A warning to anyone who uses verisign vip access App two factor authenticat


Recommended Posts

When you first open the application up it generates a "Credential ID" and then based off that ID starts generating Security codes. Now if say with Paypal you register that Credential ID and that security code you can then use this app on your smart phone as two factor authentication

.mzl.lhzbvxcv.320x480-75.jpg

Accept, there is one problem

If you ever, for any reason have to reinstall the application, it gives you a COMPLETELY DIFFERENT Credential ID and thus the app will no longer generate codes that will work with your sites you already have setup.

So unless have "I for got my two factor authentication device" which defeats the purpose. You will be totally screwed.

I wish it would some how register with an account so upon re-installation of the application you retain the same Credential ID.

I got totally ****ed by this when I used it on my Paypal account. For security reasons I did not want someone to be able to get around my security key by clicking "I don't have it with me"

Then I formatted my iPod touch 4th gen and went to reinstall the VIP app and got a different ID I was totally locked out of my account. This was before you could also use your cell phone, or in the case of eBay they only allow you to activate one device on the account

So this is just a slight warning for anyone who uses this as their sole method of two factor authentication.

  • Like 1

if the credential ID was generated from a hardware ID for example, then wouldn't this create another security risk if you lose your device or even sell it?

and about creating some account, again, wouldn't that also create another security risk? if someone hacks that account, then they can generate codes too.

I think even though their method is somewhat cumbersome, its still the safest route.

if the credential ID was generated from a hardware ID for example, then wouldn't this create another security risk if you lose your device or even sell it?

and about creating some account, again, wouldn't that also create another security risk? if someone hacks that account, then they can generate codes too.

I think even though their method is somewhat cumbersome, its still the safest route.

Why not create the credentials ID based on a device ID + a password or pin of your choice.

First allow you to protect opening the app with a password (right now there is none)

second when you go to install / reinstall the application, have it ask for the special pin or password that it then hashes with the device ID to create the same Credential ID.

Why not create the credentials ID based on a device ID + a password or pin of your choice.

of course they can do that,and it would be easier,but a random credential id is still safer. the algorithm to generate the credential id from a hardware id and password would be known by looking at the code of the app. someone would just have to know your password,and a piece of static info that will never change, to be able to start generating codes on their own.

of course they can do that,and it would be easier,but a random credential id is still safer. the algorithm to generate the credential id from a hardware id and password would be known by looking at the code of the app. someone would just have to know your password to be able to start generating codes on their own.

Well assuming someone isn't an idiot and wouldn't use a password they always use. how would anyone know what the password would be? I'm no longer using this application because you could VERY easily get locked out of your account.

Lets say you are using this as a sole two factor authentication and the phone dies? Or android crashes or for any reason you have to reinstall the application. Anyone using this would be so ****ed.

I still like a Text message SMS.

Well assuming someone isn't an idiot and wouldn't use a password they always use. how would anyone know what the password would be? I'm no longer using this application because you could VERY easily get locked out of your account. I still like a Text message SMS.

there are plenty of idiots :) ,and that's why this application does what it does the way it does it.

there are plenty of idiots :) ,and that's why this application does what it does the way it does it.

I had a hell of a time getting back into my paypal account. Took a phone call.

see how secure it is,even the rightful account holder has a hard time getting into his account :laugh: . you win,verisign.

What about how Google authenticator does it. They give you special QR codes. That you can save. If you have to reinstall google authenticator on your phone you take a picture of the QR code and you are back in business! :)

What about how Google authenticator does it. They give you special QR codes. That you can save. If you have to reinstall google authenticator on your phone you take a picture of the QR code and you are back in business! :)

that's actually a really good idea. well until you lose your QR codes. what do you do if that happens?

lol yep. gotta love security.

As a test i've uninstalled Google Authenticator from my phone and reinstalled it and then took a picture of the saved QR code. It worked beautiful, I almost got a tear in my eye.

As a test i've uninstalled Google Authenticator from my phone and reinstalled it and then took a picture of the saved QR code. It worked beautiful, I almost got a tear in my eye.

I just installed the Microsoft authenticator app on my WP,and it works beautifully too for my microsoft accounts by scanning QR codes. nice.

I just installed the Microsoft authenticator app on my WP,and it works beautifully too for my microsoft accounts by scanning QR codes. nice.

Did you almost get a tear?

  • 2 years later...
12 minutes ago, Bachsau said:

Lol, so you blame the app for you being dumb enough not to remove it from your account before resetting your device?

There is that. But also if the device were to get broken or stolen and you had to reinstall the application on a new device. Same issue.

 

 

13 minutes ago, warwagon said:

There is that. But also if the device were to get broken or stolen and you had to reinstall the application on a new device. Same issue.

 

 

This is the way that keys are supposed to work. ;)

 

If you lose your key you can't open your door. I mean you can't blame a security app for… well, being secure. To get access to your PayPal account again, you will just have to provide some more of your information to prove your identity, which I think is okay if you don't get your devices stolen on a daily basis.^^

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • One of Logitech's best productivity mice is now available for just $79.99 by Taras Buria The MX Master 3S, formerly Logitech's flagship productivity mouse, is now available at an all-time low price during Prime Day sale. Thanks to the latest discount, you can have this mouse for as little as $79.99. This large-sized mouse has many things to like. From its ergonomic shape to the iconic MagScroll wheel, the MX Master 3S is a great productivity-focused accessory. It has an 8K DPI sensor that tracks on various surfaces, including glass. Its main MagScroll has two modes: ratched and infinite, with the latter capable of scrolling up to 1,000 lines in just a second. Additionally, there is a secondary wheel for horizontal scrolling. The MX Master 3S has plenty of buttons, which can be remapped to gestures, keyboard shortcuts, or other actions in the Options+ app on Windows and macOS. You can connect the mouse to up to three devices (via Bluetooth or the Bolt connector) and switch between them with a dedicated button. You also get a USB Type-A to Type-C cable to recharge the built-in battery, which lasts up to 70 days on a full charge, and a quick one-minute charge gets you three hours of use. Logitech MX Master 3S - $79.99 | 20% off for Prime Members Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Exactly, this is just the beginning. I hope that by that time, our inept politicians devise something like a Universal Basic Income, because unemployment and poverty rates will skyrocket otherwise. And believe me, robots that perform physical work aren't a matter of IF, but WHEN. No career is truly safe from AI/robots, it's just a matter of time.
    • Subtitle Edit 5.0.0 by Razvan Serea Subtitle Edit is a powerful, free, and user-friendly subtitle editing tool designed for creating, editing, and converting subtitles for videos. It supports a wide range of subtitle formats, including SRT, ****, and SUB, allowing users to easily modify and adjust subtitles for accurate timing and formatting. With its intuitive interface, Subtitle Edit provides a variety of features such as waveform audio display, spell-check, subtitle synchronization, and real-time video preview, making it an ideal choice for both beginners and professionals. The software also includes powerful tools for batch processing, translating subtitles, and converting between different subtitle formats. Subtitle Edit features: Create/adjust/sync/translate subtitle lines Convert between SubRib, MicroDVD, Advanced Sub Station Alpha, Sub Station Alpha, D-Cinema, SAMI, youtube sbv, and many more (300+ different formats!) Cool audio visualizer control - can display wave form and/or spectrogram Video player uses mpv, DirectShow, or VLC media player Visually sync/adjust a subtitle (start/end position and speed) Audio to text (speech recognition) via Whisper or Vosk/Kaldi Auto Translation via Google translate Rip subtitles from a (decrypted) dvd Import and OCR VobSub sub/idx binary subtitles Import and OCR Blu-ray .sup files - bd sup reading is based on Java code from BDSup2Sub Can open subtitles embedded inside Matroska files Can open subtitles (text, closed captions, VobSub) embedded inside mp4/mv4 files Can open/OCR XSub subtitles embedded inside divx/avi files Can open/OCR DVB and teletext subtitles embedded inside .ts/.m2ts (Transport Stream) files Can open/OCR Blu-ray subtitles embedded inside .m2ts (Transport Stream) files Merge/split subtitles Adjust display time Fix common errors wizard....and more. Subtitle Edit 5.0.0 changelog: Subtitle Edit 5 is a major new release and a big step for the project. For the first time, Subtitle Edit runs natively on Windows, macOS, and Linux from a single, modern, cross-platform codebase. The builds are self-contained, so no separate .NET installation is required, and on macOS and Linux the needed media components (mpv/ffmpeg) are bundled in. Please read before upgrading: Subtitle Edit 5 is a new application, not just an update of Subtitle Edit 4. It has been rebuilt from the ground up to be cross-platform, so: It is not 100% the same app. The look, layout, and some workflows have changed. Some things are in different places, and a few behave differently than in SE4. Not every SE4 feature exists in SE5 yet. SE5 covers all the core editing, conversion, sync, video playback, OCR, and online services, but some of the more specialized SE4 tools are not available yet. Features will continue to be added. If you rely on a specific SE4 feature that is missing, please keep SE4 installed alongside SE5. The easiest way to run both side by side is to use the Portable versions of SE4 and SE5, which keep their settings separate and do not interfere with each other. Which version should I use? Subtitle Edit 5: recommended for most users on Windows 10 (22H2) or newer, macOS 12+, and Linux. Subtitle Edit 4: please continue to use SE4 if you are on an older Windows version (Windows 7/8), or on older / slower computers where SE5 may not run well. SE4 remains available and is the right choice in those cases. To run SE4 and SE5 at the same time, use the Portable versions - you can try SE5 while keeping SE4 as a fallback. Download: Subtitle Edit 5.0.0 | ARM64 | ~60.0 MB (Open Source) Download: Subtitle Edit Portable | 103.0 MB View: Subtitle Edit Homepage | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Google Pixel 11 series: Here's what to expect by Hamid Ganji Google Pixel 10 series In recent years, Google has successfully turned its Pixel devices into worthy contenders in the smartphone market. The search giant is now preparing to launch the Pixel 11 series in just a few months, and many Pixel fans are likely wondering what Google has in store for them this year. The next lineup of Google smartphones includes four devices: the Pixel 11, Pixel 11 Pro, Pixel 11 Pro XL, and Pixel 11 Pro Fold. This year, we don’t expect Google to bring revolutionary upgrades to its handsets, and the Pixel 11 series is likely to receive modest hardware improvements alongside a slew of AI-powered features. Here are the rumored specifications of the Google Pixel 11 series ahead of its official debut: When will the new Pixel phones be unveiled? The last two generations of Google Pixel phones (Pixel 9 series and Pixel 10 series) were launched in August, unlike the previous three generations that debuted in October. With that in mind, we expect Google to unveil the Pixel 11 series sometime in August 2026. The exact launch date has yet to be confirmed. Google Pixel 11 CAD renders - Image via AndroidHeadlines How much will the Pixel 11 series cost? Predicting the final price of upcoming smartphones has become increasingly difficult. As you may know, RAM and memory prices are rising sharply, leading to significant increases in the cost of consumer electronics. Recently, Apple CEO Tim Cook said that price increases for some future Apple products are unavoidable, suggesting that the iPhone 18 series could become more expensive. Google has remained tight-lipped about any potential price increases for the Pixel 11 series. If the company manages to maintain last year’s pricing structure, here’s what the lineup could cost: Pixel 11: $799 Pixel 11 Pro: $999 Pixel 11 Pro XL: $1,199 Pixel 11 Pro Fold: $1,799 Given current market conditions, it may be difficult for Google to avoid raising prices unless it adopts cost-saving measures, such as equipping the base model with 8GB of RAM. Google Pixel 11 series anticipated specs: We expect the Google Pixel 11 series to debut with a new Tensor G6 processor as well as an upgraded camera system. The overall design, however, is expected to remain largely unchanged across the lineup. Specifications Pixel 11 Pixel 11 Pro Pixel 11 Pro XL Pixel 11 Pro Fold Display 6.3-inch LTPO AMOLED / 120Hz refresh rate / up to 3100 nits of brightness 6.3-inch Super Actua LTPO OLED, 120Hz refresh rate, up to 3600 nits of brightness 6.8-inch Super Actua LTPO OLED, 120Hz refresh rate, up to 3600 nits of brightness 8-inch inner screen and 6.4-inch outer display, 120Hz refresh rate, up to 3600 nits of brightness RAM & Processor Tensor G6 / 8-12GB of RAM Tensor G6 / 12-16GB of RAM Tensor G6 / 12-16GB of RAM Tensor G6 / 16GB of RAM Storage options 128GB or 256GB 256GB, 512GB, 1TB 256GB, 512GB, 1TB 256GB, 512GB, 1TB Camera 50MP main sensor, 13MP ultra-wide, 10.8MP 5x telephoto, 10.5MP front camera 50MP main camera, 48MP ultra-wide, 48MP telephoto with 5x optical zoom, 42MP selfie camera 50MP main camera, 48MP ultra-wide, 48MP telephoto with 5x optical zoom, 42MP selfie camera 50MP main camera, 10.5MP ultra-wide camera, 10.8MP telephoto camera, 10MP front camera, 10MP inner camera Battery 4,840 mAh 4,707 mAh 5,000 mAh 4,658 mAh Software Android 17 Android 17 Android 17 Android 17 The Pixel 11 series won’t be a major departure from its predecessor, with Google instead focusing on subtle improvements and AI additions such as Gemini Intelligence. However, a patent filed by Google suggests the company is working on a removable battery for its smartphones, and we could see this feature make its way to the Pixel 11 Pro Fold. Given that nearly all smartphones today lack removable batteries, such a feature would be a welcome addition to future Pixel devices. That said, it may not arrive with this year’s lineup after all, and the final decision is yet to be made by Google. The Pixel 11 series could also face an uphill battle in the market. In the Android segment, Samsung is performing well with the Galaxy S26 series, while the Galaxy Z Fold 8 lineup is also expected to launch next month. On the other hand, Apple is preparing to unveil the iPhone 18 Pro and iPhone 18 Pro Max in September alongside its first foldable iPhone.
  • Recent Achievements

    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      477
    2. 2
      +Edouard
      171
    3. 3
      PsYcHoKiLLa
      105
    4. 4
      Michael Scrip
      88
    5. 5
      Steven P.
      70
  • Tell a friend

    Love Neowin? Tell a friend!