Re: Google will no longer send SMSs with six digit codes for verification

Liste des GroupesRevenir à cm android 
Sujet : Re: Google will no longer send SMSs with six digit codes for verification
De : robin_listas (at) *nospam* es.invalid (Carlos E.R.)
Groupes : comp.mobile.android
Date : 03. Mar 2025, 21:28:47
Autres entêtes
Message-ID : <v0gh9lxofo.ln2@Telcontar.valinor>
References : 1 2 3 4 5 6
User-Agent : Mozilla Thunderbird
On 2025-03-03 20:45, VanguardLH wrote:
"Carlos E.R." <robin_listas@es.invalid> wrote:
 
VanguardLH wrote:
>
What was the point of Google (and Microsoft) fucking up OAUTH, a
protocol, to screw into the OAUTH2, a framework, for authenticated
logins?
>
2FA.
 Separate and independent security schemes.  OAUTH2 has the OAUTH2 server
send a token (half the key) to the client that the client stores for
later logins.  The OAUTH2 server keeps the other half.  The user never
has to enter the token, a code string, or scan some QR image.  2FA
interrupts the login making the user wait for the code to then enter
into some prompt.  2FA relies on 2 criteria: what you know, and what you
have.  Alas, many sites fuck up 2FA by never having you enter a
password, but just take your username and then send the 2FA code without
you ever entering the password, so half of the 2FA scheme (what you
know) is missing.
 I'm not part of the kiddie generation that is grafted to their
smartphones.  Also, smartphone penetration is not 100%.  It's 83% in
urban regions, and 65% in rural regions in the USA.  That means there
are folks without a smartphone.  They have no way to get SMS messages.
Lots of folks just have simple landlines.
Irrelevant. It is much higher with gmail users.

Instead of sending via SMS, the QR code could be sent via e-mail.  Geez,
like no one that intercepts your e-mails (which are not encrypted) could
possibly use a QR scanner in a script to login before you do.  Also,
there is no guaranteed delivery to email or SMS.  Ever have a web site
send a 2FA code never to get it, and you had to request another?  Well,
maybe someone intercepted that insecure communication.  A QR code isn't
going to deter a thief any more than a numeric string.
This is speculation of something in the future, but I expect the QR to pop up in the computer where you try to open email.

 
Whether on my Android phone or Windows desktop using OAUTH2 email apps,
or using a web browser with HTTPS, I've never received an SMS text (on
my phone) to complete a login to Gmail.  If they replace SMS texts with
QR codes (delivered how?), well, I wasn't getting SMS texts before, so I
won't be getting QR codes, either.
>
I have.
 On every login, or once in a blue moon?  I can see getting the messages
if you enabled 2FV in your Google account, but I did not.  I recall
faintly getting challenged on a login, and had to give my security
answers to access my account.  I didn't get a 2FA code for that.
Once in a blue moon. Usually when I try a computer that has been off for months. And a tick says "never ask again in this computer".

 
If the QR codes are sent via SMS texts, instead of getting a string of
numbers the users get a QR code.  Um, just what is a QR code?  Scan one
to see it is just embedded text.  Maybe Google is assuming no one has a
QR scanner app on their phone to decode what text it contains.
>
This is undefined. Probably you get a QR graphic in the computer, and
you have to take a photo of it with your phone, inside some application
they still have to tell us.
 So, I'd need two computers to login?
A computer and a smartphone.

Ever see an old video comedy skit where it takes 3 people with both
their hands to operate an overly complicated wrist watch with lots of
buttons that have be pressed concurrently?  Might've been on SNL, but I
can't find it now.
Nah, I haven't seen it :-D

 Seems they should just proclaim they will eventually require an
authenticator app.  However, those aren't all compatible with each
other.  The Google Authenticator App isn't usable at my bank where I
would have to use either the Symantec VIP or the Twilio Authy app.  I
did use the Authy app, but it didn't work everywhere, plus Authy dropped
their desktop app (Windows, Mac, Linux) leaving only their Android and
iOS apps (so I'm back to grafting a smartphone to my hand).  There are
variances in the protocols, so no one authenticator app works
everywhere.  I wasn't going to install multiple authenticator apps.
 The bank forced SMS delivery of 2FA codes.  No e-mail option.  My
workaround was to give my Google Voice number to my bank to where they
send their SMS texts, and configure my Google Voice account to forward
SMS texts to my Gmail account, so I get the 2FA codes via e-mail.  I
didn't have to suspend the login by having to roam through the house
looking for my phone.  I can read the e-mail at my desktop in an e-mail
client to get the code to enter into the web site's prompt.  All that
jumping through hoops because the bank forced their 2FA security
theater, but only via SMS.
My bank pushes messages to their own application on the smartphone. This is the preferred method (by the banks) over here. Only if you insist they grumble and let you use SMS.

 Yes, the minutes of the reported meeting where QR codes were mentioned
did not delve into just how the change will be implemented hence I said
the article is so uninformative as to be nearly FUD.  Something might
change, but no info on when or how implemented, or even how QR codes
(that contain text strings) are more secure than text strings sent over
insecure communication venues.  Someone had a wet dream, and someone
else thought it was news.
I can not post what I do not know :-p
--
Cheers, Carlos.

Date Sujet#  Auteur
2 Mar 25 * Google will no longer send SMSs with six digit codes for verification67Carlos E.R.
2 Mar 25 +- Re: Google will no longer send SMSs with six digit codes for verification1Jörg Lorenz
2 Mar 25 +* Re: Google will no longer send SMSs with six digit codes for verification14AJL
2 Mar 25 i+- Re: Google will no longer send SMSs with six digit codes for verification1Dave Royal
4 Mar 25 i`* Re: Google will no longer send SMSs with six digit codes for verification12Bill Powell
4 Mar 25 i +* Re: Google will no longer send SMSs with six digit codes for verification6AJL
4 Mar 25 i i+* Re: Google will no longer send SMSs with six digit codes for verification2Dave Royal
4 Mar 25 i ii`- Re: Google will no longer send SMSs with six digit codes for verification1VanguardLH
4 Mar 25 i i`* Re: Google will no longer send SMSs with six digit codes for verification3Frank Slootweg
4 Mar 25 i i +- Re: Google will no longer send SMSs with six digit codes for verification1AJL
5 Mar 25 i i `- Re: Google will no longer send SMSs with six digit codes for verification1VanguardLH
4 Mar 25 i +- Re: Google will no longer send SMSs with six digit codes for verification1Andy Burns
6 Mar 25 i `* Re: Google will no longer send SMSs with six digit codes for verification4Arno Welzel
6 Mar 25 i  `* Re: Google will no longer send SMSs with six digit codes for verification3VanguardLH
7 Mar 25 i   `* Re: Google will no longer send SMSs with six digit codes for verification2Arno Welzel
7 Mar 25 i    `- Re: Google will no longer send SMSs with six digit codes for verification1VanguardLH
3 Mar 25 `* Re: Google will no longer send SMSs with six digit codes for verification51VanguardLH
3 Mar 25  +* Re: Google will no longer send SMSs with six digit codes for verification2VanguardLH
3 Mar 25  i`- Re: Google will no longer send SMSs with six digit codes for verification1Jörg Lorenz
3 Mar 25  +* Re: Google will no longer send SMSs with six digit codes for verification47Carlos E.R.
3 Mar 25  i+- Re: Google will no longer send SMSs with six digit codes for verification1Jörg Lorenz
3 Mar 25  i`* Re: Google will no longer send SMSs with six digit codes for verification45VanguardLH
3 Mar 25  i +* Re: Google will no longer send SMSs with six digit codes for verification4Carlos E.R.
3 Mar 25  i i`* Re: Google will no longer send SMSs with six digit codes for verification3VanguardLH
3 Mar 25  i i `* Re: Google will no longer send SMSs with six digit codes for verification2Carlos E.R.
4 Mar 25  i i  `- Re: Google will no longer send SMSs with six digit codes for verification1VanguardLH
3 Mar 25  i `* Re: Google will no longer send SMSs with six digit codes for verification40Frank Slootweg
4 Mar 25  i  `* Re: Google will no longer send SMSs with six digit codes for verification39Dave Royal
4 Mar 25  i   +* Re: Google will no longer send SMSs with six digit codes for verification36VanguardLH
4 Mar 25  i   i+* Re: Google will no longer send SMSs with six digit codes for verification34Carlos E.R.
4 Mar 25  i   ii`* Re: Google will no longer send SMSs with six digit codes for verification33VanguardLH
4 Mar 25  i   ii +* Re: Google will no longer send SMSs with six digit codes for verification29Frank Slootweg
5 Mar 25  i   ii i+* Re: Google will no longer send SMSs with six digit codes for verification25VanguardLH
5 Mar 25  i   ii ii+* Re: Google will no longer send SMSs with six digit codes for verification23Carlos E.R.
5 Mar 25  i   ii iii`* Re: Google will no longer send SMSs with six digit codes for verification22VanguardLH
5 Mar 25  i   ii iii `* Re: Google will no longer send SMSs with six digit codes for verification21Carlos E.R.
6 Mar 25  i   ii iii  `* Re: Google will no longer send SMSs with six digit codes for verification20VanguardLH
6 Mar 25  i   ii iii   +* Re: Google will no longer send SMSs with six digit codes for verification15Carlos E.R.
6 Mar 25  i   ii iii   i`* Re: Google will no longer send SMSs with six digit codes for verification14VanguardLH
6 Mar 25  i   ii iii   i +* Re: Google will no longer send SMSs with six digit codes for verification12Carlos E.R.
7 Mar 25  i   ii iii   i i`* Re: Google will no longer send SMSs with six digit codes for verification11VanguardLH
7 Mar 25  i   ii iii   i i +* Re: Google will no longer send SMSs with six digit codes for verification4AJL
7 Mar 25  i   ii iii   i i i`* Re: Google will no longer send SMSs with six digit codes for verification3VanguardLH
7 Mar 25  i   ii iii   i i i +- Re: Google will no longer send SMSs with six digit codes for verification1AJL
7 Mar 25  i   ii iii   i i i `- Re: Google will no longer send SMSs with six digit codes for verification1Carlos E.R.
7 Mar 25  i   ii iii   i i `* Re: Google will no longer send SMSs with six digit codes for verification6Carlos E.R.
7 Mar 25  i   ii iii   i i  `* Phones and apps forced on you (was: Google will no longer send SMSs with six digit codes for verification)5Stefan Ram
8 Mar 25  i   ii iii   i i   `* Re: Phones and apps forced on you4Marion
9 Mar 25  i   ii iii   i i    `* Re: Phones and apps forced on you3Stefan Ram
9 Mar 25  i   ii iii   i i     `* Re: Phones and apps forced on you2Carlos E.R.
9 Mar 25  i   ii iii   i i      `- Sleep (was: Phones and apps forced on you)1Stefan Ram
7 Mar 25  i   ii iii   i `- Re: Google will no longer send SMSs with six digit codes for verification1Frank Slootweg
6 Mar 25  i   ii iii   `* Re: Google will no longer send SMSs with six digit codes for verification4Frank Slootweg
6 Mar 25  i   ii iii    +- Re: Google will no longer send SMSs with six digit codes for verification1Carlos E.R.
6 Mar 25  i   ii iii    `* Re: Google will no longer send SMSs with six digit codes for verification2VanguardLH
7 Mar 25  i   ii iii     `- Re: Google will no longer send SMSs with six digit codes for verification1Frank Slootweg
5 Mar 25  i   ii ii`- Re: Google will no longer send SMSs with six digit codes for verification1Frank Slootweg
6 Mar 25  i   ii i`* Re: Google will no longer send SMSs with six digit codes for verification3Andy Burns
6 Mar 25  i   ii i +- Re: Google will no longer send SMSs with six digit codes for verification1Dave Royal
6 Mar 25  i   ii i `- Re: Google will no longer send SMSs with six digit codes for verification1VanguardLH
4 Mar 25  i   ii `* Re: Google will no longer send SMSs with six digit codes for verification3Carlos E.R.
5 Mar 25  i   ii  `* Re: Google will no longer send SMSs with six digit codes for verification2VanguardLH
5 Mar 25  i   ii   `- Re: Google will no longer send SMSs with six digit codes for verification1Carlos E.R.
4 Mar 25  i   i`- Re: Google will no longer send SMSs with six digit codes for verification1Frank Slootweg
7 Mar 25  i   `* Re: Google will no longer send SMSs with six digit codes for verification2Dave Royal
7 Mar 25  i    `- Re: Google will no longer send SMSs with six digit codes for verification1Frank Slootweg
7 Mar 25  `- Re: Google will no longer send SMSs with six digit codes for verification1Chris in Makati

Haut de la page

Les messages affichés proviennent d'usenet.

NewsPortal