Mailchimp offers 10% discount for using 2-factor security
blog.mailchimp.com
blog.mailchimp.com
“Previously, we gave a 2% discount, which was probably only significant for high volume senders. 10% makes it significant for everybody.”
However, I'm still not doing it – too much hassle. Instead, I just have 1Password create unique passwords for each service I use and change the passwords once in a while.
That said: I'm a satisfied MailChimp customer and I really appreciate that they continue to improve their service.
And I think LastPass also supports multiple Identities, though I'm not sure how that works.
It's important to note that Google Authenticator wasn't yet open for integration (trust me--we badly wished for it). There were only rumors that they might open it up, and frankly, we couldn't wait for them to decide. Now we all know that it's been opened up, which is nice. And fwiw, in the next couple days we'll be announcing support in Alter Ego for Google Authenticator and Yubi Key pass-through.
Someone mentioned Duo. That's an impressive app. We didn't know it existed until after we launched AlterEgo (their CEO introduced himself in the comments when we launched AlterEgo). I was blown away by what a thorough app it was. Still, it wasn't "free enough" for our users (Gasp! How dare they charge money?!?). Remember, we wanted maximum usage, so it was important to make a free app. We could theoretically and happily do a pass-through integration for Duo users too.
Someone mentioned the uncertainty of relying on a Google service, considering Google's recent "spring cleaning" of Google Reader. Roughly around the time we launched AlterEgo, I don't remember all that much spring cleaning going on at Google, so I can't say we had concerns they'd kill their 2FA service. I vaguely recall them deprecating the Google Translate API (which we heavily relied on) and I vividly remember them sending us a ginormous bill for using their Maps API. Larry Page hadn't yet made his "more wood behind fewer arrows" statement, but the writing was on the wall that we can't all just feast off of Google's generosity and altruism forever. So at that time, I think we were more concerned about Google eventually charging us for the service (God forbid, right?). If we had even tens of thousands of users activating, that would be a bit expensive.
Hope that explains things.
Happy to hear MailChimp is investing in data protection. You can bet Ill be enabling it. Keep up the great work.
For example, here's a debug tool written in Javascript that has been online since early 2011: https://google-authenticator.googlecode.com/git/libpam/totp....
Google Authenticator is not a service that Google can even shut down. It's an open-source implementation of open standard protocols.
You install a library + few tens lines of code on your server, and users install the app on their phone. After this, no Google server or service is ever touched in the authentication process.
Even if Google decides to pull the app from the store, it's open source: you can build it from source and put a copy up yourself.
Duo's app is actually better than GA by allowing rearrangement of accounts, which is a long-standing open bug in GA.
On Android, there is no rearrangement possible. There's no "edit" button like there is on the ios version, that enables dragging accounts around.
https://code.google.com/p/google-authenticator/issues/detail...
They basically claim everything else was too difficult for people to use - which is funny considering the other companies[2] using Google Authenticator. They also call it "1.5-factor authentication", which is kind of unsettling.
AlterEgo is a closed-source online-only service provided by MailChimp, while Google Authenticator is an offline, open-source, standards-based, two-factor security solution that anyone can implement on a wide range of platforms. You'd have to want less compatibility, less reliability and less security to use AlterEgo.
[1] http://blog.mailchimp.com/introducing-alterego-1-5-factor-au...
Edit: Nope. Just confirmed Google Authenticator was released in February 2011 [1], and AlterEgo was released May 2011 [2].
[1] http://techcrunch.com/2011/02/10/google-rolls-out-two-factor...
[2] http://blog.mailchimp.com/introducing-alterego-1-5-factor-au...
Just make sure that whatever you rely on can be substituted for another system and you're good to go. You depend on that service but on the off chance that it's discontinued your business is not at risk.
I'm genuinely curious to hear the argument.
In other words, if a user uses a high entropy password, there's a better chance that they're not reusing it elsewhere, thus improving security.