Live data from Hacker News

Ask HN: If I get locked out of everything, please try to help me

news.ycombinator.com

261–270 of 350 posts

Re: Ask HN: If I get locked out of everything, please try to help me

#261
This is a bad situation an i really cannot help the OP, but wanted to ask a question to the wider audience:

So... perhaps i live in my german "island of the blissfull" but why rely on google in the first place? There are tons of other options around for email (many of them free or dirt cheap [sdf.org as an example]). So... why giving big-tech the opportunity to ruin ones life in the first place?

Re: Ask HN: If I get locked out of everything, please try to help me

#262

Earlier quoted context omitted.

> Please do not treat them this way. They do not grant access to your account. Can you expand on that? Once I have such code, what’s stopping me from “stealing” the account?

You need the password too. That's what makes it two factor.

If one of the factors is widely known, it's effectively not two-factor anymore.

Re: Ask HN: If I get locked out of everything, please try to help me

#264

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

I love 2FA, but only the TOTP based ones. No codes on my phone, emails or already authorized devices please

Github is extremely insistant on sending me a 2FA push notification on the mobile app every time I want to connect to the desktop. I find it very annoying because I configured TOTP based 2FA and do not want to rely on any proprietary 2FA mechanism. I just can't seem to make it understand that I want to use my TOTP tokens and only that.

Re: Ask HN: If I get locked out of everything, please try to help me

#265

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

It's simple. If you assume the real possibility of losing your digital account, then act like you'll lose it tomorrow. Adjust your life and move on. I don't care about digital accounts. I switch my main mail and phone every few years just for the sake of it. I avoid buying stuff bound to digital account. My accounts are disposable and have zero value other than nostalgic one. I didn't lose a single account yet. I hav…

> But of course that's not reliable. Registrar might just go bankrupt

If you registered a gTLD, you're theoretically safe from registrar bankruptcy, or even from a registrar losing all their data for whatever reason. Per the ICANN agreement, the registrars have to send a copy of their database to a third party escrow agent regularly (where I worked before we sent a differential backup everyday and a full backup once a week). This way, if the registrar cannot assume its role anymore, another registrar takes over.

Note that this is not true for ccTLDs (ie. every 2 character TLD). That's a reason you should prefer gTLDs if you want to prevent a worst case scenario. I usually recommend a .com or .net because Verisign is, in my opinion, the most reliable registry in the world. If you stick with .com/.net, you're safe from any registrar failure, and there's not a single chance that anything happens to the registry.

ccTLDs might have an emergency plan but it will depend on the registry. So if you really want a ccTLD:

- get familiar with the registry and its rules

- do NOT get the ccTLD of a country other than your own. Eligibility rules can change, so you could lose your domain if the registry decides that they now want to only sell to residents. British people lose eligibility over .eu for example, not because a change in eligibility rules, but because of a change in their own status.

- do NOT get the ccTLD of a small country, unless the registry delegates the technical stuff to a reliable registry backend. Small countries have crappy infrastructures, so DNS resolution could get unreliable. This famously happened to Notion.so (so -> Somalia) a little while ago.

Re: Ask HN: If I get locked out of everything, please try to help me

#266
post #264

Earlier quoted context omitted.

I love 2FA, but only the TOTP based ones. No codes on my phone, emails or already authorized devices please

Github is extremely insistant on sending me a 2FA push notification on the mobile app every time I want to connect to the desktop. I find it very annoying because I configured TOTP based 2FA and do not want to rely on any proprietary 2FA mechanism. I just can't seem to make it understand that I want to use my TOTP tokens and only that.

remove mobile app as a 2FA. Use U2F/FIDO.

Re: Ask HN: If I get locked out of everything, please try to help me

#267

If you're in LA and need a computer to use or an environment with wifi and power and what not to trouble shoot this, you're welcome to use my apartment. I have a spare ATT phone if you need something to act as a intermediate device (if your son wants their phone back :p). If I worked in tech I'd offer you access to a solution but this is all I've got. I hope this problem doesn't last long for you.

> If I worked in tech I'd offer you access to a solution but this is all I've got. I hope this problem doesn't last long for you.

Sadly, even many google employees's spouses lost account with no recourse.

Lets say you are employed in US embassy in Kabul - you just think you could issue visas out of your sympathy. (i.e) FAANG has become as large as govt.

Re: Ask HN: If I get locked out of everything, please try to help me

#268

There was a post a while back around poor and homeless people encountering exactly this problem on a regular basis. Lots of people in the comments were incredibly dismissive and sometimes actively malign about it. Edit: One suggestion from me would be to try and start the dead phone connected to power but with the battery physically removed (assuming it's removable). That might bypass whatever issue it's having and l…

> There was a post a while back around poor and homeless people encountering exactly this problem on a regular basis. Lots of people in the comments were incredibly dismissive and sometimes actively malign about it. Even worse than that, they're often connecting from public IPs that are "suspicious" which causes automated systems to treat them more harshly. In Canada it's gotten to the point where you need an interne…

In the UK, less and less places accept cash.

I experienced the only slightly inconvenient of this when I was replacing my bank card, even going into a Pret, I was unlucky enough to go into one randomly that didn't accept cash.

But for people that don't have bank cards, or can't charge their phones this is a real problem.

Re: Ask HN: If I get locked out of everything, please try to help me

#269
1. why don't you have any recovery codes? This topic comes up bi-monthly... (To everyone else reading this, no, you're not immune, go save the backup codes)

2. If it says it's sending a code to a device, that's not SMS, that's Google's own side-channel for trusted, authed devices.

In theory, you should have backup codes and/or the ability to text a number you've confirmed. Maybe you're not seeing the link for "Try Another Way/Method" ?

> If anyone has contacts at google and can tell them, yea, verily, Doreen Michele Traylor is a real person who is real poor and we all know her and please let her keep her phone number and her (my full name) google account and get me out of this fucking nightmare, that would be coolios.

Man, I just don't know what to say here. I really don't want to be mean, but I _really_ don't want someone compromising my HN account and then going "oh yeah, plz remove 2FA from [my Google] account, it's really me for sure". :/ :/

Re: Ask HN: If I get locked out of everything, please try to help me

#270

Earlier quoted context omitted.

I use authy (free) for 2FA TOTP and have it set up on my work laptop, my home laptop, and my phone. As long as least one of those is still good, I should still be able to get in. I honestly don't know what's going on behind the scenes to know if this is not as secure as it "should" be. But this was my reaction specifically to the non-SMS TOTP 2fa: Wait, if I lose my phone there's literally no way possible to get in?…

> As long as least one of those is still good, I should still be able to get in. Google has, in some cases, started requiring auth codes sent to specific devices , even if you're already using your own configured TOTP 2FA.

I've still yet to see a single bit of proof of this outside of claims from people who couldn't bother to do the things you're supposed to do when setting up 2FA. I remain skeptical.

All these claims and not a single screenshot of this scenario. Meanwhile I've been in 4 countries in 8 weeks and Google hasn't bothered me once beyond the normal "tap my yubikey on my keychain".

Post reply on HN