Ask HN: If I get locked out of everything, please try to help me
41–50 of 350 posts
Re: Ask HN: If I get locked out of everything, please try to help me
#42Re: Ask HN: If I get locked out of everything, please try to help me
#43Earlier quoted context omitted.
I use authy (free) for 2FA TOTP and have it set up on my work laptop, my home laptop, and my phone. As long as least one of those is still good, I should still be able to get in. I honestly don't know what's going on behind the scenes to know if this is not as secure as it "should" be. But this was my reaction specifically to the non-SMS TOTP 2fa: Wait, if I lose my phone there's literally no way possible to get in?…
> work laptop, my home laptop, and my phone There’s a fire or gas explosion or earthquake or something, and you need to leave all those behind. What do you do? > Oh, everyone else is just hoping they never lose their phone? Really? I would be very, very surprised if that’s not what the vast majority of the population is doing. Many people have a phone as their _only_ computing device, and no printer, and don’t really…
I get screwed!
I guess the right answer is that I have the backup codes carefully preserved.... off site! In case of natural disaster. Every time I sign up for a new account, I print out the backup codes, and take them to an off-site secure storage location, which of course i have... somewhere.
There's no way 90%+ of internet users are doing that.
I'm not even going to pretend I have any chance of doing that.
Re: Ask HN: If I get locked out of everything, please try to help me
#44Earlier quoted context omitted.
I use authy (free) for 2FA TOTP and have it set up on my work laptop, my home laptop, and my phone. As long as least one of those is still good, I should still be able to get in. I honestly don't know what's going on behind the scenes to know if this is not as secure as it "should" be. But this was my reaction specifically to the non-SMS TOTP 2fa: Wait, if I lose my phone there's literally no way possible to get in?…
> As long as least one of those is still good, I should still be able to get in. Google has, in some cases, started requiring auth codes sent to specific devices , even if you're already using your own configured TOTP 2FA.
Re: Ask HN: If I get locked out of everything, please try to help me
#45If not, then 2fa just pisses people of with no security gain But I surely hope it is not!
Re: Ask HN: If I get locked out of everything, please try to help me
#46Earlier quoted context omitted.
We're talking about hackers getting access to users accounts, that's not a Google problem, that's an everyone problem.
Yes, I am well aware of that. I have been on Hacker News since 2009 under my Mz handle and I have a Certificate in GIS from UC-Riverside, the most respected GIS program in the world at the time that I attended (2002, IIRC). I don't try to crow about being some kind of tech genius because for the HN crowd I'm not. But I'm not poor due to being mentally retarded or something. I have an incurable medical condition as do…
Edit: thanks! Solved. I’ve deleted this part of the comment because I always feel very socially awkward and afraid I’ll make others feel awkward.
Re: Ask HN: If I get locked out of everything, please try to help me
#47Also Google is totally doing the right thing here. The slow down and wait is precisely the thing that protects you from identity theft if somebody waits until your phone is turned off, clones your SIM, and pretends to be in precisely this situation.
Hopefully in THAT case, you notice the "somebody is trying to get into your account" and say "no, this is a hack attempt".
Good luck.
Re: Ask HN: If I get locked out of everything, please try to help me
#48Re: Ask HN: If I get locked out of everything, please try to help me
#49Earlier quoted context omitted.
>This is why I will not use 2FA except on services where it is absolutely required Software 2FA just computes a number based on a secret string. You treat the latter the same way you take care of your passwords. That's why it's best to handle them with your password manager. 2FA over SMS is even less of an issue (except maybe with a broken eSIM chip). Physical methods are a problem, so you have to spend money for a b…
I could store the secret in my password manager if I paid for Bitwarden Premium (and at $10 a year, price isn't really the issue), but then what is even the point? If my password and my secret are stored in the same place then that's really just a single factor, so I'm making the login process more annoying for no reason.
Of course the threat model is kinda skewed because this case is more applicable when one's reusing passwords or using weak passwords, which shouldn't be happening if you're using a password manager.
Maybe a more relevant threat is password gets compromised from a MITM attack, in which case they still don't have access to your TOTP
Re: Ask HN: If I get locked out of everything, please try to help me
#50It feels like it might.
This isn’t counting the productivity that’s lost to actually using the TFA system successfully, which is probably measurable on a population level.