Jump to content

Recommended Posts

Posted (edited)

Hi all,

 

I wondered if anyone knew of other approaches to Google's Two Factor Authentication.

 

My issue with Google's 2FA approach is that you can just "trust" a device. In my head, that doesn't really make it any more secure if the device is stolen. Yes, you can just login and "untrust" the device, but equally you can just reset a password and sign out of all sessions? They used to only remember for 30 days but this option seems to be gone now.

 

I wondered if anyone used other approaches (on Google Apps for Education); ideally I would like a PIN style approach; like online banking, where it asks for the nth letter(s) in a piece of memorable information.

Edited by riverphoenix12
Posted (edited)
I wondered if anyone knew of other approaches to Google's Two Factor Authentication.

I use a physical Yubikey U2F Security Key (£12.99) to sign into my personal Google Apps account. It works in Chrome and on any device running Chrome OS.

 

http://a.pomf.se/wulacl.png

 

In the future I think you'll also be able to use the same key to sign into Windows 10 PCs.

 

I also use the Duo Mobile app on my smartphone to generate one-time passwords just in case I lose the key or I am not using Chrome.

 

If my phone is stolen I can remotely wipe it.

 

ideally I would like a PIN style approach; like online banking, where it asks for the nth letter(s) in a piece of memorable information.

That approach isn't particularly good in terms of security. Visa and MasterCard are going to stop using passwords that work the way you describe because it isn't secure enough.

 

http://threatpost.com/visa-mastercard-removing-passwords-from-3d-secure/109393

Edited by Arthur
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...