Live data from Hacker News

Tell HN: It is impossible to disable Google 2FA using backup codes

news.ycombinator.com

231–240 of 352 posts

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#231

My advice is only actionable for others, not OP. You should have backups on places other than the phone. I warmly recommend andOTP for managing your TOTPs. It's open source and available on F-Droid. https://f-droid.org/en/packages/org.shadowice.flocke.andotp/

Even better would be Aegis which does backups for you, and (at least in my opinion) has the best UI for an aithenticator app. Also available on FDroid.

https://getaegis.app/

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#233
The person who successfully convinced people that 2FA is actually more security is the biggest scumbag in history.

The lost productivity dealing with shitty 2FA implementations and the subsequent shitty customer support is enough to build all 7 wonders of the world many times over.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#234
post #18

Earlier quoted context omitted.

In Bitwarden you can just store the key itself and it'll generate the codes for you, right next to your password, so convenient!

I expect the "so convenient" is sarcastic, but yes it is more convenient and also more secure. It helps to consider the threat model. 2FA is protection against (at least) several things: brute-force password guessing, a stolen password, a hijacked email account, etc. Since password vaults like bitwarden are designed to be uncrackable on their own, the only plausible way for an attacker to compromise one is to gain co…

What's the word, tongue in cheek? I meant it sincerely but phrased in a sarcastic tone. I unironically do this and it's saved me from two phone breakages. I cannot understand how anyone would trust any of their accounts to a single physical device that is routinely lost, stolen, or broken.

My 2FA token is just a second password that doesn't get sent over the wire directly -- it's almost like a private key where you auth via challenge... wait a minute, thought you could sneak PAKE on me?!

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#235

Earlier quoted context omitted.

Instead of SMS, get a pair of yubikey recommended by some other posters, so you are not depending on your mobile provider as they own the number and it is just "rented" to you.

How does that work? Do you have to carry around a Yubikey/Dongle everywhere with your phone?

For my phone, I'm already logged in and never get any future challenges. I needed the Yubikey when I first logged into my phone, but after that the phone has been authenticated. If I unlink my phone to my Google account I'll need the Yubikey again, but I don't normally do that. So normally I don't carry a Yubikey with me, like when I go to the store and what not.

That said, I do keep a Yubikey with me in my bag when I travel in case my phone breaks and I need to authenticate into a new device. I do take a Yubikey with me going to and from the office as there are other services and platforms which do challenge my Yubikey more often.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#236
post #155

Hey, so this is admittedly monday morning quarterbacking, but in the future, you can definitely consider moving from Google Auth to Twillio's authy [1]. It lets you move devices and all your secrets come with you (it's also got other cool features, but the one that is killer IMO is the ability to migrate from device to device). https://authy.com/

I can’t recommend Authy enough. It’s multi device from the start and has cloud backup.

I once broke my phone with Google Authenticator on it and I spent 2 days locked out from my work accounts. Never risking that again.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#237
post #86

Earlier quoted context omitted.

That’s expensive.

Won't somebody just think of Googles pocketbook. The only way they can stay afloat is telling people to go fuck themselves when Google messes something about their entire online identity up, clearly.

Or people could pay for the Workspaces account which come with support.

Basing someone’s entire online identity on a free account has always been pretty sketchy. We just haven’t come up with a better plan for most people yet.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#238

Earlier quoted context omitted.

Developers at large corporations are strictly informed that they are not the public face of the company and can't do that. These aren't mom and pop developer shops.

They can't send a link to a colleague?

How can you possibly know they don’t do that?

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#239

Earlier quoted context omitted.

Gmail is the ultimate root of way too many services for me, but I don’t really see any alternative. For example there are lots of nice paid services out there that look great, but eventually I’m going to forget to pay, or the company will go under, or whatever. IMO we need USPS email addresses for the same reason we have mailboxes. The ability to be contacted digitally is just table stakes nowadays.

> For example there are lots of nice paid services out there that look great, but eventually I’m going to forget to pay, or the company will go under, or whatever. Right, that's why I think there should be an option for a $500 permanent email address, or maybe $50 one-time payment that doesn't guarantee permanent access but does guarantee that the email address will sit there as long as it takes for you to be able to…

Purchase a domain and use your registrar's SMTP and IMAP servers. I have been doing this for about 5 years now and it feels great. I get to pay annually for a bundle of related services (domain, DNS, email, ...) instead of freeloading in a place where I'm the product and there is no support.

You could also purchase a domain and point MX records anywhere, preferably at some known-good mail service which you pay for.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#240

Earlier quoted context omitted.

Yep it absolutely ratchets up "suspicion" on your account, and failed attempts will quickly get your account in some sort of state where you're locked out. It's absolutely maddening.

Definitely - and I think now that I've gone to that 2FA page and let it time out (since I only have backup codes), I think it's racheted up suspicion higher as these login attempts count as "an attacker has the password but not the 2FA code!"

Definitely. I did that a few weeks ago and got an email from Google to my gmail saying something along the lines of "somebody has your password and is trying to log in!" even though it was just me on a different computer and after submitting password I realized I didn't have my phone on me so couldn't submit the 2FA. It was even a computer on the same LAN (with same WAN IP), so not like I had an active session in the US while the attempt came from Moscow...
Post reply on HN