Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For the second factor to mean anything, all the apps that don't support it need a password that has less rights.

Hopefully they figure out a nice way to make the rights more granular (so that a chat app can't mess with email or whatever).



Do those passwords have less rights? I figured that if any of those passwords got compromised, you were screwed (until you found out which one and revoked it).


A little less. They can't be combined with the 2nd step verification to make changes to settings that require 2 step verification.

So instead of losing access to your account, you just lose all your email (yay!).


This has always been the part I don't like about Google's 2-factor auth. Right now, I have one strong password that would have to be compromised to access my email. If I enable 2-factor, suddenly I have (last time I tried it) about 20 new passwords, any one of which could yield access to my email. That does not really seem more secure.


I think the more important question is whether it is less secure. It does make it harder to seize control of the account (which might be a lame consolation, but backups are a good idea either way), and it is (potentially) more convenient in the event that one device is lost or misplaced.

Someone who previously always logged out might be exposing themselves to more risk by storing the app passwords, but I think that's about the only case where it is worse.


It decreases the severity of a breach but increases the likelihood. Per-app passwords can't be used to take over an account. But they can be used to read my email. I think just shifting the permissions a little so that I can "authenticate" without also giving out the creds to my email would be acceptable.


Yeah, unfortunately it seems like the only rights it is missing is "update account information". Which is not much good when you are trying to protect your data.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: