Live data from Hacker News

Microsoft urges users to stop using phone-based multi-factor authentication

zdnet.com

21–26 of 26 posts

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#21
post #18

Earlier quoted context omitted.

It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.

This is a problem with Google authenticator, not with RFC 6238 TOTP in general. Plenty of authenticator apps support backing up your secrets.

Indeed. I’m trying to move from Google Authenticator to Authy for that reason - but the inability to backup/export from GA is a PITA... a cruel form of vendor lock-in.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#23

I literally hate when services and apps force me to use SMS-based authentication. When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment. Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authenti…

Occasionally my logged in Microsoft apps all suddenly re-request the 2f thing. Sometimes in the middle of the night. And when the 2f window pops up you can't tell which app has generated it.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#24
post #2

So how do they suggest you reset these authenticators when your phone breaks?

I strongly recommend Aegis on Android. Encrypted backups of the TOTP config, so you can easily recover it all if you lose your phone without having to reset everything, plus biometric support to unlock it.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#25
post #18

Earlier quoted context omitted.

This is a problem with Google authenticator, not with RFC 6238 TOTP in general. Plenty of authenticator apps support backing up your secrets.

Indeed. I’m trying to move from Google Authenticator to Authy for that reason - but the inability to backup/export from GA is a PITA... a cruel form of vendor lock-in.

If you are switching authenticator apps, I would suggest switching to one that respects your freedom, such as Aegis, andOTP, or KeePass.

It's worth also noting that Authy also has no official way to export your secrets, although there are workarounds: https://tij.me/blog/migrating-your-one-time-passwords-from-a...

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#26

Earlier quoted context omitted.

First, it is a good idea to setup the authentication on multiple devices. This is not hard to do. Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.

It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.

No. For two factor authentication to work the solution needs to be practical for most people. So it can’t involve multiple phones or backup schemes most people aren’t going to implement.

Otherwise you’re going to lock a lot of people out of their accounts which is not acceptable.

Ultimately this typically ends up with a reset scheme that depends on phone numbers or email addresses which means the protection, which is as strong as the weakest link, is worthless.

Post reply on HN