Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.mobile.android > #57320 > unrolled thread

8MB sms pic

Started byK120 <hunterfox@interweb.net>
First post2018-11-08 10:52 -0500
Last post2018-11-17 10:30 -0500
Articles 20 on this page of 170 — 15 participants

Back to article view | Back to comp.mobile.android


Contents

  8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-08 10:52 -0500
    Re: 8MB sms pic KenW                                        <ken1943@invalid.net> - 2018-11-08 09:11 -0700
      Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-08 22:31 +0000
        Re: 8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-09 17:07 -0500
          Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-10 02:36 +0000
            Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-11 11:34 +0000
              Re: 8MB sms pic Andy Burns <usenet@andyburns.uk> - 2018-11-11 11:47 +0000
                Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-11 13:08 +0100
                  Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-11 17:23 +0100
                    Re: 8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-11 12:37 -0500
                      Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-11 19:19 +0000
                        Re: 8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-11 16:34 -0500
                          Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-12 07:53 +0000
                            Re: 8MB sms pic Andy Burns <usenet@andyburns.uk> - 2018-11-12 08:11 +0000
                      Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-12 02:29 +0100
                        Re: 8MB sms pic Piet <www.godfatherof.nl/@opt-in.invalid> - 2018-11-12 12:22 +0100
                          Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-12 14:02 +0100
                            Re: 8MB sms pic Piet <www.godfatherof.nl/@opt-in.invalid> - 2018-11-12 20:01 +0100
                              Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 02:27 +0100
                                Re: 8MB sms pic Piet <www.godfatherof.nl/@opt-in.invalid> - 2018-11-13 10:51 +0100
                                  Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 11:05 +0100
                                    Re: 8MB sms pic Piet <www.godfatherof.nl/@opt-in.invalid> - 2018-11-13 12:39 +0100
                            Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 19:02 -0700
                          Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-12 21:16 +0100
                          [OT] Ping: Piet (was: 8MB sms pic) Frank Slootweg <this@ddress.is.invalid> - 2018-11-15 22:10 +0000
                            Re: [OT] Ping: Piet Piet <www.godfatherof.nl/@opt-in.invalid> - 2018-11-16 09:46 +0100
                              Re: [OT] Ping: Piet Frank Slootweg <this@ddress.is.invalid> - 2018-11-16 11:50 +0000
                      Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-12 06:19 +0100
                    Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-12 02:20 +0100
                Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-11 17:21 +0100
                  Re: 8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-11 16:44 -0500
                    Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-12 06:21 +0100
                    Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-12 08:17 +0000
                  Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-12 02:32 +0100
                    Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-11 20:47 -0500
                    Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-12 06:27 +0100
                      Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-11 23:40 -0700
                        Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-12 19:02 +0000
                        Re: 8MB sms pic Andy Burns <usenet@andyburns.uk> - 2018-11-12 19:07 +0000
                          Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-12 21:28 +0100
                            Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-12 21:21 +0000
                              Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 20:25 -0500
                                Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 02:29 +0100
                                  Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 20:39 -0500
                                    Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 08:11 +0100
                                      Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 09:03 -0500
                                        Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 15:40 +0100
                                          Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-13 15:50 +0000
                                            Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 11:13 -0500
                                              Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-13 10:26 -0700
                                                Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 13:08 -0500
                                                  Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-13 11:43 -0700
                                                    Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 13:49 -0500
                                                      Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-13 12:06 -0700
                                                      Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-14 08:28 +0000
                                                        Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 09:15 -0500
                                                          Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-14 10:17 -0700
                                                            Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 12:53 -0500
                                                              Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-14 15:38 -0700
                                                                Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 00:04 -0500
                                                                  Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 00:25 -0700
                                                            Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-14 18:46 +0000
                                                              Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-14 15:38 -0700
                                                                Re: 8MB sms pic chris <ithinkiam@gmail.com> - 2018-11-15 18:57 +0000
                                                                  Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 12:37 -0700
                                                                    Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-15 22:40 +0000
                                                                      Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 16:06 -0700
                                                                  Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-15 21:14 +0000
                                                                    Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-15 22:16 +0000
                                                          Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-14 18:41 +0000
                                                            Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 14:33 -0500
                                                              Re: 8MB sms pic chris <ithinkiam@gmail.com> - 2018-11-15 18:57 +0000
                                            Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 18:48 +0100
                                              Re: 8MB sms pic Chris <ithinkiam@gmail.com> - 2018-11-13 18:36 +0000
                                                Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-13 20:32 +0000
                                                  Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 15:49 -0500
                                                Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-16 14:30 +0100
                                      Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-13 15:12 +0000
                                        Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 10:21 -0500
                                        Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 18:51 +0100
                                Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 19:22 -0700
                                  Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 21:42 -0400
                                    Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 19:54 -0700
                                      Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 22:06 -0400
                                        Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 20:26 -0700
                                          Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 22:40 -0400
                                            Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 21:23 -0700
                                              Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 23:32 -0500
                                                Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-12 22:21 -0700
                                                  Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 00:50 -0500
                                                    Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-13 08:18 -0700
                                                      Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 19:02 +0100
                                                  Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 09:29 +0100
                                                    Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-13 08:18 -0700
                                                Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 08:27 +0100
                                              Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-12 23:34 -0500
                                                Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 09:32 +0100
                                                  Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 09:08 -0500
                                                    Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 15:43 +0100
                                                      Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 09:54 -0500
                                                        Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 19:08 +0100
                                                          Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 13:22 -0500
                                                            Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-13 18:31 +0000
                                                              Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 13:49 -0500
                                                                Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-13 19:16 +0000
                                                                  Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 14:24 -0500
                                                                    Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-14 09:34 +0100
                                                                Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-14 09:31 +0100
                                                                  Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 09:15 -0500
                                                                    Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-14 17:28 +0000
                                                                      Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 12:53 -0500
                                                                        Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-14 18:47 +0000
                                                                          Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 14:33 -0500
                                                                      Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-14 19:00 +0000
                                                                        Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-14 14:33 -0500
                                                                          Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-14 15:38 -0700
                                                                            Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 00:04 -0500
                                                                              Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 00:25 -0700
                                                                                Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 12:09 -0500
                                                                                  Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 12:53 -0700
                                                                                    Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 15:08 -0500
                                                                                      Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 15:03 -0700
                                                                                        Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 17:10 -0500
                                                                                          Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 15:40 -0700
                                                                            Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-15 16:27 +0000
                                                                              Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 12:09 -0500
                                                                                Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-15 19:01 +0000
                                                                                  Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 14:51 -0500
                                                                                    Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-15 21:11 +0000
                                                                                      Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-15 16:47 -0500
                                                                                        Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-16 14:43 +0000
                                                                                          Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-16 13:11 -0500
                                                                                    Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-17 01:10 +0100
                                                                                      Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-16 20:10 -0500
                                                                                        Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-17 11:24 +0100
                                                                              Re: 8MB sms pic 123456789 <12345@12345.com> - 2018-11-15 10:32 -0700
                                                                        Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-16 14:48 +0100
                                                            Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-14 09:34 +0100
                                                      Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 18:05 +0100
                                                        Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 19:10 +0100
                                                          Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 13:22 -0500
                                                            Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-16 15:03 +0100
                                            Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 08:23 +0100
                                              Re: 8MB sms pic "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> - 2018-11-13 11:40 +0000
                                                Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 15:46 +0100
                                        Re: 8MB sms pic Andy Burns <usenet@andyburns.uk> - 2018-11-13 06:35 +0000
                                        Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 08:17 +0100
                                          Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 09:03 -0500
                                            Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 15:37 +0100
                                      Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 06:12 +0100
                                        Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 00:21 -0500
                                          Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 11:57 +0100
                                        Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 09:34 +0100
                                          Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 11:59 +0100
                                            Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 15:38 +0100
                                    Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 06:08 +0100
                                      Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 00:21 -0500
                                      Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 09:34 +0100
                                    Re: 8MB sms pic "Carlos E. R." <robin_listas@es.invalid> - 2018-11-13 08:12 +0100
                                Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-13 06:06 +0100
                                  Re: 8MB sms pic Frank Slootweg <this@ddress.is.invalid> - 2018-11-13 15:04 +0000
                      Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-12 10:54 +0100
                      Re: 8MB sms pic M.L. <me@privacy.invalid> - 2018-11-13 06:59 -0600
                        Re: 8MB sms pic nospam <nospam@nospam.invalid> - 2018-11-13 09:03 -0500
          Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-11 13:11 +0100
            Re: 8MB sms pic Joerg Lorenz <hugybear@gmx.ch> - 2018-11-11 17:27 +0100
              Re: 8MB sms pic "Carlos E.R." <robin_listas@es.invalid> - 2018-11-12 02:37 +0100
    Re: 8MB sms pic KenW                                        <ken1943@invalid.net> - 2018-11-08 09:19 -0700
    Re: 8MB sms pic musika <mUs1Ka@NOSPAMexcite.com> - 2018-11-09 11:48 +0000
    Re: 8MB sms pic K120 <hunterfox@interweb.net> - 2018-11-17 10:30 -0500

Page 7 of 9 — ← Prev page 1 2 3 4 5 6 [7] 8 9  Next page →


#57553

Fromnospam <nospam@nospam.invalid>
Date2018-11-15 15:08 -0500
Message-ID<151120181508203581%nospam@nospam.invalid>
In reply to#57552
In article <pskirk$jil$1@dont-email.me>, 123456789 <12345@12345.com>
wrote:

> >> Getting an SMS code for devices that can't receive a text isn't a 
> >> problem for me since my phone's always nearby. Is that really a 
> >> problem for you?
> 
> > it's more convenient to click and instantly obtain a code via an app
> >  running in the background on a laptop/desktop versus waiting for a 
> > text message to a phone,
> 
> Convenience? Mine is quite convenient. *NO APP* to install and
> configure.

a couple of seconds. the horrors.

> And only *ONE* 2FA SMS text to certify the browser and I'm
> DONE and ready to go...

which goes to the phone, not the computer you're actually using.

whether a site requires a code each time or once for some period of
time has nothing to do with sms versus totp.

if it doesn't require a code each time, then you're vulnerable should
the computer be lost or stolen, or someone has access and is snooping
around.

one site i use offers an option to not ask for another totp code for 30
days. another is 2 weeks. some sites require a code every time and
offer no choice. none are sms. it's certainly possible for a site to
authenticate for years, but that would be a risk for both parties.

> I can't argue that 2FA SMS is more secure than your system but
> CONVENIENCE?? Not so much.

it's more convenient when it's on the same device, especially if
someone uses the autofill option (not required, but available).

[toc] | [prev] | [next] | [standalone]


#57558

From123456789 <12345@12345.com>
Date2018-11-15 15:03 -0700
Message-ID<pskqfs$44c$1@dont-email.me>
In reply to#57553
On 11/15/2018 1:08 PM, nospam wrote:
> 123456789 <12345@12345.com> wrote:

>>>> Getting an SMS code for devices that can't receive a text isn't
>>>> a problem for me since my phone's always nearby. Is that really
>>>> a problem for you?

>>> it's more convenient to click and instantly obtain a code via an
>>>  app running in the background on a laptop/desktop versus waiting
>>>  for a text message to a phone,

>> Convenience? Mine is quite convenient. *NO APP* to install and 
>> configure.

> a couple of seconds. the horrors.

>> And only *ONE* 2FA SMS text to certify the browser and I'm DONE and
>> ready to go...

> which goes to the phone, not the computer you're actually using.

It's sent to the phone *ONE TIME*. A couple of seconds. The horrors. (To
use your exact words.)

> whether a site requires a code each time or once for some period of 
> time has nothing to do with sms versus totp.

*YOU* brought up the CONVENIENCE angle.

> if it doesn't require a code each time, then you're vulnerable
> should the computer be lost or stolen, or someone has access and is
> snooping around.

Nope. Sensitive apps still require a user name and password, even on a
certified browser. (Unless you allow the browser to save the password,
which I don't.)

> one site i use offers an option to not ask for another totp code for
>  30 days. another is 2 weeks. some sites require a code every time
> and offer no choice. none are sms.

Fortunately all my sites allow 2FA SMS with an unlimited time limit.

> it's certainly possible for a site to authenticate for years, but 
> that would be a risk for both parties.

Don't see why. My phone's bank app was certified over 2 years ago and
counting. Someone obtaining illegal possession of my phone still needs
to know 2 separate passwords (phone and bank app) to access the account.
Seems like adequate security to me.

[toc] | [prev] | [next] | [standalone]


#57560

Fromnospam <nospam@nospam.invalid>
Date2018-11-15 17:10 -0500
Message-ID<151120181710554888%nospam@nospam.invalid>
In reply to#57558
In article <pskqfs$44c$1@dont-email.me>, 123456789 <12345@12345.com>
wrote:

> > it's certainly possible for a site to authenticate for years, but 
> > that would be a risk for both parties.
> 
> Don't see why. My phone's bank app was certified over 2 years ago and
> counting. Someone obtaining illegal possession of my phone still needs
> to know 2 separate passwords (phone and bank app) to access the account.

the bank app is the only one that matters, which could be reset via a
vish.

> Seems like adequate security to me.

but not to others.

[toc] | [prev] | [next] | [standalone]


#57564

From123456789 <12345@12345.com>
Date2018-11-15 15:40 -0700
Message-ID<pskskv$1fro$1@gioia.aioe.org>
In reply to#57560
On 11/15/2018 3:10 PM, nospam wrote:
> 123456789 <12345@12345.com> wrote:

>> My phone's bank app was certified over 2 years ago and counting.
>> Someone obtaining illegal possession of my phone still needs to
>> know 2 separate passwords (phone and bank app) to access the
>> account.

> the bank app is the only one that matters, which could be reset via
> a vish.

Nope. The perp won't know WHICH BANK to call until he gets past my
phone's password. 10 false tries erases stuff. But if he did 
miraculously guess my phone's password then he'd still need to know my 
prearranged bank contact code before anyone at the bank would talk to 
him. Still seems like adequate security to me...

[toc] | [prev] | [next] | [standalone]


#57543

FromFrank Slootweg <this@ddress.is.invalid>
Date2018-11-15 16:27 +0000
Message-ID<pskaa2.558.1@ID-201911.user.individual.net>
In reply to#57528
123456789 <12345@12345.com> wrote:
> On 11/14/2018 12:33 PM, nospam wrote:
> > Frank Slootweg <this@ddress.is.invalid> wrote:
> 
> >> "As of 2018, SMS is the most broadly-adopted multi-factor 
> >> authentication method for consumer-facing accounts."
> 
> > you're confusing popularity with security.
> 
> Perhaps not. 2FA by SMS is likely popular because it is EASILY used by
> the general population. Many customers would balk at a more complicated
> non-universal system. And it is considerably more secure than the
> insecurity questions we've been discussing.
> 
> > it is *not* secure. it's security theater.
> 
> Its security is apparently adequate, otherwise those in the know
> (banks, credit card companies, Amazon, Google, etc.) wouldn't be asking 
> people to use it.

  Exactly! *If* it was *not* adequate and there *was* a [Me:]
"practical general alternative", I'm sure that these institutions would
switch. The *fact* that they don't, proves that they consider it
adequate without a "practical general alternative".

  Some food for thought on the TOTP paper tiger(s):

- If TOTP is all that red hot, then why is the list of 'Server
  implementations' - read: service providers which use TOTP - so
  pathetically short, not even 30 providers/companies?
  And - as you say - not a financial institution in sight.

  <https://en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm#Server_implementations>

- Funny that you mentioned Google. Google (Google Account) indeed only
  offers 2FA on Android (and iOS) or via ... <drumroll> ... SMS!

  If TOTP, i.e. including Google Authenticator, is all that red hot,
  then why doesn't *Google* offer it on non-Android/non-iOS, while there
  *are* many (non-Google!) clients for non-Android/non-iOS devices?

  <https://en.wikipedia.org/wiki/Google_Authenticator>

  Google doesn't even offer TOTP (or other 2FA) on Chrome/Chrome OS!
  How silly can you get!?

  And on Windows? Again nothing. Have to use SMS.

  So apparently Google doesn't really believe in TOTP!

  N.B. I concentrated on Google/Android/Chrome/Windows, because I can
  oversee/verify what is (not) possible for those.

- TOTP RFC 6238 is of May 2011.

  "In 2016 and 2017 respectively, both Google and Apple started offering
   user two-step authentication with push notification as an alternative
   method."
  <https://en.wikipedia.org/wiki/Multi-factor_authentication>

  So for this red hot 'solution', hardly anybody could be bothered to
  implement it in *seven* years time!?

[toc] | [prev] | [next] | [standalone]


#57545

Fromnospam <nospam@nospam.invalid>
Date2018-11-15 12:09 -0500
Message-ID<151120181209098431%nospam@nospam.invalid>
In reply to#57543
In article <pskaa2.558.1@ID-201911.user.individual.net>, Frank Slootweg
<this@ddress.is.invalid> wrote:

>   Some food for thought on the TOTP paper tiger(s):
> 
> - If TOTP is all that red hot, then why is the list of 'Server
>   implementations' - read: service providers which use TOTP - so
>   pathetically short, not even 30 providers/companies?
>   And - as you say - not a financial institution in sight.

nonsense. far more than 30 companies use totp, including many banks.

unfortunately, a lot of banks consider any 2fa to be an inconvenience
and don't offer it at all. 

> <https://en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm#Server_i
> mplementations>

an incomplete list, which they readily admit.

> - Funny that you mentioned Google. Google (Google Account) indeed only
>   offers 2FA on Android (and iOS) or via ... <drumroll> ... SMS!

false. 

google offers several options, including sms, totp and a physical
hardware token for those who want maximum security:
<https://store.google.com/product/titan_security_key_kit>

in fact, google now requires a hardware token for their employees,
something which has eliminated phishing/smishing attacks:
<https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-em
ployee-phishing/>
  Google has not had any of its 85,000+ employees successfully 
  phished on their work-related accounts since early 2017, when it
  began requiring all employees to use physical Security Keys in place
  of passwords and one-time codes, the company told KrebsOnSecurity.

now ask yourself why google internally *doesn't* use sms. 

>   If TOTP, i.e. including Google Authenticator, is all that red hot,
>   then why doesn't *Google* offer it on non-Android/non-iOS, while there
>   *are* many (non-Google!) clients for non-Android/non-iOS devices?

because numerous other solutions exist, all of which produce the same
code (given the same seed), so it doesn't matter which app someone
uses.

[toc] | [prev] | [next] | [standalone]


#57549

FromFrank Slootweg <this@ddress.is.invalid>
Date2018-11-15 19:01 +0000
Message-ID<pskj9e.3n8.1@ID-201911.user.individual.net>
In reply to#57545
nospam <nospam@nospam.invalid> wrote:
> In article <pskaa2.558.1@ID-201911.user.individual.net>, Frank Slootweg
> <this@ddress.is.invalid> wrote:
> 
> >   Some food for thought on the TOTP paper tiger(s):
> > 
> > - If TOTP is all that red hot, then why is the list of 'Server
> >   implementations' - read: service providers which use TOTP - so
> >   pathetically short, not even 30 providers/companies?
> >   And - as you say - not a financial institution in sight.
> 
> nonsense. far more than 30 companies use totp, including many banks.

  Which you can't bother to mention. Why is that?

  123456789 is dying to switch to such a bank, so why not help him out!

> unfortunately, a lot of banks consider any 2fa to be an inconvenience
> and don't offer it at all.

  No such banks here.

> > <https://en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm#Server_i
> > mplementations>
> 
> an incomplete list, which they readily admit.

  So come up with a better one.

> > - Funny that you mentioned Google. Google (Google Account) indeed only
> >   offers 2FA on Android (and iOS) or via ... <drumroll> ... SMS!
> 
> false.

  Nope, true. Read on.

> google offers several options, including sms, totp and a physical
> hardware token for those who want maximum security:
> <https://store.google.com/product/titan_security_key_kit>

  Nope, they don't. Read on.

<unsnip>

> > N.B. I concentrated on Google/Android/Chrome/Windows, because I can
> > oversee/verify what is (not) possible for those.

</unsnip>

  See the "verify" bit!? Contrary to you, I don't do paper tigers, so I
*tested* this: Google Account does *only* offer SMS when setting 2-Step
Verification to On, in a *Chrome* browser on a Windows system. Them's
the *facts*.

[FYI, not that it matters, but the Titan Security Kit is not offered in
our country. Perhaps US only?
For me, your URL gives the Dutch store, which shows several products,
but not the Titan Security Kit.
If I switch to the US store and search on 'titan', I do find it (note
'?hl=en-US' part):
<https://store.google.com/us/product/titan_security_key_kit?hl=en-US>.
If I search on 'titan' in the Dutch store, it doesn't find anything.]

[Repeated irrelevancy deleted.]

> >   If TOTP, i.e. including Google Authenticator, is all that red hot,
> >   then why doesn't *Google* offer it on non-Android/non-iOS, while there
> >   *are* many (non-Google!) clients for non-Android/non-iOS devices?
> 
> because numerous other solutions exist, all of which produce the same
> code (given the same seed), so it doesn't matter which app someone
> uses.

  With the minor problem that Google does not offer the opportunity to
actually *use* these "numerous other solutions"! See above.

  "Here are a bunch of great tools! You can't *use* them (with Google),
but they all produce the same code (given the same seed)! Ain't that
great, a bunch of worthless apps, all doing the exact same useless
thing!?"

N.B. Apparently the other points you also silently snipped were even more
painful/embarassing.

[toc] | [prev] | [next] | [standalone]


#57551

Fromnospam <nospam@nospam.invalid>
Date2018-11-15 14:51 -0500
Message-ID<151120181451363321%nospam@nospam.invalid>
In reply to#57549
In article <pskj9e.3n8.1@ID-201911.user.individual.net>, Frank Slootweg
<this@ddress.is.invalid> wrote:

> > >   Some food for thought on the TOTP paper tiger(s):
> > > 
> > > - If TOTP is all that red hot, then why is the list of 'Server
> > >   implementations' - read: service providers which use TOTP - so
> > >   pathetically short, not even 30 providers/companies?
> > >   And - as you say - not a financial institution in sight.
> > 
> > nonsense. far more than 30 companies use totp, including many banks.
> 
>   Which you can't bother to mention. Why is that?

no need for a list. your claim is wrong.

but if you insist, look at the software token column:
<https://twofactorauth.org/#banking>
<https://twofactorauth.org/#finance>
<https://twofactorauth.org/#investing>

there are a *lot* of banks and many other companies offering totp.

>   123456789 is dying to switch to such a bank, so why not help him out!

he isn't 'dying to switch' to anything.

> > unfortunately, a lot of banks consider any 2fa to be an inconvenience
> > and don't offer it at all.
> 
>   No such banks here.

such banks elsewhere. see above list.

> > > <https://en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm#Serv
> > > er_implementations>
> > 
> > an incomplete list, which they readily admit.
> 
>   So come up with a better one.

see above.

> > > - Funny that you mentioned Google. Google (Google Account) indeed only
> > >   offers 2FA on Android (and iOS) or via ... <drumroll> ... SMS!
> > 
> > false.
> 
>   Nope, true. Read on.

not true.

> > google offers several options, including sms, totp and a physical
> > hardware token for those who want maximum security:
> > <https://store.google.com/product/titan_security_key_kit>
> 
>   Nope, they don't. Read on.

they do.

> <unsnip>
> 
> > > N.B. I concentrated on Google/Android/Chrome/Windows, because I can
> > > oversee/verify what is (not) possible for those.
> 
> </unsnip>
> 
>   See the "verify" bit!? Contrary to you, I don't do paper tigers, so I
> *tested* this: Google Account does *only* offer SMS when setting 2-Step
> Verification to On, in a *Chrome* browser on a Windows system. Them's
> the *facts*.

nope. them's *not* the facts.

google supports sms, phone call, hardware and *software* *token* (aka
totp), and is listed in several categories:
<https://twofactorauth.org/#cloud>
<https://twofactorauth.org/#domains>
<https://twofactorauth.org/#email>
<https://twofactorauth.org/#payments>
<https://twofactorauth.org/#social>

i've been using totp with google and many other services for several
years without issue.

i don't use chrome, but i do use vivaldi which is based on chrome, and
can easily log into google with totp, as i can with any other browser.

> [FYI, not that it matters, but the Titan Security Kit is not offered in
> our country. Perhaps US only?

that appears to be the case:
<https://www.engadget.com/2018/08/30/google-50-titan-security-keys-avail
able-us/>
  Titan Security Keys are available to US customers now through the
  Google Store. The company says they'll be available in additional
  regions soon.

> For me, your URL gives the Dutch store, which shows several products,
> but not the Titan Security Kit.
> If I switch to the US store and search on 'titan', I do find it (note
> '?hl=en-US' part):
> <https://store.google.com/us/product/titan_security_key_kit?hl=en-US>.
> If I search on 'titan' in the Dutch store, it doesn't find anything.]

that just means you can't get one yet, not that it doesn't exist.

meanwhile, you can get a yubikey instead:
<https://www.yubico.com>

there are other options, such as this:
<https://onlykey.io>

> [Repeated irrelevancy deleted.]
> 
> > >   If TOTP, i.e. including Google Authenticator, is all that red hot,
> > >   then why doesn't *Google* offer it on non-Android/non-iOS, while there
> > >   *are* many (non-Google!) clients for non-Android/non-iOS devices?
> > 
> > because numerous other solutions exist, all of which produce the same
> > code (given the same seed), so it doesn't matter which app someone
> > uses.
> 
>   With the minor problem that Google does not offer the opportunity to
> actually *use* these "numerous other solutions"! See above.

yes they do.

>   "Here are a bunch of great tools! You can't *use* them (with Google),
> but they all produce the same code (given the same seed)! Ain't that
> great, a bunch of worthless apps, all doing the exact same useless
> thing!?"

it's not useless and it works quite well with google as well as many
other companies.

> N.B. Apparently the other points you also silently snipped were even more
> painful/embarassing.

for you, yes.

[toc] | [prev] | [next] | [standalone]


#57554

FromFrank Slootweg <this@ddress.is.invalid>
Date2018-11-15 21:11 +0000
Message-ID<pskqt2.54c.1@ID-201911.user.individual.net>
In reply to#57551
nospam <nospam@nospam.invalid> wrote:
> In article <pskj9e.3n8.1@ID-201911.user.individual.net>, Frank Slootweg
> <this@ddress.is.invalid> wrote:
> 
> > > >   Some food for thought on the TOTP paper tiger(s):
> > > > 
> > > > - If TOTP is all that red hot, then why is the list of 'Server
> > > >   implementations' - read: service providers which use TOTP - so
> > > >   pathetically short, not even 30 providers/companies?
> > > >   And - as you say - not a financial institution in sight.
> > > 
> > > nonsense. far more than 30 companies use totp, including many banks.
> > 
> >   Which you can't bother to mention. Why is that?
> 
> no need for a list. your claim is wrong.

  Earth to nospam: I didn't 'claim' anything. I just pointed to a list
and said what it does (not) say.

> but if you insist, look at the software token column:

  You mean where it says "[f] Tell them to support 2FA on Facebook"!?

> <https://twofactorauth.org/#banking>

  <barf!> Thanks for proving my and 123456789 points!

> <https://twofactorauth.org/#finance>
> <https://twofactorauth.org/#investing>
> 
> there are a *lot* of banks and many other companies offering totp.
> 
> >   123456789 is dying to switch to such a bank, so why not help him out!
> 
> he isn't 'dying to switch' to anything.

  Sarchasm.

[...]

> > > > - Funny that you mentioned Google. Google (Google Account) indeed only
> > > >   offers 2FA on Android (and iOS) or via ... <drumroll> ... SMS!
> > > 
> > > false.
> > 
> >   Nope, true. Read on.
> 
> not true.

  Might be US-only. Read on.

> > > google offers several options, including sms, totp and a physical
> > > hardware token for those who want maximum security:
> > > <https://store.google.com/product/titan_security_key_kit>
> > 
> >   Nope, they don't. Read on.
> 
> they do.

  Might be US-only. Read on.

> > <unsnip>
> > 
> > > > N.B. I concentrated on Google/Android/Chrome/Windows, because I can
> > > > oversee/verify what is (not) possible for those.
> > 
> > </unsnip>
> > 
> >   See the "verify" bit!? Contrary to you, I don't do paper tigers, so I
> > *tested* this: Google Account does *only* offer SMS when setting 2-Step
> > Verification to On, in a *Chrome* browser on a Windows system. Them's
> > the *facts*.
> 
> nope. them's *not* the facts.
> 
> google supports sms, phone call, hardware and *software* *token* (aka
> totp), and is listed in several categories:
> <https://twofactorauth.org/#cloud>
> <https://twofactorauth.org/#domains>
> <https://twofactorauth.org/#email>
> <https://twofactorauth.org/#payments>
> <https://twofactorauth.org/#social>
> 
> i've been using totp with google and many other services for several
> years without issue.

  Another US-only thing again?

  As I said, here (The Netherlands), it does *not* work, because you can
*not* set it in Google Account.

  So we've your story versus my test.

  Perhaps you could persuade some non-US (and preferably non-CA) posters
to test what '2-Step Verification' options *they* can and can not set in
Google Account. Good luck with that.

  Of course US-posters are welcome to confirm/deny your US-findings.

  To reproduce:

<https://myaccount.google.com> -> Sign-in & security -> Signing in to
Google -> Password & sign-in method -> 2-Step Verification (was Off) ->
'Protect your account with 2-Step Verification ...' -> GET STARTED ->
<enter your password> (:-)) -> Next ->

"Use your phone as your second sign-in step

 Google will send a secure notification to your phone as your second
 factor during 2-Step Verification.

 Get Google prompts on these devices now
 All devices signed into your Google Account will get prompts. You can
 control which phones get prompts in your 2-Step Verification settings.

 [My Android phone]

 [My Android tablet]"

  It does *not* list my Windows computer on which I'm logged in in
Google Account.

  Further it says:

"Don't want to use Google prompt?

 Choose another option"

  Of course I *do* want to use Google prompt, but I *cannot* use it on
this device (Windows computer), so I click 'Choose another option'.

  By golley! That *does* offer "Security Key A small physical device
used for signing in", but that's not what I/we want, because this
discussion is about *software* ('apps') (TOTP) alternatives to SMS.

  The only other option is ... drum roll ...:

"Text message or voice call
 Get codes by text message or phone call"

  QED.

  So now the ball is in your court to try persuade others to test how
things are in their non-US(/non-CA) country.

[Other points which are - at least for the moment - irrelevant, deleted.]

[toc] | [prev] | [next] | [standalone]


#57557

Fromnospam <nospam@nospam.invalid>
Date2018-11-15 16:47 -0500
Message-ID<151120181647501762%nospam@nospam.invalid>
In reply to#57554
In article <pskqt2.54c.1@ID-201911.user.individual.net>, Frank Slootweg
<this@ddress.is.invalid> wrote:

> > but if you insist, look at the software token column:
> <https://twofactorauth.org/#banking>

>   You mean where it says "[f] Tell them to support 2FA on Facebook"!?

not all say that. 

many have checkmarks for sms, phone, hardware and/or software token,
often more than one.




> <https://myaccount.google.com> -> Sign-in & security -> Signing in to
> Google -> Password & sign-in method -> 2-Step Verification (was Off) ->
> 'Protect your account with 2-Step Verification ...' -> GET STARTED ->
> <enter your password> (:-)) -> Next ->
> 
> "Use your phone as your second sign-in step
> 
>  Google will send a secure notification to your phone as your second
>  factor during 2-Step Verification.

yep, and once it verifies your phone number, you can then enable totp,
optionally disabling sms entirely. it's very easy.

next time, try actually using it before assuming it doesn't work as
described.


<https://support.google.com/accounts/answer/1066447?hl=en&ref_topic=2954
345>
  If you set up 2-Step Verification, you can use the Google
  Authenticator app to receive codes even if you don¹t have 
  an Internet connection or mobile service.
...
  3. Under "Signing in to Google," tap 2-Step Verification. You might
    need to sign in.
  4. Under "Set up alternative second step," find "Authenticator app"
    and tap Set up.
  5. Follow the steps on the screen.
  6. To verify it's working, get a code from your Authenticator app.
    Enter it in your settings.


relevant photos:
<https://authy.com/wp-content/uploads/ss11.png>
<https://authy.com/wp-content/uploads/Gmail-add-ss1.png>
<https://authy.com/wp-content/uploads/Gmail-add-ss2.png>
<https://authy.com/wp-content/uploads/Gmail-add-ss5.png>
<https://authy.com/wp-content/uploads/Gmail-add-ss4.png>

full instructions for authy, one of several totp apps:
<https://authy.com/guides/gmail/>

[toc] | [prev] | [next] | [standalone]


#57577

FromFrank Slootweg <this@ddress.is.invalid>
Date2018-11-16 14:43 +0000
Message-ID<psmmd5.8oc.1@ID-201911.user.individual.net>
In reply to#57557
nospam <nospam@nospam.invalid> wrote:
> In article <pskqt2.54c.1@ID-201911.user.individual.net>, Frank Slootweg
> <this@ddress.is.invalid> wrote:
> 
> > > but if you insist, look at the software token column:
> > <https://twofactorauth.org/#banking>
> 
> >   You mean where it says "[f] Tell them to support 2FA on Facebook"!?
> 
> not all say that. 

  But many (most?) *do* say that, which invalidates your claim that TOTP
is widely used.

> many have checkmarks for sms, phone, hardware and/or software token,
> often more than one.
> 
> 
> 
> 
> > <https://myaccount.google.com> -> Sign-in & security -> Signing in to
> > Google -> Password & sign-in method -> 2-Step Verification (was Off) ->
> > 'Protect your account with 2-Step Verification ...' -> GET STARTED ->
> > <enter your password> (:-)) -> Next ->
> > 
> > "Use your phone as your second sign-in step
> > 
> >  Google will send a secure notification to your phone as your second
> >  factor during 2-Step Verification.
> 
> yep, and once it verifies your phone number, you can then enable totp,
> optionally disabling sms entirely. it's very easy.
> 
> next time, try actually using it before assuming it doesn't work as
> described.

  Sigh! I *did* "actually use it", *said* ("To reproduce:") so and
provided (copy-and-paste) dialogs of my test.

  So Mr. PKB-to-the-max, next time, *read* and try to understand what I
actually wrote/posted, including the (copy-and-paste) dialogs I quoted.

> <https://support.google.com/accounts/answer/1066447?hl=en&ref_topic=2954
> 345>

  Are you for real!? That is for the *Android/iOS* app. That is *not*
under dispute. What *is* under dispute is (Google Account offering *use*
of TOTP on) *non*-Android/*non*-iOS platforms, specifically on Windows.

  As I explaned and quoted dialogs for, (here (NL)) on Windows, Google
Account 2-Step Verification does offer:

- 'Google prompt' on Android/iOS phone. NOT under dispute.

- 'Authenticator app' on Android/iOS phone. NOT under dispute.

  [Copy-and-paste of dialog:]

  "Get codes from the Authenticator app

   Instead of waiting for text messages, get verification codes for
   free from the Authenticator app. It works even if your phone is
   offline.

   What kind of phone do you have?

   O Android

   O iPhone

    					CANCEL NEXT"

  See!? *Only* 'Android' and 'iPhone', *no* other platform(s)!

- 'Security Key', i.e. hardware. NOT applicable, because we're only
  discussing *software* solutions, not hardware ones.

- 'Voice or text message'. I.e. the ONLY possibility offered on a
  non-Android/non-iOS device.

  So Google Account does NOT offer any kind of 'Authenticator app' on a
non-Android/ non-iOS device, i.e. Windows in this case.

  QED.

  And just to try to prevent yet another round of your dodge-and-divert
tricks:

  My point is NOT that you can't use TOTP with Google services on a
non-Android/non-iOS device. My point is that *Google* - specifically
Google Account - does not offer *anything* (configuration, instructions,
downloads, etc.) to make that possible. Which is why I said: "So
apparently Google doesn't really believe in TOTP!".

<full quote>

- Funny that you mentioned Google. Google (Google Account) indeed only
  offers 2FA on Android (and iOS) or via ... <drumroll> ... SMS!

  If TOTP, i.e. including Google Authenticator, is all that red hot,
  then why doesn't *Google* offer it on non-Android/non-iOS, while there
  *are* many (non-Google!) clients for non-Android/non-iOS devices?

  <https://en.wikipedia.org/wiki/Google_Authenticator>

  Google doesn't even offer TOTP (or other 2FA) on Chrome/Chrome OS!
  How silly can you get!?

  And on Windows? Again nothing. Have to use SMS.

  So apparently Google doesn't really believe in TOTP!

  N.B. I concentrated on Google/Android/Chrome/Windows, because I can
  oversee/verify what is (not) possible for those.

</full quote>

  Bottom line: I'm done with you. Until others - who show that *they*
*can* read/ comprehend what is written/quoted - prove me wrong, it's

  EOD.

[toc] | [prev] | [next] | [standalone]


#57580

Fromnospam <nospam@nospam.invalid>
Date2018-11-16 13:11 -0500
Message-ID<161120181311412266%nospam@nospam.invalid>
In reply to#57577
In article <psmmd5.8oc.1@ID-201911.user.individual.net>, Frank Slootweg
<this@ddress.is.invalid> wrote:

> > > > but if you insist, look at the software token column:
> > > <https://twofactorauth.org/#banking>
> > 
> > >   You mean where it says "[f] Tell them to support 2FA on Facebook"!?
> > 
> > not all say that. 
> 
>   But many (most?) *do* say that, which invalidates your claim that TOTP
> is widely used.

nope. it does not invalidate it.

more than 10 million downloads for google authenticator, and that's
just for one totp app among many:
<https://play.google.com/store/apps/details?id=com.google.android.apps.a
uthenticator2>

and then there's this:
<https://techcrunch.com/2018/11/15/millions-sms-text-messages-leaked-two-
factor-codes/>
  A security lapse has exposed a massive database containing tens of
  millions of text messages, including password reset links, two-factor
  codes, shipping notifications and more.
...
  The exposure to personal information and phone numbers
  notwithstanding, the ability to access two-factor codes in
  near-real-time could have put countless number of accounts at risk of
  hijack. In some cases, websites will only require a phone number to
  reset an account. With access to the text message through the exposed
  database, hijacking an account could take seconds.
...
  Many companies, including Facebook, Twitter and Instagram, have
  rolled out app-based two-factor authentication to thwart SMS-based
  verification, which has long been seen as vulnerable to interception.



> > <https://support.google.com/accounts/answer/1066447?hl=en&ref_topic=2954
> > 345>
> 
>   Are you for real!? That is for the *Android/iOS* app. That is *not*
> under dispute. What *is* under dispute is (Google Account offering *use*
> of TOTP on) *non*-Android/*non*-iOS platforms, specifically on Windows.

it works just fine on windows as well as other non-mobile platforms.

here's one option (which should auto-detect your current platform,
click for the others):
<https://1password.com/downloads/>



>   "Get codes from the Authenticator app
> 
>    Instead of waiting for text messages, get verification codes for
>    free from the Authenticator app. It works even if your phone is
>    offline.
> 
>    What kind of phone do you have?
> 
>    O Android
> 
>    O iPhone
> 
>                    CANCEL NEXT"
> 
>   See!? *Only* 'Android' and 'iPhone', *no* other platform(s)!

that's because phones have cameras and can easily scan a qr code.

desktops and laptops require an app that can detect a qr code on the
screen. 

for example:
<https://i.1password.com/media/setup-scan-qr-code.gif>

also, android/ios apps which also have a desktop version (including
1password) can sync across platforms, so the user can still scan with
their phone and then get codes on their desktop/laptop.

tl;dr - it works quite well on other platforms.


>   And just to try to prevent yet another round of your dodge-and-divert
> tricks:

there is no dodging and diverting. you simply do not understand how it
works and have made numerous incorrect assumptions...

>   My point is NOT that you can't use TOTP with Google services on a
> non-Android/non-iOS device. My point is that *Google* - specifically
> Google Account - does not offer *anything* (configuration, instructions,
> downloads, etc.) to make that possible. Which is why I said: "So
> apparently Google doesn't really believe in TOTP!".

...such as that one.

google absolutely believes in totp or they wouldn't have released their
own totp app. the majority of people will use a phone for the codes and
scanning with a phone is very easy, so that's what they targeted.

other developers provide additional options, including downloads,
instructions, etc. for their own apps. it's not google's responsibility
to support all third party options.

[toc] | [prev] | [next] | [standalone]


#57592

From"Carlos E.R." <robin_listas@es.invalid>
Date2018-11-17 01:10 +0100
Message-ID<5s24cf-p0b.ln1@Telcontar.valinor>
In reply to#57551
On 15/11/2018 20.51, nospam wrote:
> In article <pskj9e.3n8.1@ID-201911.user.individual.net>, Frank Slootweg
> <this@ddress.is.invalid> wrote:


>>   See the "verify" bit!? Contrary to you, I don't do paper tigers, so I
>> *tested* this: Google Account does *only* offer SMS when setting 2-Step
>> Verification to On, in a *Chrome* browser on a Windows system. Them's
>> the *facts*.
> 
> nope. them's *not* the facts.
> 
> google supports sms, phone call, hardware and *software* *token* (aka
> totp), and is listed in several categories:
> <https://twofactorauth.org/#cloud>
> <https://twofactorauth.org/#domains>
> <https://twofactorauth.org/#email>
> <https://twofactorauth.org/#payments>
> <https://twofactorauth.org/#social>

None of the four banks I use or have used is even listed.

-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#57594

Fromnospam <nospam@nospam.invalid>
Date2018-11-16 20:10 -0500
Message-ID<161120182010078667%nospam@nospam.invalid>
In reply to#57592
In article <5s24cf-p0b.ln1@Telcontar.valinor>, Carlos E.R.
<robin_listas@es.invalid> wrote:

> None of the four banks I use or have used is even listed.

the list doesn't include every bank or other provider that exists.

find out what your banks support, then email the site and have them
update their list.

[toc] | [prev] | [next] | [standalone]


#57605

From"Carlos E.R." <robin_listas@es.invalid>
Date2018-11-17 11:24 +0100
Message-ID<tr65cf-i69.ln1@Telcontar.valinor>
In reply to#57594
On 17/11/2018 02.10, nospam wrote:
> In article <5s24cf-p0b.ln1@Telcontar.valinor>, Carlos E.R.
> <robin_listas@es.invalid> wrote:
> 
>> None of the four banks I use or have used is even listed.
> 
> the list doesn't include every bank or other provider that exists.
> 
> find out what your banks support, then email the site and have them
> update their list.
> 

SMS.

-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#57546

From123456789 <12345@12345.com>
Date2018-11-15 10:32 -0700
Message-ID<pskaja$sbr$1@dont-email.me>
In reply to#57543
On 11/15/2018 9:27 AM, Frank Slootweg wrote:

> - Funny that you [123456789] mentioned Google. Google (Google 
> Account) indeed only offers 2FA on Android (and iOS) or via ... 
> <drumroll> ... SMS!

When I signed up for what Google called 2FA some time back there were 2
SMS choices: Send a ONE-TIME SMS code to certify the device OR send and
require an SMS code at EVERY LOG IN.

The 2nd option might be more secure but IMO the hassle just wasn't
worth it.

In the lets make things easier for the customer department, one of my
phone's banking apps allows a 4 digit pin. After logging in with your
user name/password, and being verified by SMS 2FA, it gives you the
option of making and using only a 4 digit pin thereafter. I find it very
handy. But if the rest of my apps ever offered it I could see a problem.
While I can remember my 12 character password formula I would have
difficulty remembering a different 4 digit pin for each app. I
know...I'd just use the same pin for all... ;)

[toc] | [prev] | [next] | [standalone]


#57575

From"Carlos E.R." <robin_listas@es.invalid>
Date2018-11-16 14:48 +0100
Message-ID<2fu2cf-kgd.ln1@Telcontar.valinor>
In reply to#57524
On 14/11/2018 20.00, Frank Slootweg wrote:
> "J. P. Gilliver (John)" <G6JPG-255@255soft.uk> wrote:
>> In message <141120180915032258%nospam@nospam.invalid>, nospam 
>> <nospam@nospam.invalid> writes:
>>> In article <g524r0F19jqU1@mid.individual.net>, Carlos E. R.
>>> <robin_listas@es.invalid> wrote:
>>>
>>>>> requiring the same number is bullshit and he knows it.
>>>>
>>>> I absolutely require keeping the same number and you know it is an
>>>> important requirement.
>>
>> (Fleet vehicle painting for example. May not be relevant for Carlos.)
>>>
>>> maybe for you, but not for others, and in your case, there are a few
>>> options available.
>>
>> Such as?
>>>
>>> the point is that voip service is available *anywhere* there is
>>> internet access, including where you are.
>>
>> OK, Carlos was _perhaps_ remiss in not mentioning in the first place 
>> that number retention was important to him. 

Oh, because I thought that wanting to keep the same number is obvious.
It is the number one reason people don't change phone provider fast
here. It is so important that the law obligates phone companies to
support porting!

If you ask me why /I/ do not want to change numbers, well, all my
relations⁽¹⁾ or my parents relations have that number in their phone
books for several decades. I would have to call people I do not remember
about to tell them my new number.

(1) Relations: family, relatives, friends, acquaintances, business
contacts, employers, co-workers... whoever.

>> But can we let that drop 
>> now, and only discuss the "options available" that _do_ let him keep his 
>> number _and_ provide VoIP? Yes, I think _most_ of us do know that if you 
>> _aren't_ wanting to keep your number, VoIP is widely available.
> 
>   John, you might as well stop beating, because the horse is well and
> truly dead!
> 
>   Carlos never wanted VoIP in the first place!

Absolutely correct!


>   It was our resident Mr, Dodge-and-divert, who suggested 123456789 that
> for appointment reminders from his doctor, they should call his landline
> instead of sending an SMS, because - according to nospam - SMS is
> easily hacked and unreliable.
> 
>   VoIP was never relevant, it was just that 123456789's landline
> *happens* to be VoIP.
> 
>   But nospam is a 'master' in taking an irrelevant point and then making
> the whole discussion about that irrelevant point, often implying/saying
> that *others* brought the point up.

Yep.

> 
>   Meanwhile back in the real world:
> 
> "As of 2018, SMS is the most broadly-adopted multi-factor
> authentication method for consumer-facing accounts."
> <https://en.wikipedia.org/wiki/Multi-factor_authentication>

Indeed.

-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#57512

From"Carlos E. R." <robin_listas@es.invalid>
Date2018-11-14 09:34 +0100
Message-ID<g52516F19jqU3@mid.individual.net>
In reply to#57491
On 13/11/2018 19.22, nospam wrote:
> In article <g50i81Flbq9U1@mid.individual.net>, Carlos E. R.
> <robin_listas@es.invalid> wrote:
> 
>>>>>> No VoIP providers here.
>>>>>
>>>>> if you have internet access, which you obviously do, you have voip
>>>>> providers.
>>>>
>>>> Nope. Not locally, that is, with local phone numbers.
>>>
>>> yes with local numbers.
>>
>> Ah, yes? Please give me the link for such a service in Spain.
> 
> many voip providers offer numbers in spain, including voip.ms,
> callcentric and others and one need not actually live there to obtain
> such a number.

If they are to port numbers in Spain, they must be registered here.
And I absolutely require porting.

> 
>> They must grant me the same phone number I have now, and they must
>> handle the dropping of the phone line with Movistar (ie, land line
>> portability to VoIp), but keep internet.
> 
> that is dependent on porting rules, not voip.

So? I don't care if the rule is in this or that paper.

> 
>>>> The phone companies obviously use VoIP, but they do it in a way that we
>>>> can not access it, and give use the traditional service instead, with
>>>> traditional tarification.
>>>
>>> use an independent voip provider.
>>>
>>> here's a list:
>>> <https://www.voip-catalog.com/voip_countries_spain_1.html>
>>> <http://www.voipproviderslist.com/country/voip-spain/voip-providers-spai
>>> n/>
>>
>> Oh, I tried them time ago. Bankrupt.
> 
> every single one? the second link has 11 *pages* of options.
> 
> and that's not a complete list either.
> 


-- 
Cheers,
       Carlos E.R.

[toc] | [prev] | [next] | [standalone]


#57483

FromJoerg Lorenz <hugybear@gmx.ch>
Date2018-11-13 18:05 +0100
Message-ID<psf08m$h80$1@dont-email.me>
In reply to#57473
Am 13.11.18 um 15:43 schrieb Carlos E. R.:
> On 13/11/2018 15.08, nospam wrote:
>> In article <g4vghqFe0r9U2@mid.individual.net>, Carlos E. R.
>> <robin_listas@es.invalid> wrote:
>>
>>> No VoIP providers here.
>>
>> if you have internet access, which you obviously do, you have voip
>> providers.
>>
> 
> Nope. Not locally, that is, with local phone numbers.
> 
> The phone companies obviously use VoIP, but they do it in a way that we
> can not access it, and give use the traditional service instead, with
> traditional tarification.
> 
SIP?
That was easy.

[toc] | [prev] | [next] | [standalone]


#57490

From"Carlos E. R." <robin_listas@es.invalid>
Date2018-11-13 19:10 +0100
Message-ID<g50icbFlbq9U2@mid.individual.net>
In reply to#57483
On 13/11/2018 18.05, Joerg Lorenz wrote:
> Am 13.11.18 um 15:43 schrieb Carlos E. R.:
>> On 13/11/2018 15.08, nospam wrote:
>>> In article <g4vghqFe0r9U2@mid.individual.net>, Carlos E. R.
>>> <robin_listas@es.invalid> wrote:
>>>
>>>> No VoIP providers here.
>>>
>>> if you have internet access, which you obviously do, you have voip
>>> providers.
>>>
>>
>> Nope. Not locally, that is, with local phone numbers.
>>
>> The phone companies obviously use VoIP, but they do it in a way that we
>> can not access it, and give use the traditional service instead, with
>> traditional tarification.
>>
> SIP?
> That was easy.

Credentials? Gateway?  Official info, please, from Movistar.

Ah, they use a VPN, I believe.

-- 
Cheers,
       Carlos E.R.

[toc] | [prev] | [next] | [standalone]


Page 7 of 9 — ← Prev page 1 2 3 4 5 6 [7] 8 9  Next page →

Back to top | Article view | comp.mobile.android


csiph-web