Live data from Hacker News

Tell HN: It is impossible to disable Google 2FA using backup codes

news.ycombinator.com

111–120 of 352 posts

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#112
post #48

To avoid a situation like this, I keep backup screenshots of the 2FA QR codes stored off-line on an encrypted USB drive.

No need for screenshots even, right click and Save Image almost always works. I save them all and encrypt them in a separate archive with a different password. No, your probably shouldn’t save them to your password vault (unless you know what you’re doing).

You can also save the TOTP hash instead of the QR code (which basically just contains that hash)

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#113

Earlier quoted context omitted.

I have 2FA backup codes! They let me log into my account! But using only backup codes, I cannot remove the lost 2FA. So now I have 8 consumable backup codes and after that I will not be able to access the account. To remove the lost 2FA, I need a fresh 2FA code. No alternatives given.

The solution (which is too late to help you with now) is to take a photo of the QR code that is first showed to you when you originally set up 2FA. Keep that safe somewhere and you can always go back. For anyone who is freaked out by this and currently still has access to their google Authenticator app, I suggest exporting all your codes to a big QR code in the app and keep that safe (maybe print it out).

Fully understand why some people wouldn't want to do this given the LastPass hack, but some authenticators like Authy let you store a master backup password for all your codes.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#114

Earlier quoted context omitted.

I have 2FA backup codes! They let me log into my account! But using only backup codes, I cannot remove the lost 2FA. So now I have 8 consumable backup codes and after that I will not be able to access the account. To remove the lost 2FA, I need a fresh 2FA code. No alternatives given.

The solution (which is too late to help you with now) is to take a photo of the QR code that is first showed to you when you originally set up 2FA. Keep that safe somewhere and you can always go back. For anyone who is freaked out by this and currently still has access to their google Authenticator app, I suggest exporting all your codes to a big QR code in the app and keep that safe (maybe print it out).

If you use 1Password, the initial code (just a string) is always available in the app. You can use it to move TOTP to another app, if you wish.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#115
I completely believe you. I got in a similar situation in 2020. In that case it was a change of password of the main account that went wrong. How?

Don't know, I have a password manager that captured the password I inputted and it was exactly as it should inputted. But when I put it in google it told me that it was incorrect.

When I commented to people, everyone told me that they could change their password doing this and that, but... I wasn't. Looks like there are different security levels based on arbitrary rules and what an user could do, I was unable to do it.

I only had the account logged in in my phone, and every day I kept restoring the account, every day to be unsuccesfully.

One day, after 5 weeks from the day it happened, doing exactly the same than the previous days, one of the recovery attemps worked out, and was able to reset my password.

It completely put me off using google services, but God, it is hard to abandon your first mail services, I got way too many things hooked up with them.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#116

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

I would love to save the QR codes, but Google bans screenshots in the Authenticator app.

If you're on Android, get Aegis. It's better anyway and you can export backups.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#117

Earlier quoted context omitted.

The solution (which is too late to help you with now) is to take a photo of the QR code that is first showed to you when you originally set up 2FA. Keep that safe somewhere and you can always go back. For anyone who is freaked out by this and currently still has access to their google Authenticator app, I suggest exporting all your codes to a big QR code in the app and keep that safe (maybe print it out).

You can do this, or you can write down the secret (Click to get the text), and use oathtool to generate codes rather than google's auth. I keep all my 2fa secrets in pass for this reason. Never lose access again!

But be careful. If you access the passwords and 2fa secrets via the same credentials you are back to one factor authentication if secret + pass store ever get compromised.

Imho it's a different story if you use a separate gpg-key/secret to access the 2fa secrets (which should also only happen in emergency cases).

This can easily be done with pass.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#118
just be happy you didn't get caught up in the g+ debacle. i did exactly what they told me to do to keep from using a real name across their services and they fucked me 10 ways to sunday for doing so.

brand account worked great up until ~2013, then they changed something and my settings are all greyed out. can't update phone numbers, can't view mature content, etc. all i can do is collect adsense while the account lasts.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#119

Earlier quoted context omitted.

I would love to save the QR codes, but Google bans screenshots in the Authenticator app.

Not in iOS, apparently. I recently printed out my QR codes by screenshotting Authenticator's export screen on an iPhone. I just tested a moment ago and it still works.

An app can deny access to take screenshots in Android. In iOS, there's no way to deny screenshots, but apps can be notified if a screenshot is taken. What the app then does with that information... you may not know ahead of time. Be careful out there!

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#120
post #54

Earlier quoted context omitted.

If you lose your U2F security key, are you sure you'll be able to remove it from your Google account? Because what I'm experiencing right now is that they support TOTP and you can't remove it if you lose it..

Specifically you need multiple registered keys, to prevent this current situation. But yeah, this is why I dislike 2FA. There are clear security benefits, but it comes with the extreme downside of "what you know is not sufficient". When it's e.g. a corporate-controlled account and your IT desk can just reset it to "password123!" to let you back in, it's quite a good trade-off. When it's your main email, i.e. your pri…

I used to do this but it was a hassle to set up. I can't imagine a normal person (less interested in tech) to use this.
Post reply on HN