Live data from Hacker News

Tell HN: It is impossible to disable Google 2FA using backup codes

news.ycombinator.com

281–290 of 352 posts

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#283
post #261

Earlier quoted context omitted.

Anecdotally, my wife works for a pharmaceutical company and is mandated to report possible impacts that people report about a drug, even in casual conversation. People working under this mandate simply avoid these areas entirely. We avoid watching certain Instagram and Youtube personalities with certain conditions in the chance they might say something she has to report.

Is that for real? I'd love to hear more about this mandate. Why would someone refuse to watch celebrity Youtube videos, in private with their husband , because of some mandated self-reporting by their pharma overlords? I'm in awe at the level of corporate control and domestication implied. On the face of it, your anecdote reminded me of that (apocryphal?) prank that natives played on early explorers: "Will he eat thi…

It is real. To my recollection, this isn't so much a matter of corporate control as it is following FDA guidelines to the letter.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#284

Earlier quoted context omitted.

Instead of SMS, get a pair of yubikey recommended by some other posters, so you are not depending on your mobile provider as they own the number and it is just "rented" to you.

How does that work? Do you have to carry around a Yubikey/Dongle everywhere with your phone?

Personally, I don't, since I've never wanted to log into my Google account on a device I encountered while out of the house. I'm not really sure why you'd ever do that IMO.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#285

Earlier quoted context omitted.

I have 2FA backup codes! They let me log into my account! But using only backup codes, I cannot remove the lost 2FA. So now I have 8 consumable backup codes and after that I will not be able to access the account. To remove the lost 2FA, I need a fresh 2FA code. No alternatives given.

The solution (which is too late to help you with now) is to take a photo of the QR code that is first showed to you when you originally set up 2FA. Keep that safe somewhere and you can always go back. For anyone who is freaked out by this and currently still has access to their google Authenticator app, I suggest exporting all your codes to a big QR code in the app and keep that safe (maybe print it out).

This. I always keep that qr code screenshot & pharse in a seperate keypass database. Instant same 2fa anytime.

https://spa.bydav.in/otp.html

Shameless plug, I spinned up a local html javascript page to import export these code phrases anytime, with customization options, like issuer name, account name etc.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#286
post #261

Earlier quoted context omitted.

Anecdotally, my wife works for a pharmaceutical company and is mandated to report possible impacts that people report about a drug, even in casual conversation. People working under this mandate simply avoid these areas entirely. We avoid watching certain Instagram and Youtube personalities with certain conditions in the chance they might say something she has to report.

Is that for real? I'd love to hear more about this mandate. Why would someone refuse to watch celebrity Youtube videos, in private with their husband , because of some mandated self-reporting by their pharma overlords? I'm in awe at the level of corporate control and domestication implied. On the face of it, your anecdote reminded me of that (apocryphal?) prank that natives played on early explorers: "Will he eat thi…

It's not a random Pharma company mandate, it's an FDA one. I think it's in here: 21 CFR Part 314.80 Postmarketing reporting of adverse drug experiences.

https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfCFR/CFR...

At its heart I get it — you don't want a company's employees to be burying reports of adverse events. But now the company is liable to ensure such things get reported. And thus they pass this liability onto their employees.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#287
post #133

Earlier quoted context omitted.

Best advice in this thread: https://landing.google.com/advancedprotection/

Keep in mind that this can make signing into some devices tricky. On devices which do not support webauthn (nintendo switch) it will prompt you to acknowledge the code sent to another device which does support webauthn. You can't authenticate some Roku channels as well, such as PhotoView for Google Photos.

also many Google TVs do not support it

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#288
When I was 16 I locked the keys in my parents old car when I drove it so many times that my father, having grown tired of coming to my rescue, put a spare key on a dog tag chain and told me to wear it around my neck. I continued locking the keys in the car when I would drive it, but it was never a problem again.

Now I keep a key chain with a yubikey on it that serves as a redundant option for 2fa to authenticate my google account, in addition to the app in my phone. I actually have two of them and the other is in a secure remote location. If you are doing anything critical in your google services you must have multiple 2fa options for disaster recovery.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#289
Tip: You can bulk export your google authenticator app secrets for a disaster recovery like this. I had not seen this functionality before but I'm glad it existed when setting up a new phone yesterday. I remember the old high friction way of having to deregister and reregister for each account.

Howto:

  ... menu in top right -> export accounts
  make sure all are selected, select export
  It will generate a series of dense QR codes.
  Screenshot / photograph / add to backup phone, save and print for your document safe, whatever.
Of course, this doesn't help if you're already in a loss situation. But recovery this way is SO much easier than typing in a backup code. Recovery is as quick as having the app scan each of the QR codes in sequence. For me it was just 3 dense QR codes.

I was a little surprised that it was this easy to extract all the secrets. I'm going to have to think even more carefully about what TOTP secrets go in there now.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#290

Earlier quoted context omitted.

Instead of SMS, get a pair of yubikey recommended by some other posters, so you are not depending on your mobile provider as they own the number and it is just "rented" to you.

How does that work? Do you have to carry around a Yubikey/Dongle everywhere with your phone?

As others have commented, on your phone you rarely ever need to authenticate, so I keep mine at home.

If you buy a Titan Key you get two (USB-A, USB-C), so sticking one of them in your safety deposit box, locked desk drawer at work or another secured space is a good backup.

Post reply on HN