I thought about it and worried about it and thought about it some more, and finally did it.
And I had no problems at all - it works really well.
I thought about it and worried about it and thought about it some more, and finally did it.
And I had no problems at all - it works really well.
After that I turned on 2FA for gmail and facebook.
Sure, it's not perfect - but no security is. But is is definitely better than using passwords alone.
Or, what if my iCloud gets hacked and my iPhone is remotely erased, can I still access my Gmail and Facebook enough to remove my phone from them?
edit: downgrade if you want to but it will be the day of my death when I let a provider dictate my needs and wants with its stupid rules and regulations. I pay for their services and barring unreasonable ones they have to provide what I need. And passing automated smsses are something that is not unreasonable.
One question, does it only block out of country automessages or do they also block 2FA messages of Turkish banks?
And not having the bank because I'm still waiting for a residence permit, which means I'm still doing the kontor thing rather than having a plan, something that's much cheaper with AVEA.
Google 2 factor authentication needs 3 things: your Google username, your password, and the token number generated by the authentication application. Stealing your phone gets one of those things.
Or, what if my iCloud gets hacked and my iPhone is remotely erased, can I still access my Gmail and Facebook enough to remove my phone from them?
You get 10 single-use codes to print out for this situation. You can revoke these code and generate new ones whenever and as often as you like.
Your concerns were all similar to what I had. Another was that I have programs that need programatic access to my Google account and I don't want to rewrite them to use 2-factor authentication. That is solved by generating a revokable application specific password.
I found that turning it on and trying it out answered a lot of concerns I had.
2 of those things, if you have an android and they're smart enough to go to Settings > Accounts
And they can get your password if you have your browser remember it.
So, potentially, losing your android could mean losing your account.
In any case, there is a fairly easy solution here: don't let your phone web browser remember your Google account password.
As a bonus, you can also use it for when logging in over ssh with password http://askubuntu.com/questions/159727/how-can-i-use-a-passco...
Anything can be hacked but it's a really solid system, even against a targeted attack and motivated attacker.
Other than stealing the phone, that is.
I'm aware of one incident (the Cloudflare hack), but that seemed to be more a vulnerability in the password reset functionality than the authentication mechanism.
SMS verification is less than ideal, though.
I know I have a printed sheet of one-time codes, but I think if an attacker compromises the phone number on my account, I'm screwed.