Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror

Comment: Re:Surely this is expected (Score 1) 49

by Eric S. Smith (#43017135) Attached to: Bypassing Google's Two-Factor Authentication

An application specific password is meant to be given to the application once and then never typed again, heavily reducing the chance of it being compromised.

If it's kept in persistent storage by the application, that actually increases the chance of it being compromised. Rather than logging keystrokes or peeking at RAM or man-in-the-middling the application in some way, you can just read a file.

"It's what you learn after you know it all that counts." -- John Wooden

Working...