Author Topic: Wish-It-Was Two-Factor Security  (Read 171 times)

Offline Thorin

  • Forum Moderators
  • Lord
  • *****
  • Posts: 5227
Wish-It-Was Two-Factor Security
« on: August 09, 2010, 11:28:32 AM »
Some (most?) of us on here are in IT, whether developer or network admin or system admin, or something.  Have you ever wondered why we get asked security questions now, or whether they're any use?  I was surprised to find background info about this on DailyWTF, of all places:

http://thedailywtf.com/Articles/Wi@%&#Was-TwoFactor-.aspx

Which just reminds me that security is incredibly easy to get wrong, as it only takes one weak link to make the security chain break. "One way to do it right, ninety-nine ways to do it wrong".
Prayin' for a 20!

Offline Darren Dirt

  • Forum Moderators
  • Royality
  • *******
  • Posts: 8034
  • urbandictionary.com/define.php?term=pineapples
    • GAFFE: Government Awareness and Freedom Foundation for Everyone
Re: Wish-It-Was Two-Factor Security
« Reply #1 on: August 09, 2010, 05:58:41 PM »
180+ comments, and one of the very earliest of them nailed it:

"Just put a post-it on the monitor!! DUH!"

aka "this kind of isn't-really-2-factor authentication encourages non-techies to just do what you are trying to prevent in the first place!" lol
DEEP: "Don't judge the world from it's people. Don't judge my hands from my gloves." -GS http://goo.gl/RaEEG http://goo.gl/j5IMn


"The secret to happiness is finding something you love and doing it well, and then being recognized for."
- George Carlin (http://bit.ly/aUchTX)

"Be so good they can't ignore you."
- Steve Martin (http://www.charlierose.com/view/interview/8831)

Offline Thorin

  • Forum Moderators
  • Lord
  • *****
  • Posts: 5227
Re: Wish-It-Was Two-Factor Security
« Reply #2 on: August 10, 2010, 10:43:04 AM »
It's interesting to read what some banks in Europe do.  For instance, sending a text message to your mobile for each transaction you want to do.  As one poster said, it's much harder to spoof your mobile...
Prayin' for a 20!

Offline Lazybones

  • Administrator
  • Lord
  • *****
  • Posts: 6804
Re: Wish-It-Was Two-Factor Security
« Reply #3 on: August 10, 2010, 07:26:13 PM »
I just get Bad Request (Invalid URL) with that link

Ha it didin't like wish it was


Offline Lazybones

  • Administrator
  • Lord
  • *****
  • Posts: 6804
Re: Wish-It-Was Two-Factor Security
« Reply #4 on: August 10, 2010, 07:39:03 PM »
At most it is brute force protection, but honestly how hard are most of those to guess or google?


Offline Thorin

  • Forum Moderators
  • Lord
  • *****
  • Posts: 5227
Re: Wish-It-Was Two-Factor Security
« Reply #5 on: August 10, 2010, 08:06:03 PM »
I just get Bad Request (Invalid URL) with that link

Ha it didin't like wish it was

Huh?  Oh, blocked at work or something?
Prayin' for a 20!

Offline Lazybones

  • Administrator
  • Lord
  • *****
  • Posts: 6804
Re: Wish-It-Was Two-Factor Security
« Reply #6 on: August 10, 2010, 09:09:48 PM »
I just get Bad Request (Invalid URL) with that link

Ha it didin't like wish it was

Huh?  Oh, blocked at work or something?

No the forum swear filter replaced the characters.


 

anything