Two Step Verification Will Fail Hard.

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Red Squirrel

No Lifer
May 24, 2003
67,901
12,370
126
www.anyf.ca
2FA is good for stuff that's actually critical. For example I use it with my domain names. The most important things to secure are probably your bank, domain names, and email. If one of those is hacked, they can basically end your online life.

Old, but good read:

https://medium.com/@N/how-i-lost-my-50-000-twitter-username-24eb09e026dd#.rmnlsf99v

It was Godaddy and Paypal's fault, too, so it comes to show how you can take all the precautions you want but all it takes is for some incompetent CSR to give away your info. Amazon is another company that is apparently really bad for that. All you need is someone's name and a fake address and you can basically get all their account info.
 

John Connor

Lifer
Nov 30, 2012
22,840
617
121
I use Authy for a of things. I used the Authy extension in Chrome so I don't have to go to my phone. But if I clear everything on the computer with Ccleaner and SystemNinja, then Authy will have to send me a text to verify my Authy account with all my logins.

Now here's the best part. I don't even reach for my phone. No, I stay on the computer and access the phone with Teamviewer.

Did I mention Teamviewer is using Authy too?
 

DrPizza

Administrator Elite Member Goat Whisperer
Mar 5, 2001
49,606
166
111
www.slatebrookfarm.com
Two factor authentication is great for people who like the extra security - and it does provide an additional layer of security. Idiots who are dumb enough to use the same password everywhere would benefit even more from such authentication; however, they're too stupid to understand why a code sent as a text message helps them, thus they whine about the extra step that protects their information.
 

TheGardener

Golden Member
Jul 19, 2014
1,945
33
56
In my first experience with a two step verification, I called a financial service firm. She didn't want to ask me my secret question and have me answer it. That would have been too easy. Hell I didn't even remember doing that second step verification. Instead she asks me my secret answer. I tell the women, "that is not how it is how it is suppose to work. You need to ask me the question, and I'll give you the answer." She tells me they don't have the secret question. After another minute of her babbling about policy, I say "how the hell am I suppose to know the answer, if you don't ask me the question?" I had no idea of what kind of question I chose. If asked, I could likely answered the question. So we parted ways. I called back later and spoke to someone with a reasonably rational mind.
 

John Connor

Lifer
Nov 30, 2012
22,840
617
121
Because of this thread I found out I could also Two-factor Box and Dropbox. It never did occur to me to two-factor my Google account so I did that too.

My domains are two-factored, my WordPress site, Github and a few other things.
 

poofyhairguy

Lifer
Nov 20, 2005
14,612
318
126
You have a better idea?

LastPass type vault plus a fingerprint reader. The vault app automatically creates for you a crazy long password for each site, and each of those are secured in the password vault via your fingerprint. On each site you give the vault app your fingerprint and it will blast in the unique password for you.

This is already possible on Android, and it way more practical than people making their own passwords.
 

BurnItDwn

Lifer
Oct 10, 1999
26,127
1,603
126
For work, over the last bunch of years we have been using some form of RSA token + Password combo...

It was a bit of a PITA to start but takes maybe 5 seconds nowdays. Its nothing compared to the pain of dealing with shit like sharepoint, any "atlassian tool", Remedy, Planwell or any/every other web based tool ...

Im a unix guy, give me a server and a command line and man pages, Id rather have to figure out 100 new command line arguments and tools than deal with any one of these so called tools ..
 

Naeeldar

Senior member
Aug 20, 2001
854
1
81
2FA is very easy when used with a mobile app. It's far from cumbersome and this is coming from the sales guy that had it implemented on him in the last year.

Frankly it's needed and it won't fail because not implementing is costing companies and govts. far to much $$$
 

Midwayman

Diamond Member
Jan 28, 2000
5,723
325
126
2FA has already saved my ass a couple times with all the hack running around. Get those pw reset emails once in awhile where I'm pretty sure they managed to enter the PW, but all the PW change stuff needs to go through my email with 2FA. I use a PW manager with 2FA as well and generate long and random PWs. Unlikely anyone is brute forcing them, so if they have them, they have them through a hack.
 

Spungo

Diamond Member
Jul 22, 2012
3,217
2
81
A process that makes it extremely difficult to hack your account? Yeah, what a stupid idea. Then I can't blame hackers when I get drunk and start tweeting about Jews.
 

JimKiler

Diamond Member
Oct 10, 2002
3,559
205
106

foghorn67

Lifer
Jan 3, 2006
11,885
53
91
According to this article if an identity thief takes over your mobile phone account they can then get a hold of your TFA and potentially get into your bank info.

http://www.nbcnews.com/tech/tech-news/fraud-alert-id-thieves-hijack-mobile-phone-accounts-n599761

I think this article is more hype at that point, while it could happen they provide no example of it happening. Just people getting free phones from the identity theft.
Setup a verbal password with your phone carrier.

Sent from my SM-G930T using Tapatalk
 

sdifox

No Lifer
Sep 30, 2005
96,156
15,774
126
LastPass type vault plus a fingerprint reader. The vault app automatically creates for you a crazy long password for each site, and each of those are secured in the password vault via your fingerprint. On each site you give the vault app your fingerprint and it will blast in the unique password for you.

This is already possible on Android, and it way more practical than people making their own passwords.

This is how you lose fingers.
 

Nashemon

Senior member
Jun 14, 2012
889
86
91
Google changed their scheme so now all you have to do is hit Yes on the other side and it's done. Much easier than reading and punching in digits.
I had to deal with it today. It basically told me that if I'm doing it entirely from an Android phone, all it has to do is receive the text. I didn't even have to open the message app at all.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |