Live data from Hacker News

Tell HN: It is impossible to disable Google 2FA using backup codes

news.ycombinator.com

311–320 of 352 posts

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#311
post #87
post #67

Earlier quoted context omitted.

Good luck trying to save those QR codes, though. I had to resort to pulling out my DSLR to take a photo of my phone with them. All screenshot/print/save functionality is disabled when you have the codes up on your phone. You need an actual camera on a second device to save them in most cases.

Not true, I just did it a few weeks ago when moving to a new phone. Just screenshotted the backup QR code and when I got my new phone later I used the screenshot.

At least on recent Android versions, it blocks you from screenshotting it, FWIW.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#312

Earlier quoted context omitted.

If you're using a password manager, you probably have one-time secure passwords, so the only probable way someone gets it is by stealing your password manager.

This isn't accurate - they don't get access to multiple stuff. - Site0 leaks your password because they store it poorly. - It's just one password, but it's still leaked. - You have 2F in 1Password so even though it's picked up in an account list the attacker can't login. - Weeks later you learn there was a breach. This is the common case for most accounts and breaches. Though the sites most likely to leak are also on…

So the attacker gets access to the plaintext passwords but not the rest of the database or the ability to skip the 2FA server-side, and the site doesn't notice. Guess I can see that happening still, since the password DB is likely separate.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#313

I had a similar situation with Facebook. Set up 2FA with an app called Duo-somethingorother. Broke my phone. Trying to use Facebook with new phone requires 2FA. Duo-somethingorother app on the new phone won't authorize my Facebook login because the app on the new phone isn't linked to my Facebook account. Result: I'm locked out of Facebook Every year or so I follow Facebook's login authentication steps, including sen…

> I'm not in Europe, so I have no rights to my photos and nowhere to complain. If it makes you feel any better, Facebook doesn't care about the law and Europeans don't have any more luck than you do when it comes to this: https://ruben.verborgh.org/facebook/

An interesting read. Too bad the author made himself look like a kook in his correspondence, and thus ignoreable by Facebook.

I'd like to see an actual lawyer try it and document the effort with similar rigor. I wonder what the response from FB would be.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#314

Many years ago, I lost my phone with Google Authenticator (which doesn't have a backup option like Authy does) and got locked out from AWS. The next day there was a production issue with our website. Long story short, our website was down for more than 2 weeks while I was trying to regain access to our AWS account. #2faneveragain

Your website was down for more than 2 weeks not because 2FA is badly designed, but because you bet everything on your phone not getting lost or damaged. And now you refuse to secure your accounts.

Actually in this case it's likely AWS is also responsible for having trash 2fa restrictions. AWS will only allow you to setup one single 2fa method.

If you register with a yubikey, you can't register a 2nd yubikey as backup, nor can you register an authenticatior(TOTP) as a backup.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#315
post #117

Earlier quoted context omitted.

You can do this, or you can write down the secret (Click to get the text), and use oathtool to generate codes rather than google's auth. I keep all my 2fa secrets in pass for this reason. Never lose access again!

But be careful. If you access the passwords and 2fa secrets via the same credentials you are back to one factor authentication if secret + pass store ever get compromised. Imho it's a different story if you use a separate gpg-key/secret to access the 2fa secrets (which should also only happen in emergency cases). This can easily be done with pass.

This is not entirely true.

https://security.stackexchange.com/a/194279 explains it better than I could.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#316
post #280

Earlier quoted context omitted.

Really? I've never seen anyone at Google or Apple who's in a "staff role with public outreach as part of their job". I don't think any big tech companies have those.

They do, and Google does. Job descriptions are usually something like: "As a Technical Evangelist, you will be the face of the platform and often the first contact our customers have with us, both online and in person." https://en.wikipedia.org/wiki/Technology_evangelist

That's... not what technology evangelists do. Tech evangelists are the public face of a specific, often open-source, product/project. There are no tech evangelists for "all of Google". These are narrowly-defined roles, and they aren't empowered to be the public face of the company outside of that area.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#317
This is horribly frustrating and I'm sorry you are facing this.

The thing I have taken away from these continual Tell HN posts about Google acounts getting locked up because of 2FA is that the "something you have" factor needs redundancy. I now have my phone, and 4 yubikeys on my household's carkeys and a trusted friends and a family member's firesafe. These have also given me enough stress that when I visited home for the holidays I added to my aging parents' Google accounts with a handful of additional security keys to go with their SMS 2FA.

Personally I would rather have accounts which are secure and can be lost if I am not careful with my 2nd factors than one that has vulnerabilities that the whole internet can attempt to exploit, but I realize others do not have that same priority.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#318

Earlier quoted context omitted.

> I'm not in Europe, so I have no rights to my photos and nowhere to complain. If it makes you feel any better, Facebook doesn't care about the law and Europeans don't have any more luck than you do when it comes to this: https://ruben.verborgh.org/facebook/

An interesting read. Too bad the author made himself look like a kook in his correspondence, and thus ignoreable by Facebook. I'd like to see an actual lawyer try it and document the effort with similar rigor. I wonder what the response from FB would be.

Considering the GDPR doesn’t really give you the right to sue by yourself and that the best you can hope is for the regulator to fight for your case, I’m not sure the profession of the data subject would matter.

Keep in mind that the regulator who’s supposed to regulate them is corrupt and complicit so it’s very unlikely anything would work.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#319
post #124

Whenever one of these threads about Google (or Apple) come up, I am shocked at the lack of response from people working at those companies. It seems reasonable that this site would be where you'd find someone from a team that interacted with logic that OP is having trouble with. I'd expect to see something like a "hey, yeah, I know a guy on our team that might be able to get in touch with the team who maintains this.…

Developers at large corporations are strictly informed that they are not the public face of the company and can't do that. These aren't mom and pop developer shops.

You don't have to be mom and pop to give a crap about your reputation/perception.
Post reply on HN