Live data from Hacker News

Ask HN: How do you start over with 2FA after losing your phone?

news.ycombinator.com

41–50 of 112 posts

Re: Ask HN: How do you start over with 2FA after losing your phone?

#41
post #39

Use your backup codes that you've downloaded and safe-kept somewhere (you did this right?). If not, I'm afraid you're out of luck. There are two possible outcomes from contacting support for a service, asking to regain control over a 2FA-protected account, both which sucks, but on different levels. 1. You write them, proving who you are, and they tell you to get lost unless you have the 2FA proper codes, or backup co…

I so wish u2f/yubikey was supported on all websites :-(

I use the yubikey authenticator app for the ones that don't. The secrets are saved on the key and you can password protect it... and as with all keys back it up to your spare.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#42
post #11

I've never trusted a single device for two factor authentification, My solution, trust in 1Password and it's encryption, I have access to my 2fa anywhere I need but it a computer, phone, tablette. Soon it will be passkeys and they'll be safe in the 1Password vault, no worrying about losing the device w/ the keys again.

So ... your solution is no tfa?

Putting second factor material in password managers is terrible advice. For reasons unknown to me, it might be the right solution for you. But in general, it defeats the two factor authentication purpose if you reduce the factors again to knowledge alone.

The whole point of tfa is, that the second factor is something you possess and not something you know (which is the first factor).

Re: Ask HN: How do you start over with 2FA after losing your phone?

#43

You can back up your 2FA codes to another phone, at least Google Authenticator lets you do this. An old phone is the easiest, most convenient way to do this since it has a camera that you can use to scan the code on your main phone. If you don't have the backup codes or the one-time codes, you're going to have a problem and you'll need to contact the services to somehow let you in or take off 2FA. Depending on what t…

BTW this process is broken with small display. I have a very tiny Android phone and to backup the codes I need to scan an QR code on this small display, which isn't working out. The resolution is too small. And there is no other way to backup Google Authenticator I am aware of. So be careful in smaller display, you probably cannot backup Goggle Authenticator.

You may have tried this already, but the QR code gets bigger the more entries you export - have you tried selecting them one at a time?

Re: Ask HN: How do you start over with 2FA after losing your phone?

#44
I use KeepassXC password manager[1], it keeps my TOTP information and makes it available to use on all my devices. It syncs between my devices using Dropbox. Kepassium[2] makes it available on iOS, and Keepass2Android[3] makes it available on Android. It also manages my SSH keys and adds them to the ssh-agent, even on Windows. It houses a backup of my GPG keys. I even found that it can manage my credentials for use in scripts and git using git-credential-keepassxc[4].

Similar functionality can be had from 1Password[5], if you're into the more fancy experience. As a bonus this approach makes it very easy to store all those backup codes that totp services often give you. Won't help your current predicament but will prevent it from happening again :)

1: https://keepassxc.org/

2: https://keepassium.com/

3: https://github.com/PhilippC/keepass2android

4: https://github.com/Frederick888/git-credential-keepassxc

5: https://1password.com/

Re: Ask HN: How do you start over with 2FA after losing your phone?

#45
post #20

If you have a backup, try to restore it on your new iphone. In the vast Google Authenticator didn’t restore, but I read it may now? FWIW, this is the reason I use Authy, it works nicely with backup/restore. Beware that Authy has a cloud backup/multi device function that I personally keep off. Another option would be 1password, though I’d personally won’t mix passwords and 2fa codes in the same app. Assuming the worst…

+1 for Authy, though I keep the backups and multi-device turned on for convenience.

My old phone died and I had no way of getting into some of my 2FA secured accounts a while back and it was a wakeup call that eventually led to using Authy.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#46
post #33

Earlier quoted context omitted.

What? Where the 2FA codes come from isn't relevant, as long as the device (laptop, phone, desktop, hardware) is protected in some way or another (like password). Backup codes come from the service which is 2FA protected anyways, not from the 2FA authenticator itself. Edit: oh, reading your message again, are you referring to SMS-based 2FA? I assumed TOTP 2FA in this submission. If you mean SMS-based 2FA, then yeah I…

Nobody has a secure password on their phone, so your requirement fails. There is no way to get a secure password on a phone as one of the requirements of a phone is quick access, and no fast password is secure. (maybe finger prints, but I have found them unreliable and so I quit using them) If your phone based code system is also available on other accounts, and you can access those other accounts without the phone t…

> Nobody has a secure password on their phone, so your requirement fails.

Well, you could if you want to. That you don't want to, is a failure on your part, not on "everyone"'s part, since most phones do offer you the feature of setting a sufficiently secure password.

> However many people only have a phone, and no other computer (or at least not a computer they use often enough that we can trust the 2fa isn't expired).

You don't need a second device in order to backup your codes. By leveraging "cryptographic splitting" you can divide a secret into N parts and share them with friends and family, and if you need to regain access, ask them each for their part back and then you can recover from there. Now I guess that's kind of advanced so most people won't/can't do that, but it is possible at least. You could try something like https://iancoleman.io/shamir/ if you're curious about the process, I've done this myself for some things.

Easier solution is to create a encrypted archive with your backups, and upload to various cloud services. As long as the encryption scheme is secure, you'll be safe.

> The 2fa I've seen mostly has a SMS based fallback, and thus is no more secure than SMS.

I'm using TOTP 2FA for 100% of every service I use and that offers it. I think only one requires SMS-based fallback, the rest are optional so obviously I'm not using that.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#47

Earlier quoted context omitted.

BTW this process is broken with small display. I have a very tiny Android phone and to backup the codes I need to scan an QR code on this small display, which isn't working out. The resolution is too small. And there is no other way to backup Google Authenticator I am aware of. So be careful in smaller display, you probably cannot backup Goggle Authenticator.

You may have tried this already, but the QR code gets bigger the more entries you export - have you tried selecting them one at a time?

Ah, did not knew that, just check it out. Thanks for the hint. Uh, if I select only one entry the QR code gets smaller in itself. So basically same problem still. facepalm :-D

Re: Ask HN: How do you start over with 2FA after losing your phone?

#48

Use your backup codes that you've downloaded and safe-kept somewhere (you did this right?). If not, I'm afraid you're out of luck. There are two possible outcomes from contacting support for a service, asking to regain control over a 2FA-protected account, both which sucks, but on different levels. 1. You write them, proving who you are, and they tell you to get lost unless you have the 2FA proper codes, or backup co…

> Use your backup codes that you've downloaded and safe-kept somewhere

... or re-initialize 2FAs from their original seeds, which are typically hidden under a "set up manually" option during the enrollment process.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#49
Always, always create a backup. Or three.

I carry a backup with me strapped to my wrist. It is a cheap digital watch with a strap modified to securely hold a microSD card with all my really important, must have data ---encrypted with Bitlocker. This data is as safe as I am.

I leave a copy of this card in a fireproof safe at home. A trusted family member has the combination. A friend has the Bitlocker decrypt key. My will brings these two people together to obtain access to the data in case of my demise.

Twice a month, I swap the two cards and update the one I will carry with only the changed info using a xcopy batch script.

My Android phone also has my 2FA keys using FreeOTP+ with an access code and backup capability.

I keep the backup from FreeOTP+ on the memory cards along with a little Windows CLI utility of my own making that can read this backup and generate 2FA codes as needed.

I'm fairly confident I won't ever be totally locked out of my accounts.

If you are locked out without a backup, your only realistic option is to contact each service provider and follow their instructions.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#50
post #11

I've never trusted a single device for two factor authentification, My solution, trust in 1Password and it's encryption, I have access to my 2fa anywhere I need but it a computer, phone, tablette. Soon it will be passkeys and they'll be safe in the 1Password vault, no worrying about losing the device w/ the keys again.

So ... your solution is no tfa? Putting second factor material in password managers is terrible advice. For reasons unknown to me, it might be the right solution for you. But in general, it defeats the two factor authentication purpose if you reduce the factors again to knowledge alone. The whole point of tfa is, that the second factor is something you possess and not something you know (which is the first factor).

There are multiple attack vectors that 2-factor helps with, and storing your 2-factor alongside your password does still help in some, just not all.

For the more common attacks I expect to encounter, namely a single password being leaked, a password manager is still based on something I "possess" (to an extent) - the decrypted password vault. It's separate from the single password that's likely to have been compromised in the most common scenario.

Of course, if my whole vault is compromised, then yes, storing my 2-factor in there made my life worse than the alternative. I just don't see that as anywhere near as likely a scenario as an individual account being compromised. Having 2-factor enabled in a less secure method is still better than not having 2-factor enabled at all.

Basically, there's nuance to this, it's not the extreme you present - a more in-depth comment on this: https://security.stackexchange.com/questions/150448/is-it-se...

Post reply on HN