Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have it, but one thing to consider when you add Two-step is that you need a plan when you travel overseas and may not have the same sim card. Not difficult to consider, but you still need to. Being in Europe for a few weeks with no email is no fun.


That's not a problem if you use the Authenticator app (or a compatible alternative) instead of getting codes over SMS.


The two step app works even with no connection to the internet. I dont know how but it does. I think you dont need to have the same sim card. only the phone turned on.


Google Authenticator uses TOTP (RFC 6238), which means the codes are a function of time plus a secret key. As long as your phone's clock is reasonably accurate, the app will work without any network access.

http://tools.ietf.org/html/rfc6238


You definitely don't need network access. I use Google Authenticator on my Wifi only tablet. You need an internet connection to sync it to Google's key but not after that. And, yes, when the tablet's clock is off by a few minutes, the code doesn't work.


I think that the two step code is a hash of a random number shared between Google and the app (when reading the QR code), and the current time.


In that case, use the one-time backup codes and make sure to refresh them every few logins while you're away. I think they give you eight at a time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: