Live data from Hacker News

Ask HN: If I get locked out of everything, please try to help me

news.ycombinator.com

41–50 of 350 posts

Re: Ask HN: If I get locked out of everything, please try to help me

#41
Google is extremely frustrating in this regard. I keep my TOTP in 1Password so that I can have it on multiple devices. When I tried to login in on a new device, I used the TOTP code. Google then wanted me to click approve in the YouTube app on an old device that was no longer functioning. Eventually I was able to get it to work by re-logging in a few times (I guess it gave up) but why the fuck do I even have 2FA if Google isn’t going to fucking respect it? Infuriating.

Re: Ask HN: If I get locked out of everything, please try to help me

#43
post #39

Earlier quoted context omitted.

I use authy (free) for 2FA TOTP and have it set up on my work laptop, my home laptop, and my phone. As long as least one of those is still good, I should still be able to get in. I honestly don't know what's going on behind the scenes to know if this is not as secure as it "should" be. But this was my reaction specifically to the non-SMS TOTP 2fa: Wait, if I lose my phone there's literally no way possible to get in?…

> work laptop, my home laptop, and my phone There’s a fire or gas explosion or earthquake or something, and you need to leave all those behind. What do you do? > Oh, everyone else is just hoping they never lose their phone? Really? I would be very, very surprised if that’s not what the vast majority of the population is doing. Many people have a phone as their _only_ computing device, and no printer, and don’t really…

> What do you do?

I get screwed!

I guess the right answer is that I have the backup codes carefully preserved.... off site! In case of natural disaster. Every time I sign up for a new account, I print out the backup codes, and take them to an off-site secure storage location, which of course i have... somewhere.

There's no way 90%+ of internet users are doing that.

I'm not even going to pretend I have any chance of doing that.

Re: Ask HN: If I get locked out of everything, please try to help me

#44

Earlier quoted context omitted.

I use authy (free) for 2FA TOTP and have it set up on my work laptop, my home laptop, and my phone. As long as least one of those is still good, I should still be able to get in. I honestly don't know what's going on behind the scenes to know if this is not as secure as it "should" be. But this was my reaction specifically to the non-SMS TOTP 2fa: Wait, if I lose my phone there's literally no way possible to get in?…

> As long as least one of those is still good, I should still be able to get in. Google has, in some cases, started requiring auth codes sent to specific devices , even if you're already using your own configured TOTP 2FA.

They expect that none of your devices will ever die? This makes no sense.

Re: Ask HN: If I get locked out of everything, please try to help me

#46

Earlier quoted context omitted.

We're talking about hackers getting access to users accounts, that's not a Google problem, that's an everyone problem.

Yes, I am well aware of that. I have been on Hacker News since 2009 under my Mz handle and I have a Certificate in GIS from UC-Riverside, the most respected GIS program in the world at the time that I attended (2002, IIRC). I don't try to crow about being some kind of tech genius because for the HN crowd I'm not. But I'm not poor due to being mentally retarded or something. I have an incurable medical condition as do…

Perfectly average geographers on HN represent! I feel like seeing another GISer in the tech world is like seeing someone from your country while on vacation. You’ve just got to say hi because it feels so rare.

Edit: thanks! Solved. I’ve deleted this part of the comment because I always feel very socially awkward and afraid I’ll make others feel awkward.

Re: Ask HN: If I get locked out of everything, please try to help me

#47
This is highly frustrating and it sucks.

Also Google is totally doing the right thing here. The slow down and wait is precisely the thing that protects you from identity theft if somebody waits until your phone is turned off, clones your SIM, and pretends to be in precisely this situation.

Hopefully in THAT case, you notice the "somebody is trying to get into your account" and say "no, this is a hack attempt".

Good luck.

Re: Ask HN: If I get locked out of everything, please try to help me

#49

Earlier quoted context omitted.

>This is why I will not use 2FA except on services where it is absolutely required Software 2FA just computes a number based on a secret string. You treat the latter the same way you take care of your passwords. That's why it's best to handle them with your password manager. 2FA over SMS is even less of an issue (except maybe with a broken eSIM chip). Physical methods are a problem, so you have to spend money for a b…

I could store the secret in my password manager if I paid for Bitwarden Premium (and at $10 a year, price isn't really the issue), but then what is even the point? If my password and my secret are stored in the same place then that's really just a single factor, so I'm making the login process more annoying for no reason.

I'd see it as a single point of failure, but not necessarily a single factor. If the password is compromised due to a problem on the application side, they still can't get in to your account without the TOTP code.

Of course the threat model is kinda skewed because this case is more applicable when one's reusing passwords or using weak passwords, which shouldn't be happening if you're using a password manager.

Maybe a more relevant threat is password gets compromised from a MITM attack, in which case they still don't have access to your TOTP

Re: Ask HN: If I get locked out of everything, please try to help me

#50
I have long wondered if two factor authentication actually causes more economic harm than it solves - it just doesn’t cause that harm to be noticeably all in one place (the harm is spread to millions of users who will lose access at some point during their lives rather than concentrated on the company that implements TFA dealing with fraud).

It feels like it might.

This isn’t counting the productivity that’s lost to actually using the TFA system successfully, which is probably measurable on a population level.

Post reply on HN