Live data from Hacker News

Tell HN: It is impossible to disable Google 2FA using backup codes

news.ycombinator.com

121–130 of 352 posts

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#121

Earlier quoted context omitted.

The solution (which is too late to help you with now) is to take a photo of the QR code that is first showed to you when you originally set up 2FA. Keep that safe somewhere and you can always go back. For anyone who is freaked out by this and currently still has access to their google Authenticator app, I suggest exporting all your codes to a big QR code in the app and keep that safe (maybe print it out).

And for authenticators that do not allow to export the secret, while your authenticator is not lost yet, add another authenticator: and during registration, save the QR code.

There is no option to add another authenticator app at https://myaccount.google.com/security (desktop UI). I think the only feasible option is to first remove Google Authenticator and then re-enable it.

Seriously, Google?

Might be micro, but this is not a sign of a healthy company on an upwards trajectory.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#122

Earlier quoted context omitted.

You are correct about the QR code just representing a (fairly short) string, but applications can handle QR code just fine - 1password can read it directly from the screen.

There may be a plugin for it but the KeePass clients I've used don't support this by default. Generally, it would be best to look for the string (and keep both the string and the image secret!).

KeepassXC lets you store the TOTP seed value associated with an entry by right-clicking on that key and selecting "Setting up TOTP".

Also, other TOTP generators like Authy and Aegis let you backup your tokens to restore to another device.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#123

Earlier quoted context omitted.

I have 2FA backup codes! They let me log into my account! But using only backup codes, I cannot remove the lost 2FA. So now I have 8 consumable backup codes and after that I will not be able to access the account. To remove the lost 2FA, I need a fresh 2FA code. No alternatives given.

The solution (which is too late to help you with now) is to take a photo of the QR code that is first showed to you when you originally set up 2FA. Keep that safe somewhere and you can always go back. For anyone who is freaked out by this and currently still has access to their google Authenticator app, I suggest exporting all your codes to a big QR code in the app and keep that safe (maybe print it out).

Printing it out and putting it in some safe is what i did.

And works like a charm.

I mean, if it works for crypto wallets it might also work for 2FA...

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#124
Whenever one of these threads about Google (or Apple) come up, I am shocked at the lack of response from people working at those companies. It seems reasonable that this site would be where you'd find someone from a team that interacted with logic that OP is having trouble with.

I'd expect to see something like a "hey, yeah, I know a guy on our team that might be able to get in touch with the team who maintains this. I've sent them this thread"...

I'm hoping OP got a private message.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#125
post #50

Earlier quoted context omitted.

I cannot access the Two Factor authentication page at all - it is when attempting to access that page that I'm forced to log in again and provide a 2FA code.

Weird, this used to work... I guess they changed it at some point.

It's a mistake to believe that every user will uniformly see the same things on the same pages. Google's account abuse system will offer different options to different users based on how suspicious their behavior appears to be.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#126
Maybe too late to give you any helpful advice, but setting up Advanced Protection may make sense. You need to buy at least two (preferably three) YubiKeys and the password plus any of these keys allow you to login to your account. Nothing more, nothing less. Costs a few bucks, but at least the auth flow is very clear.

Another thing you can do is to wait for a week and see if anything changes. Having the session last for more than a week may give you more options in passing the challenge.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#127
I was recently trying to log into Slack on a new computer. It required a login and password, and then emailed a 2FA code to my login email. Then it _also_ wanted 2FA code from my mobile app, which it seems wasn't configured correctly on my new phone. The experience left me with multiple questions - what needed to be transferred from my 2FA app on my old phone to my new phone that didn't make it? Why wasn't the email code good enough (as that is literally already two factors?)

I've largely stuck with strong passwords for most of my accounts because of issues like these, and others I saw first hand - such as when my dad used to have a password db on a palm pilot. He had no backups, some point the device fails, everything was lost. I only felt comfortable moving to a password db once dropbox became a thing as a result - the balance of security vs. usability is pretty shit if there's a single point of failure with no recovery possible, and I'm not inclined to set up some backup process manually (dropbox has reliably been something I haven't had to think about for a decade.)

2FA feels a lot like that to me, except now with multiple points of failure that can be difficult to recover. Backup codes feel half-baked; it strikes me as the kind of thing that was tacked on to help the issues around hardware failure/human error that one _should expect and design for_; instead, we put the onus on the user with "your account may be unrecoverable" warnings as an excuse.

A better system, IMO, would have N factors and require one less. Keepass is the place where this has bothered me for some time - I can configure things so my db requires a password, and a file, and a Yubikey - but why can't I have two of three? Hell, why can't I have _one_ of two? If I'm in a car crash and die and I want one particular person to cleanup some aspects of my virtual life, it'd be nice if I could give them a key file and let them know there's a Yubikey in a safe deposit box. I feel secure, as no one has all three tokens but me and two are always needed; but I also feel the system is durable, in case something is forgotten, crushed, lost, etc. I dunno, maybe there's people or companies that already do stuff like this and I just don't know about it.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#128
I had a similar situation with Facebook.

Set up 2FA with an app called Duo-somethingorother.

Broke my phone.

Trying to use Facebook with new phone requires 2FA. Duo-somethingorother app on the new phone won't authorize my Facebook login because the app on the new phone isn't linked to my Facebook account.

Result: I'm locked out of Facebook

Every year or so I follow Facebook's login authentication steps, including sending photos of my government-issued ID, but nothing happens. Facebook support? What's that?

At this point, all I want to log in to Facebook for is to download the photos from my account. But I'm not in Europe, so I have no rights to my photos and nowhere to complain.

You get what you pay for.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#129
I lost access to my Coinbase account a while back because I was using Authenticator on the iPhone and when I bought a new phone and set it up, my Authenticator codes did not transfer with the rest of my data. At that point I stopped using Authenticator. I hope that's still not an issue upgrading iPhones today.
Post reply on HN