4 ms·
One solution is to use Google Authenticator (or a similar compatible app) that generates the codes on-device so no data/SMS connection is needed.
by oddevan 10y ago
One solution is to use Google Authenticator (or a similar compatible app) that generates the codes on-device so no data/SMS connection is needed.
- gambler 10y agoYou still need your phone for that. If you're out of battery charge, you're temporarily locked out. If you loose your phone, you're locked out until you recover the number. If you can't recover the number for some reason, then what? People downplay the probability and importance of these issues, but the situations where you loose your phone are often the situations where you need access to your online accounts. One such situation can do far more damage than all the hacks combined. (For example, someone steals your backpack with your phone and wallet. Horror scenario: someone steals your backpack with your phone and wallet in a foreign country.) In short, loss of access must be considered as a tradeoff. Loosing anonymity due to phone-based 2FA is another issue that never seems to be considered in these discussions. Finally, phone-based 2FA discourages you from splitting your accounts. (It's a bit of a hassle even with one email. Imagine managing 5 or 6.)
- gilrain 10y agoThat's when you use the one-time passwords you generated and printed out in case of just such an emergency. Most (important) services I've enabled 2FA on make this an explicit step.
- epmatsw 10y ago2FA isn't limited to a single device. With 1Password, a TOTP code is available on my laptop, on my phone, on my watch, via an encrypted backup, etc. If you have access to a computer, you can access your second factor. That's not even counting paper backups as others have mentioned. Not sure how anonymity factors in here. How can typing a number into your phone to set up TOTP then typing the resulting numbers back into your already-authenticated account deanonymize you? Finally, yes, adding more security is a hassle. But if you're willing to add 5 seconds to your login on one account, I don't see why you'd be super against doing that for multiple accounts.
- deleted 10y ago[deleted]
- beilabs 10y agoUpgraded my phone (there was no way to export Google Authenticator profiles), lost 1 hour of my life getting them onto the new device.
- oddevan 10y agoOh, total agreement there. I've gone to apps that allow backups/exports (1Password currently) specifically because of this.