Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

May 13th, 2011, 16:56 GMT · By

Facebook Officially Introduces Two-Factor Authentication

SHARE:

Adjust text size:


Facebook launches Login Approvals
Enlarge picture
Facebook has officially launched a two-factor authentication feature dubbed Login Approvals aimed at protecting user accounts even in the case of login compromise.

Multi-factor authentication systems combine user passwords with additional verification methods in order to ensure the user's identity.

Such mechanism have been commonly used in the financial sector where the secondary code is generated by a hardware token in the user's possession or on their mobile phone.

Facebook's Login Approvals requires users to associate a phone number with their account and sends the authentication code to it when needed.

The feature kicks in only when users attempt to login from a device that hasn't been used before on the account.

This helps users protect their account from abuse even if hackers manage to steal their login credentials through phishing, malware infection or other ways.methods.

"If we ever see a login from an unrecognized device, you'll be notified upon your next login and asked to verify the attempted account access.

"If you don’t recognize this login, you'll be able to change your password with the knowledge that while some one else may have known your login credentials, they were unable to access your account and cause any harm," Facebook explains.

In case people lose or forget their phone, they will still be able to access their account from a device that has already been flagged as trusted.

The feature does raise some privacy concerns because it requires users to share their phone number with Facebook, a company that doesn't have a great track record when it comes to keeping information private.

Earlier this year Facebook outlined plans to allow apps to access people's home address and phone numbers, a feature which the company is still working on.

"It's a pity Facebook isn't offering an option to let you enable 2FA [two-factor authentication] every time you login. It would be even nicer if they added a token-based option (and they'd be welcome to charge a reasonable amount for the token) for the more security-conscious user," says Paul Ducklin, head of technology for the Asia Pacific region at antivirus vendor Sophos.

TELL US WHAT YOU THINK:

1,820 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Facebook Deploys Systems to Detect and Block Scam Techniques

Facebook Taps Web of Trust to Improve Its Malicious Link Detection Capability

All Facebook Apps to Support HTTPS by October

Facebook Begins Rolling Out Two-Factor Authentication

READER COMMENTS:


Comment #1 by: Paul on 16 May 2011, 18:33 UTC reply to this comment

It’s great that Facebook is strengthening security by using two-factor authentication. People share so much personal information on Facebook that relying on a single layer of password protection is simply not enough. However, sending a code by SMS text message is not very secure because they are sent in clear text. If the user were to lose their phone or have it stolen, anybody could read that text message and fraudulently authenticate.

More websites need to use two-factor authentication like Facebook is doing, but a more secure and easier-to-use approach is to send an image-based authentication challenge to the user’s phone, like Confident Technologies provides: http://bit.ly/dMNzB5. A grid of pictures is displayed on the user’s smartphone and to authenticate, the user must correctly identify the pictures that fit their pre-chosen, secret categories. Even if someone else had possession of your phone, they wouldn’t be able to authenticate because they wouldn’t know your secret picture categories.


Comment #2 by: shibuyume on 07 Jun 2011, 08:13 UTC reply to this comment

There is a two-factor authentication app for iphone http://handheld.softpedia.com/get/Security/Utilities/Mobile-BetterThanPin-117464.shtml

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM