Live data from Hacker News

Tell HN: It is impossible to disable Google 2FA using backup codes

news.ycombinator.com

81–90 of 352 posts

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#81
I lost a bunch of email addresses because they decided to start enforcing the use of security answers even when I had the correct password. Then I lost some more email accounts because I logged in from different locations (I moved) and they thought I was a fraud, even though I was able to confirm using the backup email address. I'm fairly concerned that eventually I'm going to lose all my email addresses due to these increasingly draconian requirements that are sprung upon us.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#82

Earlier quoted context omitted.

Just tested it. - Private Browser Window - Log in using backup code - can change auth app without another login.

So weird, because I cannot! Maybe it's because I haven't used a 2FA code on this account in the past year? I typically stay logged out of my Google account and just have the email forwarded to another provider.

[deleted]

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#83

And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.

I would love to save the QR codes, but Google bans screenshots in the Authenticator app.

Not in iOS, apparently. I recently printed out my QR codes by screenshotting Authenticator's export screen on an iPhone. I just tested a moment ago and it still works.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#84

Earlier quoted context omitted.

I have 2FA backup codes! They let me log into my account! But using only backup codes, I cannot remove the lost 2FA. So now I have 8 consumable backup codes and after that I will not be able to access the account. To remove the lost 2FA, I need a fresh 2FA code. No alternatives given.

The solution (which is too late to help you with now) is to take a photo of the QR code that is first showed to you when you originally set up 2FA. Keep that safe somewhere and you can always go back. For anyone who is freaked out by this and currently still has access to their google Authenticator app, I suggest exporting all your codes to a big QR code in the app and keep that safe (maybe print it out).

You can do this, or you can write down the secret (Click to get the text), and use oathtool to generate codes rather than google's auth.

I keep all my 2fa secrets in pass for this reason. Never lose access again!

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#86

Earlier quoted context omitted.

Maybe the next million new jobs is just rebuilding a reasonable level of customer support at all tech companies, funded by modest usage fees. $5/mo, $50/yr, or $500 for lifetime guaranteed permanent access so no lockouts are possible, I would definitely pay for Gmail or an equivalent service. And there are people who I’m sure would pay much more. Another short term option: $500-1000 right now to get a couple hours of…

High fees mean that most people even in places like the USA cannot afford it. Would be nice to have modest customer service options for everyone.

That’s expensive.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#87
post #67

Earlier quoted context omitted.

Auhenticator has an option to generate back up codes. it creates one or two QR codes that you can scan in a new Authenticator app and it will clone all of your accounts.

Good luck trying to save those QR codes, though. I had to resort to pulling out my DSLR to take a photo of my phone with them. All screenshot/print/save functionality is disabled when you have the codes up on your phone. You need an actual camera on a second device to save them in most cases.

Not true, I just did it a few weeks ago when moving to a new phone. Just screenshotted the backup QR code and when I got my new phone later I used the screenshot.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#88
Microsoft Authenticator syncs across all instances so you just have to log in to a new Authenticator on the new phone and the codes are there. (I think it uses OneDrive).

I am sure that is less secure than a local only copy but this may be least bad of all alternatives.

You might even give a trusted person a login and have it on their phone so you can use theirs in an emergency.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#89
post #16

> What am I supposed to do in this situation? This. Support systems in the world post computers eating everything is basically HN posts.

Maybe the next million new jobs is just rebuilding a reasonable level of customer support at all tech companies, funded by modest usage fees. $5/mo, $50/yr, or $500 for lifetime guaranteed permanent access so no lockouts are possible, I would definitely pay for Gmail or an equivalent service. And there are people who I’m sure would pay much more. Another short term option: $500-1000 right now to get a couple hours of…

Maybe, alternatively, this is just an indicator that ad-based "free" services aren't really realistically economical and we should all be paying google 50c/mo for our email addresses.

Also, I think it's unreasonable to accept "support just sucks now" as a norm - consumer protections exist to shield us from BS like this and the US has been far too lax in flexing those muscles lately.

Re: Tell HN: It is impossible to disable Google 2FA using backup codes

#90
post #16

> What am I supposed to do in this situation? This. Support systems in the world post computers eating everything is basically HN posts.

Allowing customer service to bypass customer auth requirements is just weakening your system. There will always be a CS agent who is bribed, makes a mistake, etc. And besides, the agent following a flow chart has no better info to make the decision on than a computer.

Instead the auth requirements should be sane from the start, well publicised, and make a good tradeoff between letting bad guys in vs locking the real owner out.

There should be options beforehand to adjust the balance (eg. enabling 2FA).

To prevent lockouts, there should be some time-based weakening. Eg. if you are trying to access your account, and know only some of the required auth info, and have been unable to for 1 week, and, after blasting messages to every associated recovery phone/email address nobody else does either, then you should be allowed in.

That solves the classic "my house burnt down with my phone in. All I have is my email and password, but I have no devices left, no backup codes, no access to my phone number, nothing" case.

Post reply on HN