Thursday, February 6, 2014

Google tries to enhance security, but fails to learn a lesson from 1870

Today I tried out 2-factor authentication ala Google. The process mostly worked. The notification failed miserably. I received the following email:

Hi Frank,

You have successfully created an app password

"iPad" Created on "Feb 6, 2014 10:10:40 AM"

This application password will allow you to
access your Google account from a device or
application that can only be configured
with a username and password, rather than
a username, password, and a verification code. 

Hmm, notice anything conspicuously missing? Oh yes - a timezone. Seems this new service couldn't possibly be used by anyone not on the west coast of the US.

#GoogleFail

Perhaps they should read this article