EmailDiscussions.com  

Go Back   EmailDiscussions.com > Email Service Provider-specific Forums > FastMail.FM Forums > FastMail.FM General Discussions
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

FastMail.FM General Discussions Everything that does not belong in the help or feature requests Forums goes here. This includes discussion about FastMail.FM policies, development (such as stylesheet development),FastMail.FM support sites like the Wiki, and so forth.

Reply
Thread Tools
Unread 10th August 2012, 03:48 PM   #1
Ginix
Member
 
Join Date: Aug 2012
Posts: 30
Preferred Alternative Login

What is your preferred alternative login method in Fastmail?
Ginix is offline   Reply With Quote
Unread 11th August 2012, 10:38 AM   #2
n5bb
Intergalactic Postmaster
 
Join Date: May 2004
Location: Irving, Texas
Posts: 6,025
I use two Alternative Login Methods:
  • Regular: If you normally log in using this type of password, your backup email address and existing passwords can't be changed. Since you don't need to change those things very often, this adds security to your account. For example, if you accidentally leave you computer logged into Fastmail where others can access it, others can't change the two most critical settings in your account.
  • OTP (One Time Password set): I use this if I'm in a hotel business center or anywhere else I'm using a computer which doesn't belong to me. I print the OTP list and keep it in my wallet (using a short base password I can remember). Then when I need to use Fastmail from that untrusted computer I use an OTP password (with my memorized base password) and mark it off the list, since it can only be used once.
    • If someone is keylogging (capturing your keystrokes) as you log in, they can't use that password later because it only works once.
    • If you lose the OTP printout it can't be used by others, since they don't have the base password you memorized.
    • The only way someone could get around this system would be if they keylogged a successful login (so they knew your base password) and obtained your OTP password list.
Bill

Last edited by n5bb : 12th August 2012 at 04:59 AM. Reason: OTP passwords can be used in any order
n5bb is offline   Reply With Quote
Unread 11th August 2012, 04:30 PM   #3
Ginix
Member
 
Join Date: Aug 2012
Posts: 30
Thanks for the reply Bill
Ginix is offline   Reply With Quote
Unread 11th August 2012, 08:07 PM   #4
Quincy_G
Member
 
Join Date: Jun 2012
Location: Germany
Posts: 40
Quote:
Originally Posted by GeraldR View Post
Bill,

Are the OTP passwords accepted only in the order they are printed?
No,
One-Time passwords
When you create a one-time password set, a page with 100 randomly generated passwords is presented for printing. You must print it before leaving the page, because it's not cached and you can't view the passwords again. You can use these passwords in any order.
Quincy_G is offline   Reply With Quote
Unread 11th August 2012, 10:17 PM   #5
janusz
The "e" in e-mail
 
Join Date: Feb 2006
Location: EU
Posts: 3,051
Quote:
Originally Posted by n5bb View Post
IThe only way someone could get around this system would be if they keylogged a successful login (so they knew your base password) and obtained your OTP password list and knew which password was the next one to be used.[/list]
Quote:
Originally Posted by Quincy_G View Post
You can use these passwords in any order.
Spot a contradiction ....
janusz is offline   Reply With Quote
Unread 11th August 2012, 10:31 PM   #6
FredOnline
Cornerstone of the Community
 
Join Date: Apr 2011
Location: Manchester UK
Posts: 711
FastMail Help indicates:

When you create a one-time password set, a page with 100 randomly generated passwords is presented for printing. You must print it before leaving the page, because it's not cached and you can't view the passwords again. You can use these passwords in any order.

For myself, when traveling - I always have my netbook with me, so don't need to use other computers.

However, my netbook has a restricted login to (hopefully) limit any wifi hacking, etc. from severely damaging the account.
FredOnline is offline   Reply With Quote
Unread 12th August 2012, 04:59 AM   #7
n5bb
Intergalactic Postmaster
 
Join Date: May 2004
Location: Irving, Texas
Posts: 6,025
Yes, I made an error. The OTP passwords can be used in any order, but you can only use each of them only one time. I was confused because if you create an OTP list named "test"and try to log in twice with the same password from that OTP list you get this error message:
Quote:
ERROR: OTP test:15 has been used, first unused is test:16
You are shown the OTP number of your attempt (1-100) and the OTP number of the next unused password starting at 1 (the lowest number which is unused). I thought this meant that you had to use them sequentially starting at 1 (which seems to be easiest). But you can use them in any order if you wish, although I can't see why you would want to do this.

My previous post has been corrected. Thanks for pointing out my error!

Bill
n5bb is offline   Reply With Quote
Unread 31st August 2012, 12:24 AM   #8
zyler
Junior Member
 
Join Date: Jun 2007
Posts: 22
I use an alternative login with a base password plus a yubikey when I am not confident of the environment I am in.
zyler is offline   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT +9. The time now is 08:48 AM.

 

Copyright EmailDiscussions.com 1998-2013. All Rights Reserved