{"id":3732,"date":"2013-06-13T15:13:21","date_gmt":"2013-06-13T15:13:21","guid":{"rendered":"http:\/\/learningaloud.com\/blog\/?p=3732"},"modified":"2013-06-13T15:19:05","modified_gmt":"2013-06-13T15:19:05","slug":"something-you-know-and-something-you-have","status":"publish","type":"post","link":"https:\/\/learningaloud.com\/blog\/2013\/06\/13\/something-you-know-and-something-you-have\/","title":{"rendered":"Something you know and something you have"},"content":{"rendered":"<div>\n<p>Data protection is obviously a very important issue and companies that encourage us to use their services to store our data must take security seriously. Two-factor authentication has been developed to offer greater security. I have heard two factor authentication described as something you own and something you know. Cute and easy to remember, but the operationalization translates as &#8220;you know your password&#8221; and you &#8220;own your phone&#8221;. In concept it works like this, once you turn two-factor authentication on, your existing services are immediately disabled. You now must use the two factors to activate them again. So, instead of using your password which is initially rejected, you use a code (a number) that is sent to the SMS system on your phone when your password fails.<\/p>\n<p>Here is my problem with this system. It seems designed by engineers with little insight into how real people actually use devices. It first assumes you have a smart phone (there is a way around this, but the way around makes the process even more complicated). Second, it is not system wide approach and must be completed for each device. My situation involved authenticating (so far) on my phone, two iPads and a Nexus 7, three lap tops and three desktops. This may be a little extreme, but not really. I have equipment purchased for me by my university and equipment I have purchased for my personal use, etc.<\/p>\n<p>It gets worse. I commonly use Google apps through a browser. For a time, I had to authenticate each time I opened the browser. This was a hassle because I am not one of those tech guys who carries my phone or enjoys doing all possible things with it. The issue here concerned my phone settings. As a security measure (I use so many different devices &#8211; mine and public), I had my browser set to delete cookies when I shut down. Hence, the engineer&#8217;s solution of permanence was to set a cookie. So, I changed this permission and this seemed to fix the problem with browsers. It is kind of funny though, don&#8217;t you think, to address a security issue by eliminating a security precaution?<\/p>\n<p>OK, so you authenticate once using something you have and you use your password (something you know) each time and you have a cookie set and this fixes the browsers (once for each one by the way). Then there are your apps. Apps don&#8217;t set cookies (I don&#8217;t think) so this process will not work for apps. Google has apps. What were they thinking?<\/p><\/div>\n<div><\/div>\n<div>There is a <a href=\"https:\/\/support.google.com\/accounts\/answer\/185833\">completely different system for apps<\/a>. Instead of the app sending a message to your phone and setting a cookie, you request an app-specific password using your device and you are sent a 16 element password to enter. You destroy any evidence\u00a0of this display. Then, the app works. Again, repeat with all devices.<\/div>\n<div><\/div>\n<div><a href=\"http:\/\/learningaloud.com\/blog\/wp-content\/uploads\/2013\/06\/googleauthenticate.png\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"3733\" data-permalink=\"https:\/\/learningaloud.com\/blog\/2013\/06\/13\/something-you-know-and-something-you-have\/googleauthenticate\/\" data-orig-file=\"https:\/\/learningaloud.com\/blog\/wp-content\/uploads\/2013\/06\/googleauthenticate.png\" data-orig-size=\"582,233\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"googleauthenticate\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/learningaloud.com\/blog\/wp-content\/uploads\/2013\/06\/googleauthenticate.png\" class=\"aligncenter size-full wp-image-3733\" alt=\"googleauthenticate\" src=\"http:\/\/learningaloud.com\/blog\/wp-content\/uploads\/2013\/06\/googleauthenticate.png\" width=\"582\" height=\"233\" srcset=\"https:\/\/learningaloud.com\/blog\/wp-content\/uploads\/2013\/06\/googleauthenticate.png 582w, https:\/\/learningaloud.com\/blog\/wp-content\/uploads\/2013\/06\/googleauthenticate-300x120.png 300w\" sizes=\"auto, (max-width: 582px) 100vw, 582px\" \/><\/a><\/div>\n<div><\/div>\n<div>OK &#8211; perhaps there is a better way and I don&#8217;t understand. However, what I have described here works, but was labor intensive.<\/div>\n<div><\/div>\n<div>I am concerned. I am heading to Russia for three weeks. I value security, but I also do not intend to take my phone. I know there is a way to request multiple codes I can take with me (printed on a piece of paper in my bill fold). I keep thinking there must be a better way.<\/div>\n<div><\/div>\n<div><\/div>\n<p>&nbsp;<\/p>\n<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_3732\" class=\"pvc_stats all  \" data-element-id=\"3732\" style=\"\"><i class=\"pvc-stats-icon medium\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/learningaloud.com\/blog\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p>\n<div class=\"pvc_clear\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Data protection is obviously a very important issue and companies that encourage us to use their services to store our data must take security seriously. Two-factor authentication has been developed to offer greater security. I have heard two factor authentication described as something you own and something you know. Cute and easy to remember, but &hellip; <a href=\"https:\/\/learningaloud.com\/blog\/2013\/06\/13\/something-you-know-and-something-you-have\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Something you know and something you have<\/span><\/a><\/p>\n<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_3732\" class=\"pvc_stats all  \" data-element-id=\"3732\" style=\"\"><i class=\"pvc-stats-icon medium\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/learningaloud.com\/blog\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p>\n<div class=\"pvc_clear\"><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[1],"tags":[78],"class_list":["post-3732","post","type-post","status-publish","format-standard","hentry","category-general","tag-google"],"a3_pvc":{"activated":true,"total_views":31,"today_views":0},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p1zo8Q-Yc","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/posts\/3732","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/comments?post=3732"}],"version-history":[{"count":5,"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/posts\/3732\/revisions"}],"predecessor-version":[{"id":3738,"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/posts\/3732\/revisions\/3738"}],"wp:attachment":[{"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/media?parent=3732"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/categories?post=3732"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/tags?post=3732"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}