Earlier quoted context omitted.
Good idea! That had never occurred to me before this incident.
You have to take a photo of the screen on another phone, Google disallows you from screenshotting them.
Tell HN: It is impossible to disable Google 2FA using backup codes
31–40 of 352 posts
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#32Earlier quoted context omitted.
Doesn't keeping the seed remove the whole point of one time passwords? If an attacker steals at TOTP, its only good for (I think) less than a minute. If they steal the seed, its good forever.
the point is to have a second factor which isn't really destroyed by having a printout of what you entered onto your phone somewhere secure (now if you store both in your password manager: that completely defeats the point)
The threat model is someone gets your password, not somebody gets access to your password manager.
If the latter is your threat model then yes having your 2F in there is worse, but really the former is the more common thing to protect against and the tradeoff of not having 2F in your 1Password and getting locked out because your phone breaks is worse than the risk of having it in there.
It’s similar to the tradeoff of having a nano yubikey always in your laptop or a large one on your keys. For most people the nano is better (though you should have a second one in either case)
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#33Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#34Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#35I just tested this. You should not disable 2FA. - Just click on the Authenticator app - Change Authenticator app - https://ibb.co/dPCMpdN Just works.
On what page do you see the Authenticator app listed? I suspect it's on the "Two Factor Auth" page. My problem is that I cannot even load that page. I click on "Security" in the menu, and it's when I click on "Two factor auth" to do any 2fa-related task, that's when I'm forced to log in and provide a 2fa code (which I do not have)
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#36TOTP is bad 2FA. Google supports U2F security keys. Use them.
If you lose your U2F security key, are you sure you'll be able to remove it from your Google account? Because what I'm experiencing right now is that they support TOTP and you can't remove it if you lose it..
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#37And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
Doesn't keeping the seed remove the whole point of one time passwords? If an attacker steals at TOTP, its only good for (I think) less than a minute. If they steal the seed, its good forever.
They aren't accessed often, are not used during your normal login flow, and provide you a recovery mechanism that actually works.
Yes - you should store them as securely as you can, but I'd say this is better than disabling 2fa entirely, which seems like the other sane approach.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#38Try enrolling another 2FA method while you're in there.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#39It would be useful if people went to their Google Account page, clicked the Security tab, then tried to access the Two Factor Auth page and reported back what options they had to authenticate. Do you have options other than "enter a two factor auth code"? Can you authenticate on that page with SMS or a backup code?
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#40I just tested this. You should not disable 2FA. - Just click on the Authenticator app - Change Authenticator app - https://ibb.co/dPCMpdN Just works.
Hey, thank you so much for trying to help me. On what page do you see the Authenticator app listed? I suspect it's on the "Two Factor Auth" page. My problem is that I cannot even load that page. I click on "Security" in the menu, and it's when I click on "Two factor auth" to do any 2fa-related task, that's when I'm forced to log in and provide a 2fa code (which I do not have)
Then, https://myaccount.google.com/signinoptions/two-step-verifica...
There you can see Authenticator app.
(I am doing this on desktop. Not sure about phone)