Live data from Hacker News

Still locked out of my AWS account

docs.google.com

271–280 of 283 posts

Re: Still locked out of my AWS account

#271
post #218

Earlier quoted context omitted.

Google Authenticator is a bad 2FA app. Authenticator+ costs a couple of bucks but has many features that make it much easier to use, including the ability to back up an encrypted copy of your 2FA keys (standard disclaimers about risk of compromise to this file, yadda yadda yadda). When you change phones, you just download that, decrypt, and pick up where you left off; no hassle trying to replace the 2FA generators, w…

Mobile phone authenticator apps are not that great anyway. They rely on the security of a phone that is connected to the net to keep the keys secure. If someone can get code running on the phone and exploit a privilege escalation vulnerability to get root, they can read the keys. A hardware token like a Yubikey or similar is probably more secure. Another problem with the Google authenticator, at least for Google acco…

You can remove the phone number once you add another 2FA method, such as U2F (Security Key) or TOTP (Google Authenticator or other TOTP app).

Re: Still locked out of my AWS account

#272
post #134

Earlier quoted context omitted.

This anecdote makes me very happy with AWS. I want loss of 2FA to completely revoke access to my account. Otherwise any smart hacker can social engineer Amazon support with some fake drivers license photo and steal all my BTC (for example).

So what is your plan in case your phone gets lost/stolen/whatever and you lose access to your TOTP app?

I use Authy as my TOTP client. It has a encrypted backup feature and allows me to share tokens between my devices (computer, phone, iPad, etc.) It's saved me on more than one occasion. :)

Re: Still locked out of my AWS account

#273

Also having problem with AWS - can't access it and they keep billing me for something there I want to shut it down (EC2?) but I can't. I recently moved from Brazil to UK (new address) and changed phone + sim card (Authenticator after restore from backup lost all 2 factor auth entries). This is the moment when you realise that you're outside of predefined use cases of The Machine and you're fucked. Nobody is here to h…

I store my 2FA in 4 different authenticator apps on my phone just in case. Google Authenticator has never restored these properly, ever. Encrypted backups or not.

You should try Authy. I switched over to it after I got burned by Google Authenticator deleting all my tokens after an upgrade. It can store your tokens in a encrypted central location and allows you to share tokens between devices (computer, phone, tablet, etc.) It kinda freaked me out at first but now I really like it.

Re: Still locked out of my AWS account

#274
post #269

Earlier quoted context omitted.

I learned this the hard way when google authenticator failed to restore my keys after a phone upgrade. Now I make sure I copy the data from those QR codes and store them in a GPG encrypted file (I store the data and the QR code itself as utf-8 art in the file).

The way that first sentence is phrased makes it sound like it was the app's fault.

I blame the app entirely. Not marking the private keys as something to backup is a really really sucky thing to do.

Re: Still locked out of my AWS account

#275
post #152

Earlier quoted context omitted.

Yes, my bank branch notarizes for free.

This is quite different in Australia where notaries public are appointed either by the State Supreme Court or by an Archbishop. Almost all of which of which are solicitors or barristers, sometimes retired from practice.

As an Australian, if your workplace has a legal department - make friends with someone there.

It can save you a huge headache when you need to do something like apply for a home loan, and need tonnes of notarised papers.

Re: Still locked out of my AWS account

#276

Earlier quoted context omitted.

If you aren't paying your bills, then you shouldn't be surprised that it gets shut down.

Who downvoted you for saying one shouldn't be surprised when an account gets shut down after not paying for 3 years? On that note: why hasn't the account been shut down for nonpayment?

Please don't complain about downvotes

Re: Still locked out of my AWS account

#277
post #156

Earlier quoted context omitted.

I love your willingness to be blackmailed.

It's not blackmail. He locked himself out of his account, and Amazon is erring on the side of caution before turning off services and shutting down accounts. While it might be a nuisance to get a document notarized, it's not some extraordinary hardship. The policy is there to prevent abuse. If he prefers to let his bill go unpaid as a result of locking himself out of his account, that's his choice.

The point of humans providing customer service is that they can judge that in this case the account can in fact be closed without harm.

Re: Still locked out of my AWS account

#278

Earlier quoted context omitted.

This is why I have my own domain. I have a catch-all email box that just accepts everything and can make up emails on the spot, service@example.com. It makes things a lot easier down the road if I have a problem with my current provider as I can change the MX records at will. This means though that my DNS service must be under another domain for safety though but that's less of an issue.

Do you have anything written about the components & configuration, by any chance?

In my case I'm using an old grandfathered free google apps setup. So I don't have anything to really setup/configure myself. I know it's possible to do it with postfix and other mailing agents.

https://www.cyberciti.biz/faq/howto-setup-postfix-catch-all-...

Re: Still locked out of my AWS account

#279
post #249

Earlier quoted context omitted.

Yeah, for real why does my Comcast account need 2FA?

so you would have no problem posting your username and password for comcast publicly?

i would have a problem posting them publicly. Now, if someone wants to trick Comcast support so they can pay my bill, go ahead !

Re: Still locked out of my AWS account

#280
post #249

Earlier quoted context omitted.

Yeah, for real why does my Comcast account need 2FA?

so you would have no problem posting your username and password for comcast publicly?

Hell no, without 2FA those are the only things protecting my account! Why would I want to post them publicly? That doesn't even make sense.

I do business with 4 banks and have no less than 4 credit cards, and I'm pretty sure that none of them offer proper 2FA with tokens for the online accounts. Now that you mention it, this is a serious question. Why does Comcast get there before any of the major and/or local banks?

I'll admit, if I can protect my Comcast account and as a result, I never have to speak to another one of their Customer Service Reps, it would be a huge victory! This is probably part of their retention strategy, to be fair.

It's telling that there's no mention of on any document, or interface to Comcast's 2FA settings (that I can find anyway) that speaks to how to use it for protecting the set-top box from ordering Pay-Per-View content.

If I turn on 2FA, I'm pretty sure I won't have the option to use it when ordering PPV. It looks like they have a PIN lock instead. Maybe I can disable PPV and protect it with the second factor?

I honestly have no idea why it's even an option. Are swatters gonna log into my Comcast account, upgrade my XFINITY connection to the maximum bandwidth, and sign me up for all of the premium channels?

Or are they hacking my account so they can pay the bill for me :-D

Post reply on HN