Live data from Hacker News

Ask HN: If I get locked out of everything, please try to help me

news.ycombinator.com

251–260 of 350 posts

Re: Ask HN: If I get locked out of everything, please try to help me

#251
I really don't have anything to say to the OP, but I wonder(in a similar situation) if with the recent push towards e-sim, will SMS based 2FA become more problematic?

If a phone with an e-sim dies, and you need some kind of OTP, I wonder how you'll receive it. You can't exactly 'transplant' the SIM into another phone.

Re: Ask HN: If I get locked out of everything, please try to help me

#252

Earlier quoted context omitted.

They expect that none of your devices will ever die? This makes no sense.

It makes plenty of sense to Google: engineer for the 98% use case and the remaining 2% should just go away and stop wasting their time.

Many things are designed by roughly the same kind of people in roughly the same area. They are blind to a lot of use cases. Besides, it's a government's mandate to cover edge cases. Businesses only do it when compelled.

Re: Ask HN: If I get locked out of everything, please try to help me

#253

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

>This is why I will not use 2FA except on services where it is absolutely required Software 2FA just computes a number based on a secret string. You treat the latter the same way you take care of your passwords. That's why it's best to handle them with your password manager. 2FA over SMS is even less of an issue (except maybe with a broken eSIM chip). Physical methods are a problem, so you have to spend money for a b…

SMS is a much bigger issue if you are in another country, temporarily lose access to your phone, or work in a building without phone reception. It's prone to SIM swaps and could be intercepted by other apps on your phone. It requires having a fixed, serviced phone number, which people don't always have: children, homeless people and recent immigrants might struggle with that.

All of these scenarios happened to me, and I'm a fairly normal person.

Re: Ask HN: If I get locked out of everything, please try to help me

#254

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

I use authy (free) for 2FA TOTP and have it set up on my work laptop, my home laptop, and my phone. As long as least one of those is still good, I should still be able to get in. I honestly don't know what's going on behind the scenes to know if this is not as secure as it "should" be. But this was my reaction specifically to the non-SMS TOTP 2fa: Wait, if I lose my phone there's literally no way possible to get in?…

Password managers usually have a comment field where you can store the backup codes.

Re: Ask HN: If I get locked out of everything, please try to help me

#255

I really don't have anything to say to the OP, but I wonder(in a similar situation) if with the recent push towards e-sim, will SMS based 2FA become more problematic? If a phone with an e-sim dies, and you need some kind of OTP, I wonder how you'll receive it. You can't exactly 'transplant' the SIM into another phone.

SMS 2FA is just a terrible idea. I advise anyone to use something like TOTP but also to store the TOTP seed as well as recovery codes in e.g. a KeePass database.

You may use a different database than the one with the rest of your passwords. Sync these databases with something like Syncthing, which is completely controlled by you, can do untrusted encrypted nodes and can not only sync but also take occasional backups for you.

Also don't forget to put the master password of your KeePass databases into someone elses database. Someone you trust in person, e.g. a family member.

It may be a quite complicated setup, but once its set up, it works and not much effort to maintain it is required. If you get a new device simply add a new syncthing node.

Re: Ask HN: If I get locked out of everything, please try to help me

#256

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

Can say for sure if you have any of FAANG accounts next time you get a new laptop or even reinstall - you will get locked out.

Get a 2FA using QR code or U2F key (not SMS or phone based).

Re: Ask HN: If I get locked out of everything, please try to help me

#257

Earlier quoted context omitted.

I have uninstalled Google applications from most of the mobile devices that I use for this exact reason.

Google will send you codes to devices that don’t even have the app installed. Ask me how I know.

use AndOTP with QR code from fdroid. Go to account settings in desktop browser and remove the phone as 2FA. It will not ask any code to device.

Re: Ask HN: If I get locked out of everything, please try to help me

#258

I wanted to point out a very serious problem related to this post: Google will no longer simply accept totp as a verification but insists on sending you a notification to one of your devices. Now I can't just use KeepassXC to get into Google anymore, I have to use my phone. The problem that the OP points out provides very real and poignant evidence that this is not only annoying but dangerous. What is it that compani…

You need to remove your device as a 2FA device. then you can TOTP code as only entry point.

Re: Ask HN: If I get locked out of everything, please try to help me

#259

Earlier quoted context omitted.

We're talking about hackers getting access to users accounts, that's not a Google problem, that's an everyone problem.

Yes, I am well aware of that. I have been on Hacker News since 2009 under my Mz handle and I have a Certificate in GIS from UC-Riverside, the most respected GIS program in the world at the time that I attended (2002, IIRC). I don't try to crow about being some kind of tech genius because for the HN crowd I'm not. But I'm not poor due to being mentally retarded or something. I have an incurable medical condition as do…

Sorry for the pain

If you have been in hn so long you do know the numerous times people have lost accounts by not having backup to 2FA. TOTP is the only option.

Re: Ask HN: If I get locked out of everything, please try to help me

#260
post #111

Earlier quoted context omitted.

The trick isn't to disable 2FA. It's to add a bunch of 2FA methods that don't rely on your cell phone: authenticator app, yubi keys, backup codes.

This is terrible advice. Please don't ever rely on authenticator apps. Try changing your phone, resetting your phone or losing your phone and watch yourself get locked out of your accounts with absolutely no recourse.

Wait. make a photo of QR code and send it to your spouse. Put it on her Google photos or facebook (make it private). Very unlikely both of you lose phones on the same day.
Post reply on HN