Live data from Hacker News

Two-factor authentication is a mess

theverge.com

31–40 of 112 posts

Re: Two-factor authentication is a mess

#31

I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…

I only enable 2FA if it's TOTP or HOTP. In the case of TOTP I save the key (the data in the QR code) in my password manager (KeePass), in the case of HOTP my backup key is in my fireproof safe at home along with other important documents. That's admittedly a small portable box with a carry handle, so easy for a burglar to steal, but it's also easy to get to and I can take it with me if I ever have to evacuate or move…

Saving the 2FA key along with your password makes it a single factor. I just add every new key to my Yubikey (as well as FreeOTP on my phone), so I have a backup if one breaks (this is on top of the backup codes).

Re: Two-factor authentication is a mess

#32

I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…

The failure modes of 2FA and what happens when a token is lost or breaks are definitely one of the pain points.

I'm not a fan of the "back up recovery token" approach, as if you only need the backups once every couple of years, a lot of people (myself included) are likely to misplace, forget where the tokens were.

My current approach is TOTP with sync via iCloud, so the tokens are available on each of my mobile devices, so unless I lose all of them I should be ok.

Of course that provides a weak point (my iCloud account) but there's always a tradeoff somewhere.

Re: Two-factor authentication is a mess

#33
post #29

It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…

but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service.

Cloudflare supports Authy and Google Authenticator (or any TOTP-compliant app): https://blog.cloudflare.com/you-can-now-use-google-authentic...

Re: Two-factor authentication is a mess

#34

I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…

I got a $20 fire-resistant lock box just to keep my backup codes in, written down on index cards.

It was a huge pain in the ass to go back into all my accounts and get the codes. In many cases, I had to reset 2FA to get the codes. But now that I've done this, it's easy to keep up when adding 2FA to an account, and I no longer have the anxiety of worrying about getting locked out of important accounts.

Another idea I've been considering is a separate password manager account (from a different provider) just for backup codes. It would have a really hard password and 2FA stored on paper.

Re: Two-factor authentication is a mess

#35
post #29

It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…

I just consider them as not supporting 2FA. I'm looking at you, Namecheap. My domain registrar not having two-factor authentication in 2017 is preposterous.

I have run into several occasions when I need to urgently sign into my NameCheap account only to discover that the SMS 2 factor auth is not working. (I hit the button to send the code and nothing comes through)

Very convenient!

Re: Two-factor authentication is a mess

#36
post #29

It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…

What annoys me most about using SMS for 2FA is that it's useless if you ever travel to another country and don't have global roaming enabled.

Re: Two-factor authentication is a mess

#37
post #34

I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…

I got a $20 fire-resistant lock box just to keep my backup codes in, written down on index cards. It was a huge pain in the ass to go back into all my accounts and get the codes. In many cases, I had to reset 2FA to get the codes. But now that I've done this, it's easy to keep up when adding 2FA to an account, and I no longer have the anxiety of worrying about getting locked out of important accounts. Another idea I'…

Completely unrelated to 2FA... but what kind of fire-resistant lock box did you get? I'm looking into something like this for the same reason.

Re: Two-factor authentication is a mess

#38
post #29

It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…

I just consider them as not supporting 2FA. I'm looking at you, Namecheap. My domain registrar not having two-factor authentication in 2017 is preposterous.

Namecheap does have 2fa... https://www.namecheap.com/support/knowledgebase/article.aspx...

Do you mean because they only support SMS based 2fa?

Considering they have a drop down menu it's possible they just have not had time to develop the other options?

Re: Two-factor authentication is a mess

#39
post #29

It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…

I thought Authy was TOTP?

Re: Two-factor authentication is a mess

#40

I lost my 2FA to AWS (my phone broke), now I have to provide: 1) A completed, signed, and notarized Identity Verification Form and Affidavit 2) A photocopy of the AWS account owner’s primary proof of identification, such as a State driver’s license or US passport. (note that I don't live in the US) 3) A photocopy of the AWS account owner’s proof of address matching the address on record (I don't live there anymore) i…

For me I opened a ticket and they verified few questions and address on phone and was cleared on 2FA , in fact I wiped my phone forgot about gauth few times had no issue with aws
Post reply on HN