Live data from Hacker News

Tell HN: It is impossible to disable Google 2FA using backup codes

news.ycombinator.com

171–180 of 352 posts

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#171
post #124

Whenever one of these threads about Google (or Apple) come up, I am shocked at the lack of response from people working at those companies. It seems reasonable that this site would be where you'd find someone from a team that interacted with logic that OP is having trouble with. I'd expect to see something like a "hey, yeah, I know a guy on our team that might be able to get in touch with the team who maintains this.…

Something similar but different happened to me. I know someone who works at Google in a distant dept. The best he could do was try to follow the internal escalation policy, which was broken, so he filed an internal bug about the process. I solved my issue a different way on the end.

I bet employees feel as disempowered about this stuff as civilians…

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#172

I was recently trying to log into Slack on a new computer. It required a login and password, and then emailed a 2FA code to my login email. Then it _also_ wanted 2FA code from my mobile app, which it seems wasn't configured correctly on my new phone. The experience left me with multiple questions - what needed to be transferred from my 2FA app on my old phone to my new phone that didn't make it? Why wasn't the email…

My fear (disclaimer: I'm a bit ignorant on the topic) is that system breaches will become more common, maybe with the help of AI. Maybe AI will help with social engineering. Maybe it will help with malware proliferation. Regardless, when I hear of groups like LastPass getting breached I'm suddenly much less keen on 1FA.

Besides, some services no longer offer 1FA at all. Google seems to require 2FA of some sort no matter what (although maybe that's just my settings?). So it becomes more important to at least weed out the "bad" 2FA like SMS or security questions. I've heard warnings about Google Authenticator before, something about the inability to make backups or something?

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#173

Earlier quoted context omitted.

There may be a plugin for it but the KeePass clients I've used don't support this by default. Generally, it would be best to look for the string (and keep both the string and the image secret!).

KeepassXC lets you store the TOTP seed value associated with an entry by right-clicking on that key and selecting "Setting up TOTP". Also, other TOTP generators like Authy and Aegis let you backup your tokens to restore to another device.

Yes, but be careful which totp app you're using to store seed values/secret keys : some store them as plain text! Personally on android I'm using keepass2android and keepassium on ios to store both the QR image and the string value. It will also generate the OTP value at login. As you know, the keepass password file can be backed-up anywhere.

https://raw.githubusercontent.com/blues-lab/totp-app-analysi...

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#174
post #133

Maybe too late to give you any helpful advice, but setting up Advanced Protection may make sense. You need to buy at least two (preferably three) YubiKeys and the password plus any of these keys allow you to login to your account. Nothing more, nothing less. Costs a few bucks, but at least the auth flow is very clear. Another thing you can do is to wait for a week and see if anything changes. Having the session last…

Best advice in this thread: https://landing.google.com/advancedprotection/

Keep in mind that this can make signing into some devices tricky. On devices which do not support webauthn (nintendo switch) it will prompt you to acknowledge the code sent to another device which does support webauthn.

You can't authenticate some Roku channels as well, such as PhotoView for Google Photos.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#175

Oh my god. 2-Step verification on your Google Account is actually less secure than not using it at all. I just posted about something similar maybe 3 months ago?[1] > I kid you not. Google's actual official answer to this is... create another account![1][2][3] > Edit: Now that I have your attention: > PSA: Go create "Backup codes" for your Google Account in your 2-Step Verification settings. > [1]: https://support.go…

I have 2FA backup codes! They let me log into my account! But using only backup codes, I cannot remove the lost 2FA. So now I have 8 consumable backup codes and after that I will not be able to access the account. To remove the lost 2FA, I need a fresh 2FA code. No alternatives given.

If you login on your phone, it’s possible your phone will automatically become a “second factor” if on Android, or if you have Google apps installed on iOS. This would resolve the problem, but I can’t promise it’ll work.

Note: I mean in mobile apps, not browsers.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#176
post #16

> What am I supposed to do in this situation? This. Support systems in the world post computers eating everything is basically HN posts.

Completely agree! Especially in consumer. I have two situations that are still unresolved.

1. Getting un-banished from Google ads after a failed credit card charge. No one will tell you why, appeal form doesn't tell you why and eventually I figured out a there had been a failed credit card charge 2 years ago.

2. Recovering a Facebook account with an email-password reset. The profile was frozen after it was hacked and all of a sudden a 5 year old phone number is required to unlock the profile after the password reset. --> Help page to submit a petition still tries to send you to login flow.

How can there be no way to talk to someone?!?

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#177
post #124

Whenever one of these threads about Google (or Apple) come up, I am shocked at the lack of response from people working at those companies. It seems reasonable that this site would be where you'd find someone from a team that interacted with logic that OP is having trouble with. I'd expect to see something like a "hey, yeah, I know a guy on our team that might be able to get in touch with the team who maintains this.…

Which could mean that these people have been outsourced.

Their billing collections dept is outsourced to Accenture (they say so in the email sig) and from my support conversations are pretty much siloed off.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#178

Earlier quoted context omitted.

Maybe the next million new jobs is just rebuilding a reasonable level of customer support at all tech companies, funded by modest usage fees. $5/mo, $50/yr, or $500 for lifetime guaranteed permanent access so no lockouts are possible, I would definitely pay for Gmail or an equivalent service. And there are people who I’m sure would pay much more. Another short term option: $500-1000 right now to get a couple hours of…

Maybe the next million new jobs is just rebuilding a reasonable level of customer support at all tech companies, funded by modest usage fees This already exists. It's why if you have a certain bank balance, when you call the bank a human in your own country picks up and speaks to you in your native tongue immediately. And if you don't have a certain bank balance, you sit on hold for 90 minutes and are repeatedly told…

That's called competition. Banks interoperating with each other means competitors serving different segments of the market can spring up.

Google does not interoperate and effectively has a monopoly on web search, web video (YouTube) and is one of the two evils owning the mobile market (the other being Apple). There is no way for a competitor to emerge because it just wouldn't be able to interoperate with any of these services.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#179

Earlier quoted context omitted.

I have 2FA backup codes! They let me log into my account! But using only backup codes, I cannot remove the lost 2FA. So now I have 8 consumable backup codes and after that I will not be able to access the account. To remove the lost 2FA, I need a fresh 2FA code. No alternatives given.

The solution (which is too late to help you with now) is to take a photo of the QR code that is first showed to you when you originally set up 2FA. Keep that safe somewhere and you can always go back. For anyone who is freaked out by this and currently still has access to their google Authenticator app, I suggest exporting all your codes to a big QR code in the app and keep that safe (maybe print it out).

1Password stores QR codes and syncs them across any device that has access to your vault. I highly recommend this solution if you're worried about losing access to your 2FA codes. It is also easy to back up.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#180
post #124

Whenever one of these threads about Google (or Apple) come up, I am shocked at the lack of response from people working at those companies. It seems reasonable that this site would be where you'd find someone from a team that interacted with logic that OP is having trouble with. I'd expect to see something like a "hey, yeah, I know a guy on our team that might be able to get in touch with the team who maintains this.…

Any of these large companies are like governments. Assume you complain to a Chinese or US or European that your govt does this bad/crazy/illogical thing.

how do they respond?

Do you think if you tell an engineer from John Deere that they have unethical practices the are going to complain in the next meeting? Or a Volkswagen person that does care about pollution but will be quiet.

They just look at pay checks.

Any complaints. they just shrug or chuckle ...

The teams are big and finally they cant get involved. IIRC, even spouses of Googlers cant get special access.

At the same time if they did manage to reset account/password/etc that would be the best way to circumvent security.

Post reply on HN