Live data from Hacker News

Tell HN: It is impossible to disable Google 2FA using backup codes

news.ycombinator.com

11–20 of 352 posts

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#11
And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still.

Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#12

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

Good idea! That had never occurred to me before this incident.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#13

I hate current popular implementations 2FA and similar IT fads for this exact reason. They are inherently insecure, and any security professional who pushes them without serious thought through all the failure modes should be blacklisted from the industry.

Competently administering 2FA essentially requires human intervention to handle the "I lost all my credentials" case because it will happen with probability 1 eventually. Workplaces can do this because you can call IT and have an already established identity based in the real world.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#14

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

I would love to save the QR codes, but Google bans screenshots in the Authenticator app.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#15

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

Good idea! That had never occurred to me before this incident.

You have to take a photo of the screen on another phone, Google disallows you from screenshotting them.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#17

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

Doesn't keeping the seed remove the whole point of one time passwords?

If an attacker steals at TOTP, its only good for (I think) less than a minute. If they steal the seed, its good forever.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#18

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

In Bitwarden you can just store the key itself and it'll generate the codes for you, right next to your password, so convenient!

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#19

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

I would love to save the QR codes, but Google bans screenshots in the Authenticator app.

Other apps will reveal the underlying seed string. No need to deal with QR codes after scanning them once.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#20

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

Doesn't keeping the seed remove the whole point of one time passwords? If an attacker steals at TOTP, its only good for (I think) less than a minute. If they steal the seed, its good forever.

the point is to have a second factor

which isn't really destroyed by having a printout of what you entered onto your phone somewhere secure

(now if you store both in your password manager: that completely defeats the point)

Post reply on HN