Skip to content

Comment on How Apple and Amazon Security Flaws Led to My Epic Hackingparent

Comments

Why do you use the term 'application-specific passwords' although these passwords are not application-specific at all?

They are Google-generated passwords with a user label. And if you use 2-factor authentication, they are the weakest link in the chain since they provide full access to a google account except for access vectors with 2-factor authentication. In addition, every app can use such a password, not just the app you created the password for …

2-factor authentication is great and certainly recommendable but you should not fool users by using the false term 'application-specific passwords'. In addition, more complex Google-generated password would be appreciated.

Application-specific is just a friendly name.

Also this password doesn't give you full access to your Google account. You cannot log into Google web apps this way (AFAIR). Thus you won't be able to mess with account settings (passwords etc). Before you can change critical account settings Google asks you to provide your traditional password again.

Your comment is a bit harsh if not FUD.

'Application-specific' is IMHO not just a friendly but a misleading name. They are simply not application-specific.

Using one of these so-called application-specific passwords, you can delete calendars, mails and contacts. That is critical enough for most users.

An additional concern is the usual 30-day authorization you give in order to avoid entering your 2-factor token again and again. Is there any way to de-authorize such a 30-day authorization?

Anyway, I don't rule out that my perspective might be too strict. For must users, the whole Google 2-step authentication system is probably a very important step towards improved security.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.