The Inquirer-Home

Google introduces two-stage account authentication

Texting your way in
Fri Feb 11 2011, 10:51

ONLINE ADVERTISING BROKER Google plans to deploy two-stage authentication to access its accounts.

Google's two-stage authentication for accounts requires users to enter their password and then a PIN code that is either sent to the user's mobile phone via SMS or generated by an application on an Android, Iphone or Blackberry smartphone. There will be options to remember the verification code for 30 days and application specific passwords, meaning third party applications can be verified before access is granted.

Perhaps surprisingly, Google seems to have followed the lead of Microsoft, which debuted a similar two-step authentication service last year for its Hotmail service. Google had initially made its two-stage authentication available to Google Apps users last year, however it believes that now is the time for the wider public to gain access.

The motivation behind using both a password and a mobile phone to verify a user's authenticity is based on the premise that the legitimate user should have both items in order to gain access to the account.

Google account holders will be able to opt-in to two-stage authentication in the coming days, with the firm saying the process takes 15 minutes to complete.

With Google accounts becoming ever larger repositories of data, the cost of having an account hijacked is becoming ever greater. The use of mobile phone CAPTCHAs looks set to become a popular way of mitigating the threat of account thefts. µ

 

Share this:

Comments
Problem that could not be solved email stopped coming on my Blackverry Password revalidation failing repeatedly

New password not being generated. No help coming despite repeated attempts. Pl help.

posted by : P P Shrivastav, 10 December 2011 Complain about this comment
Problem that could not be solved email stopped coming on my Blackverry Password revalidation failing repeatedly

New password not being generated. No help coming despite repeated attempts. Pl help.

posted by : P P Shrivastav, 10 December 2011 Complain about this comment
What if you don't own a cell phone?

Google's two-stage authentication for accounts requires users
to enter their password and then a PIN code that is either sent
to the user's mobile phone via SMS or generated by an application
on an Android, Iphone or Blackberry smartphone.

Ok, so what if the user doesn't own a cell phone? Does this mean that no new gmail accounts will be handed out to people that don't have cell phones?

Does this also mean that google will have your cell-phone number as part of account sign-up?

posted by : SumGuy, 11 February 2011 Complain about this comment
@George

Guess us Android users don't need to worry about that.

Since I've had my Google account compromised before, have NO idea how it happened (considering how paranoid I am about security) and am thus terrified it could easily happen again, I welcome additional security measures.

I just hope they design it so it's of minimal inconvenience as I like fast access too.

posted by : Tom, 11 February 2011 Complain about this comment
@George

Guess us Android users don't need to worry about that.

Since I've had my Google account compromised before, have NO idea how it happened (considering how paranoid I am about security) and am thus terrified it could easily happen again, I welcome additional security measures.

I just hope they design it so it's of minimal inconvenience as I like fast access too.

posted by : Tom, 11 February 2011 Complain about this comment
BS from google

This is an attempt to gain the mobile phone numbers of users so that more ads can be pushed to users. I will Opt-OUT!

posted by : George, 11 February 2011 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Facebook starts selling shares

Will you buy Facebook shares?