Earlier quoted context omitted.
Typically the way these codes are compromised is when they are stored in a non-HSM location like Google drive or transferred somehow. Then again, if you are just trying to keep people out of your Facebook account it's not a big deal. But if you are trying to keep people from financial accounts I wouldn't recommend transferring TOTP keys. Instead using a backup method like a printed out one time use sheet would be bet…
It sucks Yubikey (or other hardware based auth) isn't more prevalent in the financial/banking world. It helps mitigate a lot of types of attacks: - No tokens to exfiltrate off a computer - Avoids keylogger style attacks - More durable than cell phones That said, for people that have high amounts of money in certain accounts (> 1m), it might also present physical dangers (e.g. kidnapping, home invasion) for thieves at…
Authy corrupted my 2FA backup and all I got was this lousy blogpost
21–28 of 28 posts
Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost
#22They refuse to start the app on GrapheneOS literally because they cannot be arsed, offloading the claim of security of the handset to Google (which says an old handset not patched in the last 8 years is secure, but the most recent, best patched OS is not).
When the shit hit the fan Authy even removed the way to export the seeds from the desktop version of the app. Big FU to customers.
Never again.
Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost
#23Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost
#24tl;dr > Much to my surprise, when checking the App Store page, I saw that an update to the app had been approved by Apple only 14 minutes prior. I downloaded the update, tapped upon one of the previously "locked" items, and entered my backup password. Boom, the previously locked 2FA codes were now unlocked and restored, ready for use.
Or what is the purpose of your comment? :)
Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost
#25Earlier quoted context omitted.
"Security reasons" is pretty insane, considering how easy it is to lose access to a good number of accounts if any 2FA app breaks from a bad update. Google Authenticator has done this before too, way back in 2013: https://news.ycombinator.com/item?id=6325760
It is indeed the very epitome of sanity, if you simply consider that the codes are secrets , and this entire practice is derived from having hardware dongles with secure enclaves, where secrets go in but never come out. It is the utmost in security when this one-way relationship is observed. The ability to export secrets is an unfortunate compromise which vendors make for consumer markets. The MFA apps were not desig…
Not all TOTP implementations, especially indie PHP websites, are robust enough to have implemented backup codes.
Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost
#26Earlier quoted context omitted.
It is indeed the very epitome of sanity, if you simply consider that the codes are secrets , and this entire practice is derived from having hardware dongles with secure enclaves, where secrets go in but never come out. It is the utmost in security when this one-way relationship is observed. The ability to export secrets is an unfortunate compromise which vendors make for consumer markets. The MFA apps were not desig…
> The reason that you don't lose access to accounts when losing your MFA apps is that you took down the emergency backup codes and you committed them to paper, or some other durable medium, in a place where they can easily be accessed during a crisis. You did this scrupulously with each MFA activation, didn't you? Didn't you? Not all TOTP implementations, especially indie PHP websites, are robust enough to have imple…
I have been dismayed at some supposedly professional implementations, such as when I telephoned Wal-Mart to ask what can be done if I lost my phone (SMS is their only 2FA) and they said that they were prohibited from changing anything in account settings or profiles, and the best idea was to create a new account. (That is crazy -- if you shop at a marketplace like that, they've stored all your receipts, your membership, a potentially years-long trail of paperwork that you may need for taxes, or reimbursement, or refunds later on!)
Even worse, I had a bad time with the United States Postal Service. If I recall correctly, I'd lost access to the registered email address, and I was requesting to change it to something within my control, and they said "no can do", and they told me that my only recourse would be to create a new account, so that's what I did. Interestingly, USPS offers 2FA via either email or SMS, and their SMS gateway service is frequently out of order, so I always use email when logging in there.
Once, around 2021, I contacted GitLab to inform them that their account recovery process was a backdoor to circumvent MFA. They denied any such problem. I suggest that any account recovery implementation be just as secure as the front door to sign in, but also not impossible, because why do you want loyal customers to lose their accounts completely?
Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost
#27Highly recommended by a highly satisfied user.