TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Thoughts on Twitter's new Two-Factor Authentication

99 pointsby cveigtalmost 12 years ago

9 comments

abalonealmost 12 years ago
Not a tremendously compelling argument, and I think the company may come to regret the know-it-all tone of the post. Hubris is not what you want in a security platform company.<p>The author cites two &quot;flaws&quot;:<p>1. Your phone is offline sometimes.<p>Twitter has a backup code mechanism that covers this case. They talk about it, right in the post.<p>2. An attacker can send verification requests that look exactly like yours.<p>The sole use case for this mechanism is to verify login attempts by the phone&#x27;s owner in <i>real-time</i>. If a verification request comes in and you&#x27;re not actually trying to log into Twitter, or if you see more than one, you know you&#x27;re being attacked.<p>It&#x27;s true if you share a login among multiple coworkers then you&#x27;re vulnerable to being tricked. But that&#x27;s a bad practice to begin with, and this 2-factor system is still a massive improvement in security even for that scenario.
评论 #6176729 未加载
dmixalmost 12 years ago
Neither TOTP (Google Authenticator) or Twitter factor in how easy it is to malware&#x2F;root Android phones these days. I still prefer Yubikey or other opensource cards until the state of mobile security improves (for ex SEAndroid).
评论 #6174888 未加载
评论 #6174760 未加载
评论 #6175949 未加载
sbarrealmost 12 years ago
My first experience with the new two-factor auth has been poor.<p>1. I sign into Twitter with my browser<p>2. My phone receives a push notification saying that I have a pending auth request.<p>3. So I click it and load the Twitter iOS app, and I see &quot;You have no login requests&quot; for that account, no matter how much I refresh it (it has been 10 minutes now).<p>4. Now I can&#x27;t get into my Twitter account on the browser.<p>The urge to disable it is certainly strong..
评论 #6175056 未加载
评论 #6176063 未加载
elliottcarlsonalmost 12 years ago
Would one possible solution be to show a random word on the screen and add that as part of the authentication request? This would allow it to pair up with what you currently see on the screen and keep it simple enough where IP address or other technical details aren&#x27;t required to be known.
评论 #6174543 未加载
theg2almost 12 years ago
I know Twitter did this (primarily) in response to the AP hacking, but I fail to see how this change is going to help organizations (say...news) with multiple people sharing an account for business purposes.<p>We want to secure with 2 factor here in our offices, but it involves giving 10 people the app and possibly getting spammed every time someone logs in. I realize they went for this approach rather than have your average user type in numbers but I can&#x27;t help but feel confused by this move.
评论 #6176689 未加载
kylelibraalmost 12 years ago
For anyone who is interested in implementing two-factor authentication, Authy (company behind blog post) is quite easy to use. I recommend it.
评论 #6175412 未加载
bpicoloalmost 12 years ago
Not sure why there are complaints about it only working when the phone is online. Twitter will only work with a phone online anyway.
评论 #6174517 未加载
评论 #6174501 未加载
评论 #6175366 未加载
umsmalmost 12 years ago
I have a bad feeling that one of these days we will lock ourselves out of our own accounts...
zobzualmost 12 years ago
Mozilla Personna also uses pub&#x2F;private key pairs, btw. And it seems just fine.<p>OTPs are great and all but in the end you keep the damn unhashed secret on all machines that have to accept the OTP.