I still much prefer TOTP whenever possible as the phone is potentially vulnerable to social engineering against the SIM provider.
Two-factor authentication is a mess
61–70 of 112 posts
Re: Two-factor authentication is a mess
#62Earlier quoted context omitted.
Thank you, I didn't know this, and it was something I was judging against CF for years. It makes me a little uncomfortable though that there aren't any offline recovery codes in the event the TOTP device is lost/stolen/etc EDIT: as pointed out below, there is one briefly on the QR dialog, it's not a separate sheet you generate/download like GitHub/Google/etc
Be careful using 2FA on CF. I got locked out of my account because I reformatted my phone and hadn't kept backup codes. That's my fault, not CF's. They wouldn't accept email verification or uploading a html file to the root of my domains to grant access. But here's the kicker: Cloudflare were happy to grant access if I could recall some previous name server history for some of my domains. Information that is in the p…
Re: Two-factor authentication is a mess
#63It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…
I thought Authy was TOTP?
Re: Two-factor authentication is a mess
#64https://blog.namecheap.com/authy-based-2-factor-authenticati...
Re: Two-factor authentication is a mess
#65It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…
Re: Two-factor authentication is a mess
#66Namecheap is still the big one that only supports SMS 2FA for me. It has apparently been a big engineering project to add TOTP support so they've delayed it for many (4+) years. They did recently blog they were pausing all other development to add TOTP support but there has been no progress update and their initial promise of "in 60 days" has since passed... https://blog.namecheap.com/authy-based-2-factor-authenticat…
Re: Two-factor authentication is a mess
#67It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…
There are other companies like Google that first require you to set it up over SMS before they allow you to add a security token.
What it means in practice is that when we train people to set up 2FA, we have to teach them a somewhat elaborate dance of enrolling their phone number, adding the U2F and TOTP authenticators, removing their phone number, and then making sure they don't have a recovery phone number set.
Re: Two-factor authentication is a mess
#68It drives me nuts when sites insist on using SMS or Authy instead of TOTP for 2FA. I get that some users might not be sophisticated or motivated enough to setup TOTP but when somewhere like Cloudflare insists on ONLY using Authy it makes me want to look elsewhere for service. I've spoken to AT&T numerous times to see what extra steps I can take to secure my account against any changes. So far all that's led to is an…
I thought Authy was TOTP?
Re: Two-factor authentication is a mess
#69Earlier quoted context omitted.
As of January, 2014 Namecheap said[1]: "Currently, we only accept SMS authentication but Google Authenticator, Authy, and TOTP authentication are planned." More than three years seems to me a long development cycle to add TOTP support. Am I being disingenuous to think they just don't care? [1] https://blog.namecheap.com/account-security/
It's not that they don't care. It's that $CARE_AMOUNT That formula would immediately shift if a high profile website registered on Namecheap encounters an SMS hijacking.
Re: Two-factor authentication is a mess
#70Earlier quoted context omitted.
It's not that they don't care. It's that $CARE_AMOUNT That formula would immediately shift if a high profile website registered on Namecheap encounters an SMS hijacking.
TOTP codes are straightforward to bootstrap. It's not rocket science.