A warning to anyone who uses verisign vip access App two factor authenticat


Recommended Posts

When you first open the application up it generates a "Credential ID" and then based off that ID starts generating Security codes. Now if say with Paypal you register that Credential ID and that security code you can then use this app on your smart phone as two factor authentication

.mzl.lhzbvxcv.320x480-75.jpg

Accept, there is one problem

If you ever, for any reason have to reinstall the application, it gives you a COMPLETELY DIFFERENT Credential ID and thus the app will no longer generate codes that will work with your sites you already have setup.

So unless have "I for got my two factor authentication device" which defeats the purpose. You will be totally screwed.

I wish it would some how register with an account so upon re-installation of the application you retain the same Credential ID.

I got totally ****ed by this when I used it on my Paypal account. For security reasons I did not want someone to be able to get around my security key by clicking "I don't have it with me"

Then I formatted my iPod touch 4th gen and went to reinstall the VIP app and got a different ID I was totally locked out of my account. This was before you could also use your cell phone, or in the case of eBay they only allow you to activate one device on the account

So this is just a slight warning for anyone who uses this as their sole method of two factor authentication.

  • Like 1

if the credential ID was generated from a hardware ID for example, then wouldn't this create another security risk if you lose your device or even sell it?

and about creating some account, again, wouldn't that also create another security risk? if someone hacks that account, then they can generate codes too.

I think even though their method is somewhat cumbersome, its still the safest route.

if the credential ID was generated from a hardware ID for example, then wouldn't this create another security risk if you lose your device or even sell it?

and about creating some account, again, wouldn't that also create another security risk? if someone hacks that account, then they can generate codes too.

I think even though their method is somewhat cumbersome, its still the safest route.

Why not create the credentials ID based on a device ID + a password or pin of your choice.

First allow you to protect opening the app with a password (right now there is none)

second when you go to install / reinstall the application, have it ask for the special pin or password that it then hashes with the device ID to create the same Credential ID.

Why not create the credentials ID based on a device ID + a password or pin of your choice.

of course they can do that,and it would be easier,but a random credential id is still safer. the algorithm to generate the credential id from a hardware id and password would be known by looking at the code of the app. someone would just have to know your password,and a piece of static info that will never change, to be able to start generating codes on their own.

of course they can do that,and it would be easier,but a random credential id is still safer. the algorithm to generate the credential id from a hardware id and password would be known by looking at the code of the app. someone would just have to know your password to be able to start generating codes on their own.

Well assuming someone isn't an idiot and wouldn't use a password they always use. how would anyone know what the password would be? I'm no longer using this application because you could VERY easily get locked out of your account.

Lets say you are using this as a sole two factor authentication and the phone dies? Or android crashes or for any reason you have to reinstall the application. Anyone using this would be so ****ed.

I still like a Text message SMS.

Well assuming someone isn't an idiot and wouldn't use a password they always use. how would anyone know what the password would be? I'm no longer using this application because you could VERY easily get locked out of your account. I still like a Text message SMS.

there are plenty of idiots :) ,and that's why this application does what it does the way it does it.

there are plenty of idiots :) ,and that's why this application does what it does the way it does it.

I had a hell of a time getting back into my paypal account. Took a phone call.

see how secure it is,even the rightful account holder has a hard time getting into his account :laugh: . you win,verisign.

What about how Google authenticator does it. They give you special QR codes. That you can save. If you have to reinstall google authenticator on your phone you take a picture of the QR code and you are back in business! :)

What about how Google authenticator does it. They give you special QR codes. That you can save. If you have to reinstall google authenticator on your phone you take a picture of the QR code and you are back in business! :)

that's actually a really good idea. well until you lose your QR codes. what do you do if that happens?

lol yep. gotta love security.

As a test i've uninstalled Google Authenticator from my phone and reinstalled it and then took a picture of the saved QR code. It worked beautiful, I almost got a tear in my eye.

As a test i've uninstalled Google Authenticator from my phone and reinstalled it and then took a picture of the saved QR code. It worked beautiful, I almost got a tear in my eye.

I just installed the Microsoft authenticator app on my WP,and it works beautifully too for my microsoft accounts by scanning QR codes. nice.

I just installed the Microsoft authenticator app on my WP,and it works beautifully too for my microsoft accounts by scanning QR codes. nice.

Did you almost get a tear?

  • 2 years later...
12 minutes ago, Bachsau said:

Lol, so you blame the app for you being dumb enough not to remove it from your account before resetting your device?

There is that. But also if the device were to get broken or stolen and you had to reinstall the application on a new device. Same issue.

 

 

13 minutes ago, warwagon said:

There is that. But also if the device were to get broken or stolen and you had to reinstall the application on a new device. Same issue.

 

 

This is the way that keys are supposed to work. ;)

 

If you lose your key you can't open your door. I mean you can't blame a security app for… well, being secure. To get access to your PayPal account again, you will just have to provide some more of your information to prove your identity, which I think is okay if you don't get your devices stolen on a daily basis.^^

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • No its not, there are ton of Youtube videos to get you started, what do you think people did before AI existed?
    • Read this in Humor Simpson 's voice, "Out of my way Moe".
    • You still can, its just under the Transform flyout for WordArt now
    • Likely nothing will be done in corporate America, there have been countless Tesla self-driving incidents. Then again, there have also been countless human operated incidents. It's literally daily news here in Canada, to the extent that it's now odd if we get a day where a collision doesn't get announced on the radio throughout the day...
    • SKG Hand Massager with Heat OS500 hands on by Steven Parker I was offered the chance to test out the SKG Hand Massager with Heat OS500, and full disclosure, they let me keep it regardless of my findings. Anyway, I jumped at the chance due to my long hours sitting at my desk, mousing around. Apologies for the knife cut across the top of the box; that was my doing, being a bit too heavy-handed with opening up the outer packaging. First up, what's in the box: SKG Hand Massager with Heat OS500 1x Type-C charging cable User Manual 1-Year Warranty (card) In short, everything you need to get started. According to the official Amazon listing, here are the key features: Full-Hand Air Compression: OS500 wraps your fingers, palm, and wrist with multi-chamber air compression for a complete hand relaxation experience. The extended massage chamber helps cover more of the hand and wrist area than standard palm-only hand massagers Palm Kneading with 6 Modes & 6 Intensities: Built-in palm kneading rollers add a hands-on massage feel, while 6 preset modes and 6 pressure levels let you choose the comfort level that fits your day—from gentle relaxation to a firmer full-hand massage 3 Heat Levels with Cooling Fan: Choose from 104°F, 113°F or 122°F warmth to suit different seasons and comfort preferences. The built-in cooling fan helps reduce stuffiness during heated sessions, keeping your hand feeling fresh and comfortable Easy Visual Display & Smart Timer: The digital image display clearly shows massage area, mode, intensity, heat level, and remaining time at a glance. Select 10, 15, or 20-minute sessions for quick office breaks, evening relaxation, or everyday hand care Rechargeable, Cordless & Comfortable: A 3000mAh battery supports over 90 minutes of full-function use on a full charge, with convenient USB-C charging. The soft inner lining, smooth ABS/PU finish, and premium black-gold design make OS500 ideal for home, office, or gifting With all that out of the way, here are my own findings. I gave it a try on both left and right hands, and as you can maybe see from the above YouTube Short, (sorry for the shaky video), my whole hand fits in, but my wrist barely enters the Hand Massager. I was able to push through a bit more with my fingertips extending out the other end to get a bit of massaging on the start of my wrist. Usage For some reason, there is a strap that is very difficult to fasten to my wrist with one hand. I am not sure what function it has, and it isn't mentioned in the user manual. The only thing I could find was in the product images that claimed "wrist precision". Unlike the Bob and Brad Hand Massager, this device does not massage the wrist anyway, even though a "wrist mode" is mentioned, which must be for smaller hands than I have, as it is mainly intended for the hand and fingers. In addition, for its steeper price, there are no disposable gloves provided in the box, which is a bit of an issue considering the internal cover (which appears to be elasticated nylon) cannot be removed for washing; so you are left with only one choice: always thoroughly wash your hands before using it. I can imagine this thing getting a bit grimy after a period of use, and that is a bit of a shame. With that said, the buttons on the device, from left to right, do the following: Heat button: 3-level heat control at 104°F, 113°F, or 122°F Mode button: Auto mode Circular mode Soothing mode Relax mode Palm and fingers mode Palm and wrist mode Intensity button: from (First-time users) 15Ka, 25Ka, 35Ka, 45Ka, 55Ka, 60Ka (Intensive relief) Knead button: on or off (6 pressure levels) Power button: Long-press to turn on or off Cooling button: turn on or off the cooling fan Also, in the product imagery, it states there are 36 "custom modes," but nowhere is it listed what these modes are. I can only imagine that they mean a combination of all of the above settings in different intensity levels. The device itself seems to rely on a single "kneading" mechanism located at the palm area of the hand, which spins when in use, and the other massage features are mainly utilized through the air sacs, increasing and decreasing at various levels on the hand and fingers. I am not sure it offered too much relief for someone who is typing and operating a mouse for hours at a time; further testing may be required. It does feel nice, though. Finally, you may be wondering how this fits into the scope of a tech website? Well, let me tell you something: sometimes I sit for up to 15 hours working on Neowin, and although I take breaks in between, it takes a toll on my body. I think in the immediate absence of a partner to apply relief, a good massager like this Hand Massager can shed the strains of the day in just a couple of 15-minute bursts. On the official website, this has an MSRP of $99.99, but luckily for our readers, it is selling at $10 off for just $89.99 right now on Amazon. SKG Hand Massager with Heat OS500 for $89.99 (with $10 off coupon), $99.99 MSRP For me, this gets a thumbs hands(?) down. However, it could be improved by making it so that the protective covering could be removed and thrown into the washing machine, or get yourself some disposable gloves to use with it. As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
    • First Post
      DrWankel earned a badge
      First Post
    • Reacting Well
      DrWankel earned a badge
      Reacting Well
    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      505
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      86
    4. 4
      Michael Scrip
      78
    5. 5
      Steven P.
      76
  • Tell a friend

    Love Neowin? Tell a friend!