two factor on amazon

I enabled two factor on many sites last year. Amazon is a bit late to the party, but they finally have two factor support. While they waited a long time, they did a good job with it.

Sign up was easy. They give you a choice of an authenticator app including scanning with your device to connect. Or you can use a mobile phone number for voice or text. Or you can use a landline with voice. You can set a second of these options as a backup. I like that there were choices.

You are also asked if the current device is trusted. Which is good as you don’t get prompted repeatedly from your main/home computer.

I also took this opportunity to check on twofactorauth.org to see if any other sites I use have added support. I was disappointed by how many banks don’t support two factor. I tweeted at four of them with the link on the page. (I don’t have accounts at all four).

the new two factor authentication for apple

I upgraded the OS on my iPad and MacBook Pro today. I also set up the “new” two factor system. I hadn’t set it up with the old system when I set up two factor on many other accounts.

Setup was easy as described here. I added both my home and cell numbers. I like that you can choose whether to receive a text or phone call with the code. A code was sent to or called on each phone to verify. Since I set this up from my Mac, it became a trusted device. My iPad is recognized as logged in, but not trusted so the code only appears on my Mac.

I then signed in to my apple account in Safari to try to set it up as trusted. On my Mac, the six digit verification code automatically popped up. Minor bug, it was a window that went to the background when I tabbed away and I couldn’t find it when command+tab to switched. I had to drag my browser window out of the way to get it back. When I went to look at iCloud > username > devices on my iPad, I again got the location/verification code pop up on my computer. More convenient this time since it was a different device. I like that it shows the location of the device that wants the code.

I also got an email saying I turned on two factor and that I can opt out by clicking the link for a limited time. I like that the link expires to reduce the attack surface. Of course, I can always opt out through actually logging into my account.

The only problem is that I can’t figure out how to make my iOS 9.1 iPad a trusted device. The option just isn’t there under iCloud > username > password and security.

griping about a “password” system

I emailed a company today asking for my account to be linked. I did NOT ask for a password reset. What I got was an email with plain text copy of my password. Aghhhhh! That’s just asking for someone to hack my account (or all the accounts.) Passwords should be stored using a one way hash at least.

Problem 1 – username

My user id is not my last name, email or anything I have any shot of remembering. And I didn’t get to pick it. Which means it is written down.

Problem 2 – storing the password in plain text

This company shouldn’t be storing passwords in plain text or any “encoding” where they can get the original password. And the only thing I can think of to make that worse is to email the password.

Problem 3 – password requirements

Since my password was sent in the clear, I went to change it. I wanted to make it a sentence about not emailing the password. That way if someone does it again, he/she at least has to read my note. I changed the letter s to $ in my sentence as one might expect. Guess what? Only letters and numbers are allowed.

Really guys? It’s 2015.