Live data from Hacker News

Tell HN: It is impossible to disable Google 2FA using backup codes

news.ycombinator.com

51–60 of 352 posts

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#51
post #16

> What am I supposed to do in this situation? This. Support systems in the world post computers eating everything is basically HN posts.

When I had a self-inflicted issue with my non-Google email service I context support and has the issue resolved within a couple hours.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#52
post #21

TOTP is bad 2FA. Google supports U2F security keys. Use them.

> TOTP is bad 2FA

How so? The only downside is that you have to glance up and make sure you're on a google.com domain before entering it, in exchange for which you get massively simpler implementation, a wider variety of options, and the ability to back up token if you really want.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#53
post #16

> What am I supposed to do in this situation? This. Support systems in the world post computers eating everything is basically HN posts.

Maybe the next million new jobs is just rebuilding a reasonable level of customer support at all tech companies, funded by modest usage fees. $5/mo, $50/yr, or $500 for lifetime guaranteed permanent access so no lockouts are possible, I would definitely pay for Gmail or an equivalent service. And there are people who I’m sure would pay much more.

Another short term option: $500-1000 right now to get a couple hours of support to unlock an account.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#54
post #21

TOTP is bad 2FA. Google supports U2F security keys. Use them.

If you lose your U2F security key, are you sure you'll be able to remove it from your Google account? Because what I'm experiencing right now is that they support TOTP and you can't remove it if you lose it..

Specifically you need multiple registered keys, to prevent this current situation.

But yeah, this is why I dislike 2FA. There are clear security benefits, but it comes with the extreme downside of "what you know is not sufficient".

When it's e.g. a corporate-controlled account and your IT desk can just reset it to "password123!" to let you back in, it's quite a good trade-off. When it's your main email, i.e. your primary online identity, losing access is kinda a big deal, and Google has famously bad support.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#55
post #36

Earlier quoted context omitted.

If you lose your U2F security key, are you sure you'll be able to remove it from your Google account? Because what I'm experiencing right now is that they support TOTP and you can't remove it if you lose it..

Yes, I lost a key 6 months ago and removed it from my Google account. I have multiple other U2F keys also registered.

Having those extra registered I think is the missing bit. The OP could have also registered additional 2FA methods, but didn’t thinking backup codes were as advertised.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#56

Earlier quoted context omitted.

Good idea! That had never occurred to me before this incident.

Really? At what point do we blame the victim because this is so obvious to me. I keep the TOTP and only sometimes keep the backup codes I avoid the issue created from losing my phone, because the next device can generate codes immediately by importing or scanning the TOTP I also don’t call it “2 factor” I just call it “one time passcode”

Nothing is "obvious" in tech any more, because there is simply too much. Two "tech savvy" people will often each have things they think is "obvious" that the other isn't familiar with.

And this isn't even a good example of something that is "obvious" to some people, because Google makes it very, very clear that saving the QR code is NOT a backup option. It is labeled only as a mechanism to transfer to a new phone, so one has no reason to believe that it's non-ethereal. Further, the app disallows taking a screenshot. You have to point a camera at your phone. It's mind-blowing to suggest that it might be appropriate to blame the user for not doing this.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#58

To avoid a situation like this, I keep backup screenshots of the 2FA QR codes stored off-line on an encrypted USB drive.

I do the same. But lately, for some but not all sites, I've been putting 2FA codes in Bitwarden and using their app to fill the codes instead of using Authenticator apps.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#59

Earlier quoted context omitted.

go to https://myaccount.google.com/security?hl=en Then, https://myaccount.google.com/signinoptions/two-step-verifica... There you can see Authenticator app. (I am doing this on desktop. Not sure about phone)

Thanks for the followup. I'm also on desktop. When I click the second link, I'm forced to reauthenticate. During that reauthentication my only option for 2-factor auth is... a valid 2FA code. Backup codes are not allowed. I suspect since you originally logged in with a 2FA code (I'm guessing), your session is marked as "recently two factor verified", and when I logged in with a backup code, I was not marked the same…

since you told me I am using a I tried without 2FA code but with backup-code

> When I click the second link, I'm forced to reauthenticate.

Here, I am being asked my password.

Then get that page.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#60

Oh my god. 2-Step verification on your Google Account is actually less secure than not using it at all. I just posted about something similar maybe 3 months ago?[1] > I kid you not. Google's actual official answer to this is... create another account![1][2][3] > Edit: Now that I have your attention: > PSA: Go create "Backup codes" for your Google Account in your 2-Step Verification settings. > [1]: https://support.go…

I have 2FA backup codes! They let me log into my account! But using only backup codes, I cannot remove the lost 2FA. So now I have 8 consumable backup codes and after that I will not be able to access the account. To remove the lost 2FA, I need a fresh 2FA code. No alternatives given.

The solution (which is too late to help you with now) is to take a photo of the QR code that is first showed to you when you originally set up 2FA. Keep that safe somewhere and you can always go back. For anyone who is freaked out by this and currently still has access to their google Authenticator app, I suggest exporting all your codes to a big QR code in the app and keep that safe (maybe print it out).
Post reply on HN