Two million Facebook, Gmail and Twitter passwords stolen
money.cnn.com
money.cnn.com
I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient.
I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...
What if Google started charging people (only ones with credit card on file which means they are in place with necessary infrastructure) $5 a year for NOT using 2 factor authentication... I guess I can dream...
(Just wondering, as the above are the reasons I decided not to use it)
So, your laptop that's logged into GMail will stay logged in when you're out of the country. Unless you explicitly log out, it will stay this way.
I enter maybe one two-factor auth code a week, if that.
So:
i) Prepare ahead and log into your services.
ii) Walk to the nearest window, get the code, and go back to your desk.
iii) Replace your phone - you keep your number - request the auth key again.
None of these are completely seamless of course, but the idea is that all of the above happen rarely enough, and are mitigable enough, that it's far better than the alternative: getting pwned.
There are also second factors in the form of mobile apps, which eliminate the need for SMS, so as long as you have data/WiFi you're set. There are also ones that don't need data at all (see: the Battle.net Authenticator, which is basically a RSA key on your phone), but require more substantial initial setup.
The Google Authenticator mobile app doesn't require data, so that meets the OP's requirements perfectly (ie, no SMS or data).
Use that, print out the one-time use codes and keep them in your wallet.
AS for theft, you have backup codes which you should store securely (in a Truecrypt file with multiple backups or something), which allow you to log into your account once per code.
I've always felt like putting all your passwords in one place defeats the purpose of memorizing separate, secure passwords (or, better yet, pass phrases).
That's one of the nice things about password managers. You reduce the number of potential points of failure from many to one. Why is this good? Think of Thermopylae. You increase the stakes, but you also dramatically improve your ability to fight back.
The idea is that password managers should meet both these goals as well.
All the articles I've found are at least a couple months old.
But maybe there are simpler alternatives. Maybe passwords shoudn't mean anything, just like losing a key on a busy street is not exactly a security threat to its owner, password leaks shouldn't be harmful. Maybe the problem is not how passwords are stored or encrypted but how meaninful our 'ids' are - and how they are attached to that password.
Of course, you should take care to shield your screen while you type the password, or use a combination of mouse+keyboard when entering it.
Saying that, I'm sorry to hear you got locked out! How inconvenient.
I figure my job is to protect my username and password, so that's exactly what I do, secure them, and have backups. What I don't expect is getting locked out of my account when I have the valid username and password to login. Also, Google provides zero support. I generate them at least $20k a year in profits off advertising, and I lose my Gmail account for no reason. Anyway, I'm done with them, and switching to alternatives.
As for password managers, I think it would be cool if the browser &/or websites could figure out a way to launch a default password manager installed on the computer (or in the cloud?) and auto-populate a strong password and enter it into the manger. Way more people would use best practices if they were virtually automatic.
Maybe possible with 2-factor-auth, but it would still require me to input my password on an untrusted device. No.
At any time you'd have two passwords: one regular, which you use every day; and one for one-time-use only, which you keep around in case of need.
When sitting at an untrusted computer, you use your one-time-use password. This proves your identity, but also immediately expires your one-time-use password. Next time you want to generate a usable one-time-password you'll have to login with your regular password again.
Is that it?
But they don't require my normal password to be entered at all. I'd accept punching in my real password or a code on my phone to generate the smart token, since the time required to brute force something like that would be give me plenty of time to revoke it's authorization.
Nothing quite like a hands-on demo.
http://blog.spiderlabs.com/2013/12/look-what-i-found-moar-po...
May be at CNN, that is what they use to work from home.
define( 'FS_METHOD', 'direct');
318,000 Facebook accounts
70,000 Gmail, Google+ and YouTube accounts
22,000 Twitter accountsOr: "Two million passwords stolen, including from Facebook, Gmail, and Twitter".
The real story: Personal computers were infected, passwords were keylogged. yawn
The point is lastpass is designed to protect you from weak passwords and password reuse. It doesn't do anything to protect against attacks on your actual computer.
I think the main point was that a password manager would have been much less susceptible to the keylogger attack which lead to this particular incident.
Apparently this one:
http://malware.dontneedcoffee.com/2013/10/jolly-roger-steale...
You know... for science.
Apparently this keylogger was used:
http://malware.dontneedcoffee.com/2013/10/jolly-roger-steale...
Is that a Windows only issue or are other OSes affected?
I wonder if connected..
> The hackers set up the keylogging software to rout information through a proxy server, so it's impossible to track down which computers are infected.
Have I missed something or are these statements contradictory?
The sad part is that many people with this keylogger may react to the password change before/without removing the logger, which would entirely defeat the point.
http://blog.spiderlabs.com/2013/12/look-what-i-found-moar-po...
The ADP employee site hasn't changed in the past ten years and still uses basic auth. It's horrible. And freaky. When you login to your new company account, it shows all paystubs from your past employers too. [With the implication of your current payroll department being able to see how much you were getting paid at all your previous jobs since it's the same account?]
The article here says that the account information that was compromised can. I'm not sure if that is a result of bad reporting on the same level as that related to FTP in the article, or the accounts that were compromised are different than the ones for the website you are talking about.
The more power you wield in an organization the less competent with technology you are.