My advice is only actionable for others, not OP. You should have backups on places other than the phone. I warmly recommend andOTP for managing your TOTPs. It's open source and available on F-Droid. https://f-droid.org/en/packages/org.shadowice.flocke.andotp/
Tell HN: It is impossible to disable Google 2FA using backup codes
231–240 of 352 posts
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#232I keep a cold yubikey in a locked cabinet at work as well as my TOTP secret, encrypted and printed.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#233The lost productivity dealing with shitty 2FA implementations and the subsequent shitty customer support is enough to build all 7 wonders of the world many times over.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#234Earlier quoted context omitted.
In Bitwarden you can just store the key itself and it'll generate the codes for you, right next to your password, so convenient!
I expect the "so convenient" is sarcastic, but yes it is more convenient and also more secure. It helps to consider the threat model. 2FA is protection against (at least) several things: brute-force password guessing, a stolen password, a hijacked email account, etc. Since password vaults like bitwarden are designed to be uncrackable on their own, the only plausible way for an attacker to compromise one is to gain co…
My 2FA token is just a second password that doesn't get sent over the wire directly -- it's almost like a private key where you auth via challenge... wait a minute, thought you could sneak PAKE on me?!
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#235Earlier quoted context omitted.
Instead of SMS, get a pair of yubikey recommended by some other posters, so you are not depending on your mobile provider as they own the number and it is just "rented" to you.
How does that work? Do you have to carry around a Yubikey/Dongle everywhere with your phone?
That said, I do keep a Yubikey with me in my bag when I travel in case my phone breaks and I need to authenticate into a new device. I do take a Yubikey with me going to and from the office as there are other services and platforms which do challenge my Yubikey more often.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#236Hey, so this is admittedly monday morning quarterbacking, but in the future, you can definitely consider moving from Google Auth to Twillio's authy [1]. It lets you move devices and all your secrets come with you (it's also got other cool features, but the one that is killer IMO is the ability to migrate from device to device). https://authy.com/
I once broke my phone with Google Authenticator on it and I spent 2 days locked out from my work accounts. Never risking that again.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#237Earlier quoted context omitted.
That’s expensive.
Won't somebody just think of Googles pocketbook. The only way they can stay afloat is telling people to go fuck themselves when Google messes something about their entire online identity up, clearly.
Basing someone’s entire online identity on a free account has always been pretty sketchy. We just haven’t come up with a better plan for most people yet.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#238Earlier quoted context omitted.
Developers at large corporations are strictly informed that they are not the public face of the company and can't do that. These aren't mom and pop developer shops.
They can't send a link to a colleague?
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#239Earlier quoted context omitted.
Gmail is the ultimate root of way too many services for me, but I don’t really see any alternative. For example there are lots of nice paid services out there that look great, but eventually I’m going to forget to pay, or the company will go under, or whatever. IMO we need USPS email addresses for the same reason we have mailboxes. The ability to be contacted digitally is just table stakes nowadays.
> For example there are lots of nice paid services out there that look great, but eventually I’m going to forget to pay, or the company will go under, or whatever. Right, that's why I think there should be an option for a $500 permanent email address, or maybe $50 one-time payment that doesn't guarantee permanent access but does guarantee that the email address will sit there as long as it takes for you to be able to…
You could also purchase a domain and point MX records anywhere, preferably at some known-good mail service which you pay for.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#240Earlier quoted context omitted.
Yep it absolutely ratchets up "suspicion" on your account, and failed attempts will quickly get your account in some sort of state where you're locked out. It's absolutely maddening.
Definitely - and I think now that I've gone to that 2FA page and let it time out (since I only have backup codes), I think it's racheted up suspicion higher as these login attempts count as "an attacker has the password but not the 2FA code!"