The “big” news of the week (thus far), if you can call it that, is Google’s announcement of the availability of soft tokens for Google Apps as of today (read about in their post “Moving security beyond passwords“). From a security perspective I’m greatly underwhelmed. Maybe I’ve just become jaded in my old age, but this really strikes me as a big “so what?” announcement. AOL did this several years ago (unsuccessfully, I might add) using RSA hard tokens. The reason for their failure is myriad, ranging from a lack of promotion to requiring customers to pay for it, but ultimately it came down to one specific concern: usability.

I don’t for a minute accept TechCrunch’s take on this announcement (see: “Google Is Making Your Account Vastly More Secure With Two-Step Authentication“). Sure, having 2-factor authN as an option is great, and is certainly better than just using a password, but let’s be very honest about something here: due to the resulting decrease in usability, how many people will actually opt into this solution? Also, let’s not also discount the relatively limited geographical applicability to this approach. For example, I travel from the US to Mexico last week, which caused me to not have access to mobile networks and, most importantly, TXT messages (SMS) due to exorbitant roaming costs. On travel in Mexico is probably where I would need the additional security of 2-factor authN more than at home in the US. And yet, to use the service, I would not have been able to make use of the service.

We also know from experience that users typically do not like having additional login steps, nor do they like having to wait for things like second-factor tokens to arrive via TXT/SMS or email. I know I hate having to wait when I login to banking or credit card sites today. How will this go over with Google? I’m guessing it will be largely ignored.

Instead of promoting old, tired practices like passwords and various manually-entered factors, I would have been much more excited if Google had announced an entirely new class of authentication mechanisms. Unfortunately, no such luck; and, until that happens, we’re stuck here in the land of the living and perpetually compromised. Back to the old mantra of “strong” passwords (or at least suitably long ones – 12+ characters, and forget about complexity rules as they’re generally less relevant today… oh, and don’t reuse passwords across sites!).

2 thoughts on “Does Mainstream 2-Factor Matter?

  1. Kevin Heald says:

    I actually think value here is for those companies that use Google Apps. There are a LOT of companies that use Google Apps, and providing them a way to better secure their employees accounts is a step in the right direction. Employers can at enforce the policy (if Google supports a policy….which if they don’t, they should) and feel a little better about their employees authenticating to an outsourced service.

  2. Ben says:

    @Kevin – You’re probably right that there is value. However, I still doubt the likely degree of adoption. I can’t think of any situation where 2-factor tokens (soft or hard) have been welcomed by the user-base. Given enough time and chaffing, it seems inevitable that these solutions will eventually be discarded.

Comments are closed.