Earlier quoted context omitted.
It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.
This is a problem with Google authenticator, not with RFC 6238 TOTP in general. Plenty of authenticator apps support backing up your secrets.
Microsoft urges users to stop using phone-based multi-factor authentication
21–26 of 26 posts
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#22And yet Azure login forces me to use SMS for 2FA.
You can change your settings here: https://myaccount.microsoft.com
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#23I literally hate when services and apps force me to use SMS-based authentication. When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment. Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authenti…
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#24So how do they suggest you reset these authenticators when your phone breaks?
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#25Earlier quoted context omitted.
This is a problem with Google authenticator, not with RFC 6238 TOTP in general. Plenty of authenticator apps support backing up your secrets.
Indeed. I’m trying to move from Google Authenticator to Authy for that reason - but the inability to backup/export from GA is a PITA... a cruel form of vendor lock-in.
It's worth also noting that Authy also has no official way to export your secrets, although there are workarounds: https://tij.me/blog/migrating-your-one-time-passwords-from-a...
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#26Earlier quoted context omitted.
First, it is a good idea to setup the authentication on multiple devices. This is not hard to do. Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.
It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.
Otherwise you’re going to lock a lot of people out of their accounts which is not acceptable.
Ultimately this typically ends up with a reset scheme that depends on phone numbers or email addresses which means the protection, which is as strong as the weakest link, is worthless.