that how its supposed to work? That's how it works on my Nexus S. Much hassle... Would be better to have an app that does that automatically (since android is pretty much always logged in but the phone browser pretty much never is).
Hi there - thanks for your interest in our phone-based login experiment. While we have concluded this particular experiment, we constantly experiment with new and more secure authentication mechanisms.
Stay tuned for something even better!
Dirk Balfanz, Google Security Team.
While we have concluded this particular experiment, we constantly experiment with new and more secure authentication mechanisms.
Stay tuned for something even better!
https://accounts.google.com/sesame/uc?s=vlrPimUVe5-LGarBtJxU...
The `s` parameter is changed with every refresh, but the majority of the URL remains constant.