Live data from Hacker News

Ask HN: If I get locked out of everything, please try to help me

news.ycombinator.com

291–300 of 350 posts

Re: Ask HN: If I get locked out of everything, please try to help me

#291

Earlier quoted context omitted.

> There was a post a while back around poor and homeless people encountering exactly this problem on a regular basis. Lots of people in the comments were incredibly dismissive and sometimes actively malign about it. Even worse than that, they're often connecting from public IPs that are "suspicious" which causes automated systems to treat them more harshly. In Canada it's gotten to the point where you need an interne…

> they're often connecting from public IPs that are "suspicious" which causes automated systems to treat them more harshly. What's worse is that the the error messages never explain the problem. It's just an endless sequence of "Oops! Something went wrong" "We could not fulfill your request" "Please try again later". Could drive someone crazy if they're not savvy enough to realize what's going on.

I tried to sign up for a tutanota email account the other day through a VPN and when it came back and said "We don't trust your IP, use another connection." rather than being annoyed I was just glad they gave me a straight answer for once. It wasn't the answer I wanted but it sure beat being gaslighted into thinking I was having connection timeouts or browser incompatibilities to waste my time.

Re: Ask HN: If I get locked out of everything, please try to help me

#292
post #68

Quoted post unavailable.

I never flag content but this was an easy one. Ignoring the utter stupidity of not being able to sanely transfer money in the US, there are countless better ways of sending someone money in a scenario like this. In fact, it's hard to think of a worse way than using crypto, and I'm far from a crypto hater. Linking to a long form YT video with some gd floating talking head screencasting a Mac, with no text description…

> Linking to a long form YT video with some gd floating talking head screencasting a Mac, with no text description really just seals the deal.

Fair enough!

> I'd Western Union cash to you Doreen, if it would help, or help you purchase a good meal so you can regroup/recharge.

Very generous of you and you're right, probably more user friendly to the OP. But I can't remember I haven't used WU in a long time.

Re: Ask HN: If I get locked out of everything, please try to help me

#293

A lot of people treat printable recovery codes as something that should be protected, locked in a safe, etc. As a result they don't bother to use them as it seems like too much effort to secure them. Please do not treat them this way. They do not grant access to your account. Print many copies of your recovery codes and spread them around. Wallet, home, car, parents' house, etc. It doesn't matter if they get stolen o…

I think it’s because of the copy that usually comes with these codes. It usually reads something like “COPY DOWN THESE CODES AND KEEP THEM IN A SAFE PLACE.” Which doesn’t come off as “look, you’ll still need your password”

Yeah, the way it was written when generating the codes, I also had the impression that they would bypass everything.

Re: Ask HN: If I get locked out of everything, please try to help me

#294
I have both YubiKey and SMS 2FA active on my Google account. However, for SMS purposes I got an extra phone number that nobody knows (well, nobody but me, Google and my phone provider) and that is inactive except when (A) I need to use it for 2FA purposes or (B) I need to top it up to keep it in service (which is every 6 months, approximately).

Is there still a risk of someone cloning my simcard even though I did not, ever, share my phone number with anyone?

Re: Ask HN: If I get locked out of everything, please try to help me

#295

Earlier quoted context omitted.

I could store the secret in my password manager if I paid for Bitwarden Premium (and at $10 a year, price isn't really the issue), but then what is even the point? If my password and my secret are stored in the same place then that's really just a single factor, so I'm making the login process more annoying for no reason.

Really 2FA is just a complex way to give users a strong unique password. Everything else about it is security theatre (e.g. why do you care about your password and secret stored in the same place, when your session cookie is just stored in one place and all the attacker needs)

Well, and that's why I'm not eager to enable 2FA just to store the secrets in the same place I already store my passwords (Bitwarden).

Re: Ask HN: If I get locked out of everything, please try to help me

#296

Earlier quoted context omitted.

Losing access because someone stole your account is even worse because of how much access a Google account gives someone.

Honestly, I would suspect that for many homeless people, the "losing access" part is much, much worse than "someone else having access".

Once a hacker gets access they immediately change the password, and then the homeless person loses access anyway.

Re: Ask HN: If I get locked out of everything, please try to help me

#297

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

I use authy (free) for 2FA TOTP and have it set up on my work laptop, my home laptop, and my phone. As long as least one of those is still good, I should still be able to get in. I honestly don't know what's going on behind the scenes to know if this is not as secure as it "should" be. But this was my reaction specifically to the non-SMS TOTP 2fa: Wait, if I lose my phone there's literally no way possible to get in?…

Also, it's kinda like Google corrupted 2FA TOTP's workflow : it should work on any device that implements the right algorithm and secret key. Instead Google sometimes turns it into MFA tied to a specific mobile device.

When that happens, Google asks to confirm with a known mobile device even though I have specifically configured 2FA TOTP since 2012 to be device independent (and I currently use keepassxc or mobile equivalent to generate the totp value). Google subsequently doesn't allow login by any other method and if the required device is lost or broken you lose access.

Re: Ask HN: If I get locked out of everything, please try to help me

#298
post #49

Earlier quoted context omitted.

I could store the secret in my password manager if I paid for Bitwarden Premium (and at $10 a year, price isn't really the issue), but then what is even the point? If my password and my secret are stored in the same place then that's really just a single factor, so I'm making the login process more annoying for no reason.

I'd see it as a single point of failure, but not necessarily a single factor. If the password is compromised due to a problem on the application side, they still can't get in to your account without the TOTP code. Of course the threat model is kinda skewed because this case is more applicable when one's reusing passwords or using weak passwords, which shouldn't be happening if you're using a password manager. Maybe a…

> If the password is compromised due to a problem on the application side, they still can't get in to your account without the TOTP code.

But as you say, since I'm using a password manager, this doesn't feel like a legitimate concern. If the application's database leaks, my password is still safe, because no one will crack a randomly generated 20+ character password.

> Maybe a more relevant threat is password gets compromised from a MITM attack, in which case they still don't have access to your TOTP

But they'll have the code, so as long as they use it right away, they can still get into my account and download my data / spam my contacts / whatever.

Re: Ask HN: If I get locked out of everything, please try to help me

#299
post #294

I have both YubiKey and SMS 2FA active on my Google account. However, for SMS purposes I got an extra phone number that nobody knows (well, nobody but me, Google and my phone provider) and that is inactive except when (A) I need to use it for 2FA purposes or (B) I need to top it up to keep it in service (which is every 6 months, approximately). Is there still a risk of someone cloning my simcard even though I did not…

Be careful that the provider doesn't disable that number after 1-2 years without any activity.

Re: Ask HN: If I get locked out of everything, please try to help me

#300
post #208

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

> Am I worried about getting hacked? Absolutely! If you set a strong, long, unique password for every account, your chances of getting the account compromised are just about zero. 2FA is a good thing in most cases, but I do hate how the industry has blindly adopted it as some sort of mantra that you can't exist without. The reality is that if you chose 128+ bit passwords generated out of /dev/random, they cannot be b…

Where do you store those passwords?
Post reply on HN