[180162] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: gmail security is a joke

daemon@ATHENA.MIT.EDU (Valdis.Kletnieks@vt.edu)
Wed May 27 04:17:45 2015

X-Original-To: nanog@nanog.org
To: Anil Kumar <akumar@anilkumar.com>
In-Reply-To: Your message of "Wed, 27 May 2015 09:13:47 +0530."
 <70986901-348F-415A-92B9-40997F4F8E26@anilkumar.com>
From: Valdis.Kletnieks@vt.edu
Date: Wed, 27 May 2015 04:17:34 -0400
Cc: nanog <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org

--==_Exmh_1432714654_27623P
Content-Type: text/plain; charset=us-ascii

On Wed, 27 May 2015 09:13:47 +0530, Anil Kumar said:
> that link, since I have two-step verification set up, I was presented
> with a demand for a number provided by the Google Authenticator
> app on my phone. I provided that number and only then was I allowed
> to reset the password.

And you have to pre-register the phone number.

Sounds about as secure as you're going to get when trying to scale to 10
digits of users....

And as I said earlier - if your threat model involves needing more security
than that, you have bigger problems.. :)

--==_Exmh_1432714654_27623P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: Exmh version 2.5 07/13/2001

iQIVAwUBVWV9ngdmEQWDXROgAQKBoRAAtJ8odq8nH8ido0LTH1qzKgtnFDYIv+ss
6rF4BgJ7mSyj7+RXTHUaBAUUFX2YrxEMyP8pC02ElmzWviY1nxiVcIWSUeu+GHvE
ozvQzlqnz+Ii0zZHkCO2ZVsZNflY+hukMKfnMuQQkiDiQoqCUW5DnafZNHza/h2r
ZKZSbJ+2Knr2SsFgh3kPCJV7+Aac3qjzXFd3i2714i9QASWZKq8+g3eWO7DNHpp+
NHelEPqMPKCbK2aFLMFKKoEy1fEBT/T2DWHFhKOyOJULFZOUGDrjaZ8rHglAImBa
Vm35Oz4WMhQnDT7mWwD7yLGlH1NeXSk1VcuYmSVkE0CRTiOWKTmtklHSbiI/PSlW
5eZ1wMLuHRk2SKLVa+WNHh8aSU/DXVR7XiyDXbL0EjGYW0iHejS6bp2Y397WDv/g
fPqnytox4MGcvkVGVd1ajJRljdZlLHLyWW8izDMSv2S0Q90HPCzPl/s2ob2PMq4g
Px25praYAsymiEqINwQ1Kqb4gzeU9n3iwJXLIp0gcNSEe8BH0g0BtAZEenVRhEer
FrScC0tPFeHbDnC+5KBxWKu03iU4GDarH/fe3gfhNpLowE3LLTvwK7zzyweAkMo3
PnDgj7Do+Gn00rc37AQdzN/5mbpTpappJbrQ74pBgMLmi4sKmU6uJpWXMc+Tfz5+
Y7cQnUOSThs=
=W71D
-----END PGP SIGNATURE-----

--==_Exmh_1432714654_27623P--

home help back first fref pref prev next nref lref last post