Two Step Verification Will Fail Hard.

Page 3 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.
Oct 25, 2006
11,036
11
91
It'll fail because it's cumbersome to you and because some people use shitty passwords? Yeah, no. Also, I don't get why it matters how strong the password is... isn't that part of the point of 2-step?

2 Factor doesn't always authenticate. Gmail/Banks/etc etc tend to give your computer a 30 day cookie where you don't have to 2 factor login again. So anyone local who knows your "12345" password can still trivially login.

2 Factor works against remote login attempts so you should still have a strong password.
 
Last edited:

Ichinisan

Lifer
Oct 9, 2002
28,298
1,234
136
According to this article if an identity thief takes over your mobile phone account they can then get a hold of your TFA and potentially get into your bank info.

http://www.nbcnews.com/tech/tech-news/fraud-alert-id-thieves-hijack-mobile-phone-accounts-n599761

I think this article is more hype at that point, while it could happen they provide no example of it happening. Just people getting free phones from the identity theft.

Without 2FA on your email account, they could take over the email account and gain access to everything else through password resets.

No need to target your phone in that case.

Also, that wouldn't work for me. Gaining access to my phone number to get my texts wouldn't work because I don't do 2FA via text. I use 2FA with the Google Authenticator app. It's set to use time based cypher, so I don't even need a mobile data connection or WiFi signal.

Dropbox and Hotmail work fine with my Google Authenticator app. I'm pretty sure Microsoft has a free multi-platform Authenticator app too.
 
Last edited:

stlc8tr

Golden Member
Jan 5, 2011
1,106
4
76
2 Factor doesn't always authenticate. Gmail/Banks/etc etc tend to give your computer a 30 day cookie where you don't have to 2 factor login again. So anyone local who knows your "12345" password can still trivially login.

2 Factor works against remote login attempts so you should still have a strong password.

If you're that worried about a local attack, you can set a password for your PC or configure your browser to wipe cookies periodically.
 

Charmonium

Diamond Member
May 15, 2015
9,587
2,951
136
I called one of my credit card companies a few days ago, Citi I think, and they asked if they could voice print me. I said yes.

This will probably be the next thing in biometrics.
 

biostud

Lifer
Feb 27, 2003
18,406
4,967
136
I use it for google and microsoft accounts. And we have a public NemID (EasyID) two step verification system in Denmark you use with all public servives, banks, insurance etc. You get a small piece cardboard with a lot of one times codes you use, combined with your social security number and personal password, and when there's 30 codes left on your card they'll send you a new one. Or you can buy an electronic number generator if you use it a lot.
 

JimKiler

Diamond Member
Oct 10, 2002
3,559
205
106
Without 2FA on your email account, they could take over the email account and gain access to everything else through password resets.

No need to target your phone in that case.

Also, that wouldn't work for me. Gaining access to my phone number to get my texts wouldn't work because I don't do 2FA via text. I use 2FA with the Google Authenticator app. It's set to use time based cypher, so I don't even need a mobile data connection or WiFi signal.

Dropbox and Hotmail work fine with my Google Authenticator app. I'm pretty sure Microsoft has a free multi-platform Authenticator app too.

What is the google 2FA app? That is an app and not a dongle like RSA keychains right?
 

Adul

Elite Member
Oct 9, 1999
32,999
44
91
danny.tangtam.com
2factor when made easy is good I like how it is setup for Microsoft multi-factor auth, blizzards updated authenticator, and a couple of others I have used. Simple to use and increases security greatly.
 

stlc8tr

Golden Member
Jan 5, 2011
1,106
4
76
What is the google 2FA app? That is an app and not a dongle like RSA keychains right?

Yes, it's an app.

https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en

It's time-based so no network access needed.

Alternatives include Authy.

https://play.google.com/store/apps/details?id=com.authy.authy&hl=en

Authy allows for multi-device linking so you can have the codes appear on all of your devices (including your browser). (There's a hack to do this for Google's app but it's much easier to do with Authy.)
 

TheGardener

Golden Member
Jul 19, 2014
1,945
33
56
I called one of my credit card companies a few days ago, Citi I think, and they asked if they could voice print me. I said yes.

This will probably be the next thing in biometrics.
So far I was asked once, and I declined. Of course just about every call that one makes to a customer service department is recorded. So if they want, they could pull a Microsoft by ignoring my opt out and do it anyway.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |