Advertisement
  1. Computer Skills
  2. Security
Computers

2-Factor Authentication Without Hassle

by
Difficulty:BeginnerLength:ShortLanguages:

Screencast

2-Factor Authentication, often referred to as 2FA, simply means using a password (something you know) and a second factor (something you have) to log into an application or website.

In the beginning, many companies would use their own proprietary 2-Factor Authentication by asking for both a password and then a personal identification code or passphrase before they sign in the user.

More secure companies would send users a key fob or USB stick that generates a predetermined set of random numbers and letters. Some other companies may even require a text or phone call be sent to a verified phone number.

The user logs in by entering a password, then the random number/letter hash generated for that particular day and time. Only when both the password and hash both match up to what the company has on file, is the customer actually logged in.

Old school 2FA using a key fob
2FA using a key fob

Using a key fob system was a costly and time-consuming option for most companies as it involved manufacturing, processing and shipping those fobs. But now, thanks to the ubiquity of smartphones, companies like Google or Authy can create apps that act as those key fobs. Thus eliminating the headaches of 2FA for companies and their users alike.

Now 2FA is easy to implement and makes the websites and applications you use so much more secure. When secured by 2FA, the hacker would need both the user's password and their random hash. Based on the way Google and Authy generate those hashes, the likelihood of a hacker acquiring both is almost nonexistent. So why not spend a few minutes making the websites and applications you use daily more secure?

In this tutorial I’ll show you how to set up 2-Factor Authentication on:

Turn on 2FA for Slack Using Google Authenticator

Slack recently announced that a four month long hack of user profiles had occurred and just recently been detected. While they assured the public that no financial data was compromised, they did admit that user profile data was. The silver lining to this very dark cloud was that the same day they announced the hack, they also enabled 2-Factor Authentication.

To enable 2FA on Slack, log in then click the upward-chevron next to the username. Choose Your Account. Click the Expand link next to Two factor Authentication. Enter your Slack password and click Enable two factor authentication. The following screen should look like similar to this:

2fA on Slack using Google Authenticator
2FA on Slack using Google Authenticator

On the iPhone, launch the App Store and do a search for Google Authenticator. Be sure that the publisher is listed as Google and the cost is Free. Download/install the application.

Open Google Authenticator. Click Begin Setup. Then click Scan Bar code. Hold the phone up to the bar code on the computer to allow it to scan. Once scanned the Slack channel will be a permanent fixture in the Authenticator app.

A 2FA code in Google Authenticator
A 2FA code in Google Authenticator

From now on, Slack will not only ask for a username and password, but it will also ask for the random number generated inside the Google Authenticator application before logging in. Those two factors will keep Slack much more secure.

Turn on 2FA for Coinbase Using Authy

Coinbase is a great online wallet where you can buy, sell, or store bitcoins. But because recovering a lost or stolen bitcoin is next to impossible, I strongly recommend enabling 2FA before any transfer in or out of the wallet is authorized.

To set up 2FA on Coinbase using Authy, log into Coinbase. Click the downward chevron next to the name, then click Settings. Click Security, then under Two-Step Verification Settings choose Any amount of bitcoins. Finally, click Save.

To get the code that will be used as the second factor of authentication going forward, download Authy from the App Store and launch it. Enter the phone number with area code to authorize the device.

Authorizing a device in Authy
Authorizing a device in Authy

Choose the preferred way to get the initial authorization code: either SMS or Phone call. Enter the code on the following screen. Click the + icon to add a new application. Choose Coinbase or scan the QR code.

Adding a 2FA account to Authy
Adding a 2FA account to Authy

Going forward Coinbase will require both a username/password combination and the randomly generated code from Authy.

Conclusion

In this tutorial I demonstrated 2-Factor Authentication for two different websites using two different iPhone applications. But don't stop there! I strongly encourage creating a list of all the applications or sites used daily. Check to see which ones offer 2FA and which ones don't.

If they do offer 2FA, enable it as soon as possible. There is a good chance that they will use either Google Authenticator or Authy, so setup should be easy. If they do not offer 2FA, encourage them via email or phone to do so. It is, after all, your information they are storing. 

















Advertisement
Advertisement
Looking for something to help kick start your next project?
Envato Market has a range of items for sale to help get you started.