Earlier quoted context omitted.
Good luck trying to save those QR codes, though. I had to resort to pulling out my DSLR to take a photo of my phone with them. All screenshot/print/save functionality is disabled when you have the codes up on your phone. You need an actual camera on a second device to save them in most cases.
Not true, I just did it a few weeks ago when moving to a new phone. Just screenshotted the backup QR code and when I got my new phone later I used the screenshot.
Tell HN: It is impossible to disable Google 2FA using backup codes
311–320 of 352 posts
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#312Earlier quoted context omitted.
If you're using a password manager, you probably have one-time secure passwords, so the only probable way someone gets it is by stealing your password manager.
This isn't accurate - they don't get access to multiple stuff. - Site0 leaks your password because they store it poorly. - It's just one password, but it's still leaked. - You have 2F in 1Password so even though it's picked up in an account list the attacker can't login. - Weeks later you learn there was a breach. This is the common case for most accounts and breaches. Though the sites most likely to leak are also on…
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#313I had a similar situation with Facebook. Set up 2FA with an app called Duo-somethingorother. Broke my phone. Trying to use Facebook with new phone requires 2FA. Duo-somethingorother app on the new phone won't authorize my Facebook login because the app on the new phone isn't linked to my Facebook account. Result: I'm locked out of Facebook Every year or so I follow Facebook's login authentication steps, including sen…
> I'm not in Europe, so I have no rights to my photos and nowhere to complain. If it makes you feel any better, Facebook doesn't care about the law and Europeans don't have any more luck than you do when it comes to this: https://ruben.verborgh.org/facebook/
I'd like to see an actual lawyer try it and document the effort with similar rigor. I wonder what the response from FB would be.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#314Many years ago, I lost my phone with Google Authenticator (which doesn't have a backup option like Authy does) and got locked out from AWS. The next day there was a production issue with our website. Long story short, our website was down for more than 2 weeks while I was trying to regain access to our AWS account. #2faneveragain
Your website was down for more than 2 weeks not because 2FA is badly designed, but because you bet everything on your phone not getting lost or damaged. And now you refuse to secure your accounts.
If you register with a yubikey, you can't register a 2nd yubikey as backup, nor can you register an authenticatior(TOTP) as a backup.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#315Earlier quoted context omitted.
You can do this, or you can write down the secret (Click to get the text), and use oathtool to generate codes rather than google's auth. I keep all my 2fa secrets in pass for this reason. Never lose access again!
But be careful. If you access the passwords and 2fa secrets via the same credentials you are back to one factor authentication if secret + pass store ever get compromised. Imho it's a different story if you use a separate gpg-key/secret to access the 2fa secrets (which should also only happen in emergency cases). This can easily be done with pass.
https://security.stackexchange.com/a/194279 explains it better than I could.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#316Earlier quoted context omitted.
Really? I've never seen anyone at Google or Apple who's in a "staff role with public outreach as part of their job". I don't think any big tech companies have those.
They do, and Google does. Job descriptions are usually something like: "As a Technical Evangelist, you will be the face of the platform and often the first contact our customers have with us, both online and in person." https://en.wikipedia.org/wiki/Technology_evangelist
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#317The thing I have taken away from these continual Tell HN posts about Google acounts getting locked up because of 2FA is that the "something you have" factor needs redundancy. I now have my phone, and 4 yubikeys on my household's carkeys and a trusted friends and a family member's firesafe. These have also given me enough stress that when I visited home for the holidays I added to my aging parents' Google accounts with a handful of additional security keys to go with their SMS 2FA.
Personally I would rather have accounts which are secure and can be lost if I am not careful with my 2nd factors than one that has vulnerabilities that the whole internet can attempt to exploit, but I realize others do not have that same priority.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#318Earlier quoted context omitted.
> I'm not in Europe, so I have no rights to my photos and nowhere to complain. If it makes you feel any better, Facebook doesn't care about the law and Europeans don't have any more luck than you do when it comes to this: https://ruben.verborgh.org/facebook/
An interesting read. Too bad the author made himself look like a kook in his correspondence, and thus ignoreable by Facebook. I'd like to see an actual lawyer try it and document the effort with similar rigor. I wonder what the response from FB would be.
Keep in mind that the regulator who’s supposed to regulate them is corrupt and complicit so it’s very unlikely anything would work.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#319Whenever one of these threads about Google (or Apple) come up, I am shocked at the lack of response from people working at those companies. It seems reasonable that this site would be where you'd find someone from a team that interacted with logic that OP is having trouble with. I'd expect to see something like a "hey, yeah, I know a guy on our team that might be able to get in touch with the team who maintains this.…
Developers at large corporations are strictly informed that they are not the public face of the company and can't do that. These aren't mom and pop developer shops.