Tell HN: It is impossible to disable Google 2FA using backup codes
81–90 of 352 posts
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#82Earlier quoted context omitted.
Just tested it. - Private Browser Window - Log in using backup code - can change auth app without another login.
So weird, because I cannot! Maybe it's because I haven't used a 2FA code on this account in the past year? I typically stay logged out of my Google account and just have the email forwarded to another provider.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#83And that is why I utilize the "very secure" flow of also keep the original qr codes ... in a keepass vault, but still. Most of the security is theater. On the other hand I think that every tech savvy person should at least try to keep the TOTP seeds.
I would love to save the QR codes, but Google bans screenshots in the Authenticator app.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#84Earlier quoted context omitted.
I have 2FA backup codes! They let me log into my account! But using only backup codes, I cannot remove the lost 2FA. So now I have 8 consumable backup codes and after that I will not be able to access the account. To remove the lost 2FA, I need a fresh 2FA code. No alternatives given.
The solution (which is too late to help you with now) is to take a photo of the QR code that is first showed to you when you originally set up 2FA. Keep that safe somewhere and you can always go back. For anyone who is freaked out by this and currently still has access to their google Authenticator app, I suggest exporting all your codes to a big QR code in the app and keep that safe (maybe print it out).
I keep all my 2fa secrets in pass for this reason. Never lose access again!
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#85Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#86Earlier quoted context omitted.
Maybe the next million new jobs is just rebuilding a reasonable level of customer support at all tech companies, funded by modest usage fees. $5/mo, $50/yr, or $500 for lifetime guaranteed permanent access so no lockouts are possible, I would definitely pay for Gmail or an equivalent service. And there are people who I’m sure would pay much more. Another short term option: $500-1000 right now to get a couple hours of…
High fees mean that most people even in places like the USA cannot afford it. Would be nice to have modest customer service options for everyone.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#87Earlier quoted context omitted.
Auhenticator has an option to generate back up codes. it creates one or two QR codes that you can scan in a new Authenticator app and it will clone all of your accounts.
Good luck trying to save those QR codes, though. I had to resort to pulling out my DSLR to take a photo of my phone with them. All screenshot/print/save functionality is disabled when you have the codes up on your phone. You need an actual camera on a second device to save them in most cases.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#88I am sure that is less secure than a local only copy but this may be least bad of all alternatives.
You might even give a trusted person a login and have it on their phone so you can use theirs in an emergency.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#89> What am I supposed to do in this situation? This. Support systems in the world post computers eating everything is basically HN posts.
Maybe the next million new jobs is just rebuilding a reasonable level of customer support at all tech companies, funded by modest usage fees. $5/mo, $50/yr, or $500 for lifetime guaranteed permanent access so no lockouts are possible, I would definitely pay for Gmail or an equivalent service. And there are people who I’m sure would pay much more. Another short term option: $500-1000 right now to get a couple hours of…
Also, I think it's unreasonable to accept "support just sucks now" as a norm - consumer protections exist to shield us from BS like this and the US has been far too lax in flexing those muscles lately.
Re: Tell HN: It is impossible to disable Google 2FA using backup codes
#90> What am I supposed to do in this situation? This. Support systems in the world post computers eating everything is basically HN posts.
Instead the auth requirements should be sane from the start, well publicised, and make a good tradeoff between letting bad guys in vs locking the real owner out.
There should be options beforehand to adjust the balance (eg. enabling 2FA).
To prevent lockouts, there should be some time-based weakening. Eg. if you are trying to access your account, and know only some of the required auth info, and have been unable to for 1 week, and, after blasting messages to every associated recovery phone/email address nobody else does either, then you should be allowed in.
That solves the classic "my house burnt down with my phone in. All I have is my email and password, but I have no devices left, no backup codes, no access to my phone number, nothing" case.