Skip to main content
  1. Home
  2. Computing
  3. Mobile
  4. Legacy Archives

Google rolls out 007-style ‘two-step verification’ security

Add as a preferred source on Google
Image used with permission by copyright holder

Many of us go about our day, logging into online accounts from home, work, the library, the Apple store, and wherever else in order to read that inspirational story Mom e-mailed us about a kitten befriending a dog, and everything is hunky dory. Someone, on the other hand, is currently becoming the person you read about who had their password stolen, and their bank account hacked using the information they e-mailed themselves “that one time.” (Almost two thirds of all Americans have been affected, according to a study from Internet security giant Symantec. This type of digital information theft is easier than many of us realize.)

Security concerns have grown steadily over the last several years as users continue to put more and more private data behind the security vault door that is a Google account login. But perhaps these concerns are finally being laid to rest. Google is rolling out a new solution for those desiring additional protection that will make Google as the Alfred to your Bruce, the M to your James, the home base secret-keeper to your mobile, private data-accessing lifestyle.

Recommended Videos

You can now activate a “two-step verification,” which will will require you to login with your username and password as usual, and then, on a second page, fulfill a request for a verification code before admitting you to your account. This verification code, randomly generated by Google, is only valid for the few seconds while you are completing the login process, and provided to you upon your request. Anyone who steals your password, or even this secret code, will not be able to login to your account later and steal all of the details of your “girls night out” planned for next Thursday night.

Google is providing a variety of ways for you to obtain this temporary password. According to a beta tester at over at TechCrunch, you can request it via a new mobile app called Google Authenticator (for your Android, iPhone, or Blackberry), text Google for it, or have them company call you. You can also authenticate a second phone if you lose access to your primary one, or use a pre-printed list of one-time use passwords (which you will inevitably keep hidden in the sole of your shoe), if you need a fail-safe backup.

To ease the burden of this process for the numerous times a day you access your Google account, you can input a one-time authentication code for devices you use all the time. A little trickier is the requirement to generate and store app-specific pass-codes for programs like Apple Mail and iCal, which often automatically login to your Google account and regularly pull down new data for your preferred method of interface.

We’ve been on the old username-and-password system for some time now, but this new, second-tier authentication approach is starting to spread. You may have seen it on bank websites, with their periodic prompt of security questions, or a “call and answer” system with unique images tied to your account, so that you can verify the page you’re on before inputting your password. You may even have received a portable, random password-generating key fob for your corporate or securities-trading account. Yahoo has taken steps to protect users by helping team them up with Norton’s Internet Security product.

We can’t say your information is now invulnerable, but Google, as usual, has taken another promising step towards solving a big consumer problem. Google’s Accounts Help Center has details on how to get your own Google account set up with two-step verification.

Adam Milgrom
Former Digital Trends Contributor
AI models from Anthropic and OpenAI were caught breaking the rules again
A new report states AI agents from both companies took unauthorized actions during safety tests, from hacking a website to tricking real people online.
Claude website open on laptop

OpenAI and Anthropic have both had a rough few weeks on the AI safety front. OpenAI recently disclosed that its models broke out of a test environment and hacked into Hugging Face and four other organizations. The news prompted Anthropic to review its own testing, which revealed that Claude had also gained unauthorized access to three companies.

Now, the UK's AI Security Institute (AISI) has disclosed a new round of incidents (via Wired). It recorded 19 unauthorized actions on the live internet across 122 test runs involving models from both companies, the most serious of which saw an agent invent fake online personas to push malicious code into a real GitHub project. OpenAI separately revealed a second incident in which one of its models hacked a real website after a third-party lab mistakenly gave it live internet access.

Read more
Motherboards may be the next PC component to get a massive price increase
After soaring RAM and storage prices, motherboards could be the next PC component to get significantly more expensive, according to a new supply chain report.
Gigabyte X870E AORUS INFINITY NEXT motherboard on display

Building a PC from scratch has already become a lot more expensive, thanks to skyrocketing RAM and storage prices driven by rising AI data center demand. Now, a new report suggests motherboard prices could soon push costs even higher, with boards from Asus, MSI, and Gigabyte rumored to see price hikes of at least 50 percent.

Your next PC upgrade could get a lot pricier

Read more
Deepfake bosses are crashing video calls, and researchers are trying to expose them
Seeing your boss on video no longer proves they are real
Researchers at Fraunhofer SIT are fighting against deepfake meeting video calls

Entering into a meeting with your boss and several familiar coworkers inside a video conference is the next area vulnerable to cybercrimes, and it's all because of deepfake technology. Researchers at the Fraunhofer Institute for Secure Information Technology SIT are working on a real-time warning system designed to identify attempted fraud during corporate video conferences.

The report states that criminals are increasingly targeting video meetings for identity theft and financial scams, taking advantage of the trust people place in familiar faces and voices. The intention is to flag suspicious activity while the meeting is still taking place. This gives an employee a chance to stop before following an expensive instruction from an AI-generated executive.

Read more