Live data from Hacker News

Two-factor authentication is a mess

theverge.com

51–60 of 112 posts

Re: Two-factor authentication is a mess

#51
post #43

Earlier quoted context omitted.

but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. Cloudflare supports Authy and Google Authenticator (or any TOTP-compliant app): https://blog.cloudflare.com/you-can-now-use-google-authentic...

Thank you, I didn't know this, and it was something I was judging against CF for years. It makes me a little uncomfortable though that there aren't any offline recovery codes in the event the TOTP device is lost/stolen/etc EDIT: as pointed out below, there is one briefly on the QR dialog, it's not a separate sheet you generate/download like GitHub/Google/etc

There is a backup code.

"Your second-factor backup code is 'blah'. This can be used for manual setup, and is necessary to recover your account in case your mobile phone is lost or stolen."

Re: Two-factor authentication is a mess

#52
post #47
post #42

Earlier quoted context omitted.

SMS receiving is free everywhere, it has nothing to do with data roaming and generic roaming - available on the network - has been free since I had a mobile phone (~17 years). Doesn't make it a the best option though.

Don't know where you are from, but with the company and pre-paid plan I use, I can't receive an Australian SMS from my Australian phone when I'm not in Australia.

Europe, and even in China I was able to receive sms. MMS is a different story.

Re: Two-factor authentication is a mess

#53
post #2

One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…

I still remember the pit in my stomach when I logged into my brokerage account and saw virtually all of my money gone.

Yes, I had just bought a house. Yes, I had initiated the wire transfer. In fact, I was logging in to check my balance and make sure the transfer had gone out. But it was STILL shocking to see all my money missing.

Re: Two-factor authentication is a mess

#54
post #2

One thing I'd like is different levels of authentication based on the importance of the action. When I bought I house I drained by savings account and my brokerage account. It was scary that I could instantly transfer my life savings, with just a few clicks from the regular online screens I use each day. Such events should have extra authentication and some delays - like I need to take ID to a branch. Similarly for d…

[deleted]

Re: Two-factor authentication is a mess

#55
post #38

Earlier quoted context omitted.

Namecheap does have 2fa... https://www.namecheap.com/support/knowledgebase/article.aspx... Do you mean because they only support SMS based 2fa? Considering they have a drop down menu it's possible they just have not had time to develop the other options?

As of January, 2014 Namecheap said[1]: "Currently, we only accept SMS authentication but Google Authenticator, Authy, and TOTP authentication are planned." More than three years seems to me a long development cycle to add TOTP support. Am I being disingenuous to think they just don't care? [1] https://blog.namecheap.com/account-security/

It's not that they don't care. It's that $CARE_AMOUNT That formula would immediately shift if a high profile website registered on Namecheap encounters an SMS hijacking.

Re: Two-factor authentication is a mess

#56
post #43

Earlier quoted context omitted.

but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. Cloudflare supports Authy and Google Authenticator (or any TOTP-compliant app): https://blog.cloudflare.com/you-can-now-use-google-authentic...

Thank you, I didn't know this, and it was something I was judging against CF for years. It makes me a little uncomfortable though that there aren't any offline recovery codes in the event the TOTP device is lost/stolen/etc EDIT: as pointed out below, there is one briefly on the QR dialog, it's not a separate sheet you generate/download like GitHub/Google/etc

Be careful using 2FA on CF. I got locked out of my account because I reformatted my phone and hadn't kept backup codes. That's my fault, not CF's. They wouldn't accept email verification or uploading a html file to the root of my domains to grant access.

But here's the kicker: Cloudflare were happy to grant access if I could recall some previous name server history for some of my domains. Information that is in the public domain and can be purchased as a report.

Re: Two-factor authentication is a mess

#57
post #52
post #47

Earlier quoted context omitted.

Don't know where you are from, but with the company and pre-paid plan I use, I can't receive an Australian SMS from my Australian phone when I'm not in Australia.

Europe, and even in China I was able to receive sms. MMS is a different story.

China has great mobile infrastructure that, at least from a user perspective, is better than what Australia has to offer (it's significantly cheaper and covers significantly more area).

I still can't receive SMSs from my Australian phone when I visit there however and always pick up a local SIM for the duration of my visits.

It's not about pricing, it's just that my Australian provider has no agreements with carriers for other countries.

Re: Two-factor authentication is a mess

#58
post #56
post #43

Earlier quoted context omitted.

Thank you, I didn't know this, and it was something I was judging against CF for years. It makes me a little uncomfortable though that there aren't any offline recovery codes in the event the TOTP device is lost/stolen/etc EDIT: as pointed out below, there is one briefly on the QR dialog, it's not a separate sheet you generate/download like GitHub/Google/etc

Be careful using 2FA on CF. I got locked out of my account because I reformatted my phone and hadn't kept backup codes. That's my fault, not CF's. They wouldn't accept email verification or uploading a html file to the root of my domains to grant access. But here's the kicker: Cloudflare were happy to grant access if I could recall some previous name server history for some of my domains. Information that is in the p…

Customer Support (well, humans in general) is the biggest threat to security, unfortunately .. :(

This one comes to mind, I think I remember an Amazon-related story along the same lines .. https://www.macrumors.com/2012/08/05/apple-support-allowed-h...

Re: Two-factor authentication is a mess

#59
post #56
post #43

Earlier quoted context omitted.

Thank you, I didn't know this, and it was something I was judging against CF for years. It makes me a little uncomfortable though that there aren't any offline recovery codes in the event the TOTP device is lost/stolen/etc EDIT: as pointed out below, there is one briefly on the QR dialog, it's not a separate sheet you generate/download like GitHub/Google/etc

Be careful using 2FA on CF. I got locked out of my account because I reformatted my phone and hadn't kept backup codes. That's my fault, not CF's. They wouldn't accept email verification or uploading a html file to the root of my domains to grant access. But here's the kicker: Cloudflare were happy to grant access if I could recall some previous name server history for some of my domains. Information that is in the p…

You may not even need backup codes. Just save a copy of the google authenticator setup QR code. It's just email/key, when decoded.

Re: Two-factor authentication is a mess

#60
post #56
post #43

Earlier quoted context omitted.

Thank you, I didn't know this, and it was something I was judging against CF for years. It makes me a little uncomfortable though that there aren't any offline recovery codes in the event the TOTP device is lost/stolen/etc EDIT: as pointed out below, there is one briefly on the QR dialog, it's not a separate sheet you generate/download like GitHub/Google/etc

Be careful using 2FA on CF. I got locked out of my account because I reformatted my phone and hadn't kept backup codes. That's my fault, not CF's. They wouldn't accept email verification or uploading a html file to the root of my domains to grant access. But here's the kicker: Cloudflare were happy to grant access if I could recall some previous name server history for some of my domains. Information that is in the p…

[deleted]
Post reply on HN