News: 1633481665

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google to auto-enroll 150m users, 2m YouTubers with two-factor authentication

(2021/10/06)


Google is going to automatically enroll 150 million users and two million YouTube creators into using two-factor authentication for their accounts by the end of the year, it announced on Tuesday.

Passwords aren’t good enough on their own, Google’s AbdelKarim Mardini, group product manager working on Chrome, and Guemmy Kim, director at the Account Security and Safety team, [1]explained on Tuesday. These passphrases are often simple and can be easily guessed, or stolen and shared.

Two-factor authentication provides an extra layer of security by, say, requiring a one-time code to complete your login – this code could be generated by an app on your phone or emailed to you – or a hardware key you insert into your computer. The idea being that if someone learns of or guesses your password, they also need to get something else off you, like your unlocked phone or hardware key.

[2]

Google calls this [3]two-step verification (2SV) and it involves being sent a code to type in, using a hardware key, or an app on your phone.

[4]

[5]

“2SV is strongest when it combines both "something you know" (like a password) and 'something you have' (like your phone or a security key),” Mardini and Kim said.

“And because we know the best way to keep our users safe is to turn on our security protections by default, we have started to automatically configure our users’ accounts into a more secure state. By the end of 2021, we plan to auto-enroll an additional 150 million Google users in 2SV and require two million YouTube creators to turn it on.”

[6]It's time to delete that hunter2 password from your Microsoft account, says IT giant

[7]Twitter hackers busted 2FA to access accounts and then reset user passwords

[8]Who would cross the Bridge of Death? Answer me these questions three! Oh and you'll need two-factor authentication

[9]Singapore government scraps physical 2FA tokens for government services

Although Google introduced such authentication about a decade ago, people haven’t really been using it. Google software engineer Grzegorz Milka revealed at Usenix's Enigma security conference in 2018 that less than 10 per cent of the web giant's active user accounts were protected by two-factor authentication.

At the time, Milka [10]told The Register the search giant didn’t want to force it upon its users. “The answer is usability,” he said. “It’s about how many people would we drive out if we force them to use additional security.”

[11]

Now Google's being a little more proactive, though it noted not everyone is tech savvy enough to get their heads around 2SV. As such, it is being selective with the accounts it auto-enrolls.

"We also recognize that today’s 2SV options aren’t suitable for everyone," Mardini and Kim said, "so we are working on technologies that provide a convenient, secure authentication experience and reduce the reliance on passwords in the long-term. Right now we are auto-enrolling Google accounts that have the proper backup mechanisms in place to make a seamless transition to 2SV." ®

Get our [12]Tech Resources



[1] https://blog.google/technology/safety-security/making-sign-safer-and-more-convenient/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YV0fkZLfwaBi3zlu4FTAAAAAAAU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.google.com/landing/2step/#tab=how-it-works

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YV0fkZLfwaBi3zlu4FTAAAAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YV0fkZLfwaBi3zlu4FTAAAAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/09/16/microsoft_passwordless/

[7] https://www.theregister.com/2020/07/20/twitter_security_update_hackers_broke_2fa/

[8] https://www.theregister.com/2021/06/25/something_for_the_weekend/

[9] https://www.theregister.com/2020/04/01/singapores_government_scraps_physical_tokens/

[10] https://www.theregister.com/2018/01/17/no_one_uses_two_factor_authentication/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YV0fkZLfwaBi3zlu4FTAAAAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



And because we know the best way ...

gerdesj

The road to Hell is paved with good intentions and Google "engineers" who wouldn't know what Chartered means if it kicked them in the nadgers.

Fuck wits.

Re: And because we know the best way ...

gerdesj

I feel like talking to myself.

When a Civil Engineer fucks up, a bridge collapses or a dam bursts ... err this is starting to look bad.

When a FAART or FFUNGI, FUUNG? whatever, employee fucks up then Facebook vanishes for six hours. Did anyone die as a result? Probably, sadly. I bet that somewhere a doctor or lots use FB to run clinics. Somewhere as a result of the lack of FB, someone may have died. On the other hand someone may have survived being knobbled by a well meaning but deranged doctor who could no longer communicate due to the outage.

So a real Engineer kills people when they screw up and generally ends up having to face up to that. FAANG/FLOOP etc programmers and other staff, when they fuck up, there are less cat memes in the world - that's how they seem to be seen at times of breakage. There are a lot of other businesses that have gone all in on FB and Co. Will they be compensated in some way?

No.

Re: And because we know the best way ...

Gene Cash

The BBC made a big "think of the children"-style deal over WhatsApp being down.

People around the world lost contact with their families on Monday, patients were cut off from doctors, and governments were unable to communicate with citizens when Facebook's social media and messaging tools went down for almost six hours.

Jesus H. Jumping Christ. What a bunch of moaners. FB being down is NOT the end of the world, people.

People need to stop basing their business and essential communication around a resource they DON'T EVEN PAY FOR! If I see a restaurant or other business on Google Maps or whatever, and their website is Facebook... I don't even bother to look further. I know they're too lazy to make decent food.

Google threw a shitfit over people using their well-known nicknames instead of their real names, and started locking people out of their accounts. That's when I bought an email address where I actually pay for the damn thing and I'm the customer, and shifted all my communications to that.

https://www.bbc.com/news/technology-58801814

'something you have'

Anonymous Coward

or don't have. Quite an about-face from being 'safe' to being 'f**ked' on a bad day.

I've accidently left the house without my cellphone once in maybe 2 years, but I regretted it only because of the wonderful pictures I missed taking.

The base for my passwords is 14 characters long, in a European language I don't know, and was a friend's made up nickname for himself. And he's dead now and not talking. If that is insecure - as a practicality - then turn off passwords completely, Google and world.

Re: 'something you have'

ShadowSystems

I made sure my passphrase was as strong as I could make it, mostly by taking it from the Necronomicron & transcribing it into Elder God runes so that anyone reading it ends up summoning Cthulhu. I'm not worried, he just sticks his head out his bedroom door & asks me WTF I want _this_ time. I love having a flatmate! =-D

Doctor Evil

Google has been trying really, really hard for a number of years now to get my mobile number. Always denied. Now they've come up with a novel way to force the issue: 3 options for 2SV, 2 of which involve giving them my number and the 3rd of which is unduly onerous. That'll be it for me; I can browse YouTube anonymously (until they disallow that too) and there are alternative throwaway email and other services out there.

Nothing to do with forcing people to hand over their phone numbers right?

Chet Mannly

It's obviously for security purposes, not so that they can force people that haven't already to hand over their phone numbers as well as all the other data they have on you...

Mandated? No thanks.

Barry Rueger

“The answer is usability,” he said. “It’s about how many people would we drive out if we force them to use additional security.”

I've already started dropping sites that demand too many hoops to jump through. And I honestly suspect that is much more about theater than real security.

I'm a big boy. I can read. I can decide how much, or how little, security is needed on a given site. 99% of the time I'm comfortable with a giant kickass password that should be unguessible.

At least until the site manages to have their user database appear on HaveYouBeenPowned?

Convenient?

Randesigner

"so we are working on technologies that provide a convenient, secure authentication experience"

So, like captcha?

Telephone numbers are not credentials

Anonymous Coward

A telephone number is a mapping in a database accessible to hundreds of thousands of minimum-wage telco tech support and retail employees around the globe, many of whom will happily change that mapping for a few hundred bucks -- and have, in numerous well-publicised incidents. Control of a number provides absolutely zero proof of identity, and was never intended to do so. Hardware keys are in principle a little better but they are invariably riddled with firmware bugs and far too easily lost, and remain a niche product of interest mainly to engineers and security researchers. More fundamentally, passwords align responsibility for account security (by choosing and managing passwords wisely or foolishly) with ownership of the account's data, while typical 2FA mechanisms delegate that responsibility to unaccountable third parties with no incentive to maintain security. Worst of all, the "secondary" authn method is usually allowed to trigger a password reset, making it effectively the sole authn method.

It has become an article of faith that "passwords provide poor security". In one sense that's true: it has been amply proven that many people do not use them effectively, are highly resistant to education, and under those circumstances get very little security from them. In another sense, however, it's false: for account owners who do follow sound password management practices, guessing the password or obtaining it from the account owner -- whether directly or by use of a key logger or similar malware -- become significantly more difficult and costly than other attacks against that account. Since the purpose of any security measure is to render some classes of attacks not worthwhile to or beyond the capabilities of some threat actors, passwords are in fact an effective security measure for those account owners. They may or may not be sufficient, but account owners who know they are high-value targets will almost certainly prefer passwords to the weak "2FA" alternatives that are widely used, which create ready opportunities for cost-effective attacks via third parties unaccountable to the owner. The reason passwords are attacked so frequently is that for attackers looking merely for targets of opportunity, they are the lowest-cost attack vector. Targets of opportunity are almost always of low value, so passwords are actually a reasonably effective mechanism when considered in the context of the assets to be protected and the threat landscape. Assets too valuable to be protected by passwords are likely also too valuable to be protected by a Google account, regardless of the authn methods used to access that account.

There are more secure systems, but all require specialised hardware, software, training, and/or physical security measures to use effectively, and are less convenient. Most members of the general public -- the target market for Google's services -- are not willing to accept a system with those attributes. That's probably rational: again, if you need more security than good passwords can provide, you probably also need more security than you would trust Google to provide. Moreover, it is highly unlikely that the same people who have proven incapable of good password hygiene would prove any more adept at using a more complex security system. Depending upon the choices made by the designers of that system, they will quickly be locked out permanently, stop using the protected system altogether, or bypass the security measures. One can argue that all of these are merely engineering challenges that have yet to be solved, but whether they are unsolved or insoluble makes little difference. Passwords in fact remain the best available solution for this type of service and target market. Account owners must choose their passwords and password management practices in accordance with the value of their assets and anticipated threat model. Taking that choice out of their hands reduces security for high-value targets while focusing protective measures on the lowest-value assets.

You may be gone tomorrow, but that doesn't mean that you weren't here today.