News: 1620348779

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google will make you use two-step verification to login

(2021/05/07)


Google has marked World Password Day by declaring "passwords are the single biggest threat to your online security," and announcing plans to automatically add multi-step authentication to its users' accounts.

A mere eight years after Intel [1]began promoting World Password Day as a way to raise awareness about the importance of strong passwords, Google is ready to wipe them from memory.

At the 2004 RSA Conference, Microsoft co-founder Bill Gates [2]predicted passwords would become less important in the years ahead. The Windows biz has pushed to make that happen by supporting [3]FIDO2 security keys for authentication and switching to token-based authentication to approve git operations [4]on GitHub , among other initiatives. But the password, like email, has so far defied its death watch.

[5]

[6]

[7]

Google's product management director Mark Risher, in [8]a blog post this week, noted that 66 per cent of Americans admit to using the same password across multiple sites, which is an ill-considered security practice. Account databases do get compromised, and any username and password so exposed can be easily fed to a bot that will try the combination out at popular websites, a technique known as credential stuffing.

And let's not forget that in 2017, a Google software engineer said [9]less than 10 per cent of active Google accounts were using two-step authentication.

[10]Crane horror Reg reader uses his severed finger to unlock Samsung Galaxy phone

[11]HashiCorp reveals exposure of private code-signing key after Codecov compromise

[12]Volunteer-run pirate Manga website attacked, loses hashed passwords, has ‘nobody’ to fix the mess

[13]UK's National Cyber Security Centre recommends password generation idea suggested by El Reg commenter

Today, Google has taken its two-step verification program (2SV) up a notch. This process, however, still involves passwords – entering your password is the first step.

It's also the second step, though it's not called a password in this context. Rather, it's a on-off, time-limited authentication code or token sent to the user's mobile device or generated via mobile app software or hardware or via a dedicated security key. It may even be a backup code printed out long ago just in case the second-factor device is unavailable.

In any event, authenticating using something you know and something you fleetingly have is more secure than just relying on " [14]solarwinds123 " or the like.

[15]

So it is that Google plans to make this two-step verification (2SV) ritual obligatory for those who have revealed enough about themselves and their possessions to the Chocolate Factory.

"Soon we’ll start automatically enrolling users in 2SV if their accounts are appropriately configured," explains Risher. "Using their mobile device to sign in gives people a safer and more secure authentication experience than passwords alone."

Nonetheless, Google isn't done with passwords, having built its Password Manager into Chrome, Android, and more recently iOS, and welded the code to its one-click Security Checkup, which alerts users when passwords have been publicly exposed, when they've been reused across multiple sites, and when they're too short or otherwise weak.

[16]

"One day, we hope stolen passwords will be a thing of the past, because passwords will be a thing of the past, but until then Google will continue to keep you and your passwords safe," said Risher.

One day, [17]all your base are belong to us . ®

Get our [18]Tech Resources



[1] https://itpeernetwork.intel.com/password-day/

[2] https://www.theregister.com/2004/02/25/who_needs_passwords/

[3] https://www.theregister.com/2020/02/25/fido2_azure_ad_hybrid/

[4] https://www.theregister.com/2020/12/17/github_bans_passwords/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJS7WdcZD5AgOv2nQCYs7QAAAII&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJS7WdcZD5AgOv2nQCYs7QAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJS7WdcZD5AgOv2nQCYs7QAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://blog.google/technology/safety-security/a-simpler-and-safer-future-without-passwords/

[9] https://www.theregister.com/2018/01/17/no_one_uses_two_factor_authentication/

[10] http://www.theregister.com/2021/05/06/samsung_galaxy/

[11] http://www.theregister.com/2021/04/26/hashicorp_reveals_exposure_of_private/

[12] http://www.theregister.com/2021/04/26/mangadex_data_breach/

[13] http://www.theregister.com/2021/04/09/ncsc_secure_passwords_three_words_advice/

[14] https://www.theregister.com/2020/12/16/solarwinds_github_password/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJS7WdcZD5AgOv2nQCYs7QAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJS7WdcZD5AgOv2nQCYs7QAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://knowyourmeme.com/memes/all-your-base-are-belong-to-us

[18] https://whitepapers.theregister.com/

Blackjack

SMS are even more unsafe that emails so I will resist for as long as I can.

AndrewV

Before they make it mandatory, they need to develop a universally accessible method.

I'm quadriplegic, and use my chin to type.

I can't check a phone.

I can't press a button like the ones on usb security keys.

I could probably hack together a fix, but I'm a coder. Most disabled people aren't, and shouldn't have to be to use online resources.

What about just plain Gmail?

WolfFan

Will that require 2FA as well? I foresee… problems… if so.

Re: What about just plain Gmail?

tfewster

It appears to me that Gmail already uses 2FA - the device you log in from is also a factor*. Because they send me a warning email if I log in from a new phone or computer.

So they could enforce 2FA at the point I log in from a new device. Which would be spectacularly unhelpful if my phone is stolen when I'm away from home as I wouldn't be able to register a replacement.

* Of course, as my username/password will be stored on the device to log in to Gmail automatically, it's only 1 factor in use 99% of the time

Share my phone number?

Anonymous Coward

With Google et al?

I think not.

You've crossed the line

Notas Badoff

How does this work if I go travel to other lands and have to use local sims for internet. What if I have to use a locally acquired mobile? Doesn't that mean I've changed too many things to be recognized?

Are these people real?

G R Goslin

I live in an area, so far ignored by 2g, 3g,4g and 5g, so my chances of a second factor coming to my 'phone anytime soon is a bit remote. I keep all my passwords on the Word (Psion) application on a twenty odd year old Psion netBook, which is almost never connected to the 'net. At the last count, it ran to 28 pages of A4, at four lines to an entry, for the most part. Admittedly, a whole lot of these entries are obsolete, Like the Daily Telegraph online crossword, which I gave up when they started to charge an exorbitant for an account. Everyone and their dog is requiring an acount with password. Very few of them can agree on how the password shall be constructed.Never forget that he simplest way to crack a password, is to crack the owner of the password. Usually with a big stick..A cheap and very low tech solution. I once tried to get an account on a hardware forum, for something I was using. After a couple of hours having passwords rejected. Even hitting keys at random did not generate a viable password, I decided that the manufacturer did not want people on his forum, and gave up.

Zero Factor Authentication

Paul Hovnanian

I don't use Google stuff other than as an Anonymous Coward.

They can't steal my password if I don't have one.

Justice, n.:
A decision in your favor.