Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
Tell HN: It is impossible to disable Google 2FA using backup codes
11–20 of 352 posts
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#12And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#13I hate current popular implementations 2FA and similar IT fads for this exact reason. They are inherently insecure, and any security professional who pushes them without serious thought through all the failure modes should be blacklisted from the industry.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#14And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#15And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
Good idea! That had never occurred to me before this incident.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#16This. Support systems in the world post computers eating everything is basically HN posts.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#17And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
If an attacker steals at TOTP, its only good for (I think) less than a minute. If they steal the seed, its good forever.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#18And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#19And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
I would love to save the QR codes, but Google bans screenshots in the Authenticator app.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#20And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
Doesn't keeping the seed remove the whole point of one time passwords? If an attacker steals at TOTP, its only good for (I think) less than a minute. If they steal the seed, its good forever.
which isn't really destroyed by having a printout of what you entered onto your phone somewhere secure
(now if you store both in your password manager: that completely defeats the point)