Live data from Hacker News

Tell HN: It is impossible to disable Google 2FA using backup codes

news.ycombinator.com

331–340 of 352 posts

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#331
post #124

Whenever one of these threads about Google (or Apple) come up, I am shocked at the lack of response from people working at those companies. It seems reasonable that this site would be where you'd find someone from a team that interacted with logic that OP is having trouble with. I'd expect to see something like a "hey, yeah, I know a guy on our team that might be able to get in touch with the team who maintains this.…

I guess no one wants to be responsible, while at the same time having some of the highest paid employees of tech companies. No one wants to take the blame for the crap Google is pushing down people's throats. If Google started to actually deal with these things, instead of leaving it to "the algorithm", they probably would have lots of extra costs. Some number pusher needs to make their numbers, so nothing changes.

If one has the choice, one should never rely on Google for anything, unless one has a fetish for being victim of some algorithm with no way to change it. Most of their tooling is not worth that pain anyway and looks like a thin veil around user tracking. Never forget, that Google is an ads business company and that is how they make their money.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#332
I think that as a regular consumer there is not enough training on how to manage secrets. There is a lack of transparency about the implications of enabling/ignoring security settings. I should not have to be a certified security expert to manage my account properly.

The deeper issue is the situation is kafkaesque. Imagine explaining to a stereotypical elderly grandparent (with minimal computer experience) that you need to configure a 2FA TOTP on your mobile phone and save backup codes in a secure location. BTW don’t lose your phone or you will need to initiate a complex recovery procedure. Oh BTW you need to memorize a 20 character length passphrase along with the 30 other websites you use. Perhaps you could use a password manager, but it will need a 20 character length password and 2FA TOTP as well. Oh make sure you certify the password hashing function and iteration count follows current NIST-800 guidelines. It will need to reauthenticate periodically so don’t forget your password manager’s passphrase. Be sure to make it a sentence and sprinkle in a number and punctuation mark or two.

Oh Back to your original account: It might prompt you to log with a previously known authenticated mobile app at random. There is also a random AI agent scoring how secure your device is and can cancel you at anytime. Oh BTW if you want have extra protection buy this $30 hardware key we don’t advertise. Actually buy two hardware keys and keep one offsite just in case. Don’t use that key use this one. We might drop the other key for unknown reasons. The key might be exploitable since it has Bluetooth so keep it shielded in a faraday cage at all times.

The security policy can change at anytime with no warning or requirements notification update. Do not contact customer service, because you are not a customer but a product being sold at data mining auction. Instead you will need to plead your case on Twitter, Reddit, or Hacker News and pray someone working at the company sees it and is willing to help.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#333

Earlier quoted context omitted.

Allowing customer service to bypass customer auth requirements is just weakening your system. There will always be a CS agent who is bribed, makes a mistake, etc. And besides, the agent following a flow chart has no better info to make the decision on than a computer. Instead the auth requirements should be sane from the start, well publicised, and make a good tradeoff between letting bad guys in vs locking the real…

> Allowing customer service to bypass customer auth requirements is just weakening your system I disagree, in regulated industries such as banking this is a solved problem. A combination of onshore staff, good career prospects, pay and working conditions and audit logs means I haven't heard stories of bank insiders breaching into accounts to steal. I'm sure it happened but nowhere near as frequently as fraudulent SIM…

I suspect that the level and sophistication of attacks on the banking sector is far lower than equivalent attacks for data/accounts.

In general, if you break into someones bank account and transfer money out, that money can be traced by authorities. In almost all cases, that money is recoverable by the government, even if individual banks like to shrug and tell the customer it isn't recoverable.

If you break into someone's email and steal their private info, it can't be traced. That makes the latter much more attractive.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#334

Earlier quoted context omitted.

My laptop, which contains all this secret information, is way, way more secure than my phone. There's the boot decrypt password, login password, then gpg password. My phone has ... A pin. And besides, this is fine as an archived backup in case someone loses their phone. It just so happens it's faster for me to xsel the output of oathtool than it is to unlock my phone, open app, select account, and remember code, esp…

Android phones are encrypted by default, but for encryption, they use the same PIN as your lock screen. There's some command you could run to replace it with a strong password while keeping screen lock PIN simple, but it didn't work for me last time I tried.

Surely the data is encrypted using a 128 bit key or better, and the key is stored on some secure enclave which rate limits PIN entries, is it not?

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#335
post #293
post #124

Whenever one of these threads about Google (or Apple) come up, I am shocked at the lack of response from people working at those companies. It seems reasonable that this site would be where you'd find someone from a team that interacted with logic that OP is having trouble with. I'd expect to see something like a "hey, yeah, I know a guy on our team that might be able to get in touch with the team who maintains this.…

> I'm hoping OP got a private message. I'm not. I have the same problem -- or I will if I ever lose my 2 factor identification keys, which are held by Authy NOT by myself. I always assumed that my one-time-codes (which I have carefully secured and protected) would be usable to regain control over my account. If that's not the case, then I want Google to fix it for EVERYONE.

Always back up the key/QR code before importing it into any app in case that device blows up.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#336

This is why I use SMS as my second factor for my Google account. Much harder to lose. It could be vulnerable to sim swapping attacks, but I consider Google locking me out of my own account a more likely threat (and frankly I'm probably not a high-profile enough target for anyone to bother with that, and in any case they'd still need my password).

I mostly agree with you, but be careful how often you apply this logic. People who are not already a target can be just as useful, for example when needing to frame someone else for a crime. I mean, who'd care about nicoburns if they disappeared, right?

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#337
post #195

Google's 2FA is an absolute embarrassment. Super annoying that Google hasn't yet done more to improve it. See also: https://news.ycombinator.com/item?id=33895836

I gave a big long speech on security to my company, mentioned that SMS 2FA was junk and to use authentication apps instead, then made 2FA mandatory on our Google accounts… only to find out that you can’t even enable good authentication without enabling SMS 2FA first. Absolute madness.

Actually there is a way, but instead of enabling SMS you have to enable U2F first, then it will allow you to turn on TOTP. If you don't have a U2F-capable device then you can use a program like softu2f that emulates one on your computer, even if it's just temporary in order to get TOTP turned on.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#338

I had much the same problem with AWS. Their 2FA login was not working - my logins were rejected. I think I needed to resync. The resync pages were not working. When 2FA breaks, for whatever reason, there is a form you use to let AWS know. You cannot send a message - only a phone number. AWS will call you back. Where I was at the time, a phone number was not available. That was it. End of the road. 2FA not working, co…

> I am very unlikely to be hacked

More likely to be framed for someone else's crime (maybe someone uses your AWS account to hack others), because, well, who would miss casenmgreen, right? There are non-obvious reasons people should still use 2FA even if they have "nothing to hide".

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#339

Microsoft Authenticator syncs across all instances so you just have to log in to a new Authenticator on the new phone and the codes are there. (I think it uses OneDrive). I am sure that is less secure than a local only copy but this may be least bad of all alternatives. You might even give a trusted person a login and have it on their phone so you can use theirs in an emergency.

How do you login to the authenticator itself? If it's MS-account-based doesn't that itself requires 2FA and you thus have a chicken & egg problem?

It doesn't need a login... only the syncing part uses your account.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#340

Earlier quoted context omitted.

I have 2FA backup codes! They let me log into my account! But using only backup codes, I cannot remove the lost 2FA. So now I have 8 consumable backup codes and after that I will not be able to access the account. To remove the lost 2FA, I need a fresh 2FA code. No alternatives given.

The solution (which is too late to help you with now) is to take a photo of the QR code that is first showed to you when you originally set up 2FA. Keep that safe somewhere and you can always go back. For anyone who is freaked out by this and currently still has access to their google Authenticator app, I suggest exporting all your codes to a big QR code in the app and keep that safe (maybe print it out).

So if my MFA-secured Google account is working fine right now, is the best course of action to remove MFA, then re-add it with this QR picture and/or jotting down the key trick?
Post reply on HN