Live data from Hacker News

Ask HN: How do you start over with 2FA after losing your phone?

news.ycombinator.com

71–80 of 112 posts

Re: Ask HN: How do you start over with 2FA after losing your phone?

#71
post #33

Earlier quoted context omitted.

What? Where the 2FA codes come from isn't relevant, as long as the device (laptop, phone, desktop, hardware) is protected in some way or another (like password). Backup codes come from the service which is 2FA protected anyways, not from the 2FA authenticator itself. Edit: oh, reading your message again, are you referring to SMS-based 2FA? I assumed TOTP 2FA in this submission. If you mean SMS-based 2FA, then yeah I…

Nobody has a secure password on their phone, so your requirement fails. There is no way to get a secure password on a phone as one of the requirements of a phone is quick access, and no fast password is secure. (maybe finger prints, but I have found them unreliable and so I quit using them) If your phone based code system is also available on other accounts, and you can access those other accounts without the phone t…

> Nobody has a secure password on their phone, so your requirement fails. There is no way to get a secure password on a phone as one of the requirements of a phone is quick access, and no fast password is secure. (maybe finger prints, but I have found them unreliable and so I quit using them)

I think you’re overextrapolating from your experience. I‘ve used Face ID on my phone for 5-6 years now, and the fingerprint sensors on my recent devices have been very reliable.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#72

Earlier quoted context omitted.

Why did you decide to lie in your complaint?

Yeah, this is disturbing. He's admitting he used social engineering to get back into his own locked account and he's happy that it worked. Assuming he did this over email / web the "proof" he sent them was probably a photo of driver's license which really doesn't prove ownership of identity when your account was just hacked. We really need a third party service that allows you to walk up, have some DNA taken, verify…

This isn’t secure against evil twins.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#73
You know the big black bold huge warning you clicked through to active 2fa? The one that told you you really really needed to save backup codes? The one that said you will lose your account without said backup codes?

You do have those backup codes, right?

Backups, password managers, now 2fa backups, all things that people just cannot seem to care about until it's too late

Re: Ask HN: How do you start over with 2FA after losing your phone?

#75
post #58

Earlier quoted context omitted.

> Nobody has a secure password on their phone, so your requirement fails. > maybe finger prints, but I have found them unreliable and so I quit using them You mean that you specifically do not have a secure password on your phone because you chose not to. The rest of us use finger print sensors or facial recognition to make our devices as secure as can be. Your argument applies only to you and a handful of people. Th…

Biometric phone security is only secure until a judge or police officer compels you to unlock your phone; and legally you must comply, because your face or finger aren't speech. However, if you use a passphrase, (at least in the US and other countries with string freedom of speech laws) you can't be legally compelled to unlock the phone, as that would impinge on freedom of speech. I never use biometrics to unlock my…

Android: long press power, tap lockdown. Your entire point is now just inaccurate. I do this when going through security checkpoints, if I were to get pulled over, and Android auto trihgers it under abnormal conditions upon which I have a decently long device-specific password.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#76

Earlier quoted context omitted.

Why did you decide to lie in your complaint?

Yeah, this is disturbing. He's admitting he used social engineering to get back into his own locked account and he's happy that it worked. Assuming he did this over email / web the "proof" he sent them was probably a photo of driver's license which really doesn't prove ownership of identity when your account was just hacked. We really need a third party service that allows you to walk up, have some DNA taken, verify…

Pretty much every single one of these threads is about half full of people demanding more, larger foot-guns with which to shoot themselves because they just can't be bothered (just assure you'll hear when they're eventually locked out, etc).

Re: Ask HN: How do you start over with 2FA after losing your phone?

#78
post #20

If you have a backup, try to restore it on your new iphone. In the vast Google Authenticator didn’t restore, but I read it may now? FWIW, this is the reason I use Authy, it works nicely with backup/restore. Beware that Authy has a cloud backup/multi device function that I personally keep off. Another option would be 1password, though I’d personally won’t mix passwords and 2fa codes in the same app. Assuming the worst…

+1 for Authy, though I keep the backups and multi-device turned on for convenience. My old phone died and I had no way of getting into some of my 2FA secured accounts a while back and it was a wakeup call that eventually led to using Authy.

Our org is using a mix of Google Authenticator and Authy, but I am currently trialing https://2fas.com/ which is an opensource application that work with iOS backups.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#79

Earlier quoted context omitted.

You may have tried this already, but the QR code gets bigger the more entries you export - have you tried selecting them one at a time?

Ah, did not knew that, just check it out. Thanks for the hint. Uh, if I select only one entry the QR code gets smaller in itself. So basically same problem still. facepalm :-D

> if I select only one entry the QR code gets smaller in itself

Does it block you from taking a screenshot? Maybe you could screenshot it and then zoom in the gallery app.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#80
post #41
post #39

Earlier quoted context omitted.

I so wish u2f/yubikey was supported on all websites :-(

I use the yubikey authenticator app for the ones that don't. The secrets are saved on the key and you can password protect it... and as with all keys back it up to your spare.

When you're traveling to Costa Rica, where do you keep your spare? Do you stay locked out until you get home? What if you're a nomad and you don't have a 'home'?
Post reply on HN