4 ms·
What I recall reading over the last year is that: - phonelines can be hijacked (this article) - DNS can be hijacked in a similar manner - SMS can be hijacked
by nchelluri 10y ago
What I recall reading over the last year is that:
- phonelines can be hijacked (this article)
- DNS can be hijacked in a similar manner
- SMS can be hijacked (for 2FA via text message)
I guess 2FA using an authenticator app is the way to go for now. Do you guys agree with the removal of backup phone numbers recommended here? Seems reasonable to me but scary; I've lost my phone(s :( ) before. I do have backup codes generated though.
- AdmiralAsshat 10y agoThe problem with the backup codes is that I have so many now. Pretty much a list of codes for every account I have 2FA enabled on (about a dozen). If I actually printed them out and kept them in my wallet, my wallet would be overflowing by now. Authy has been a great improvement over Google Authenticator for me. I primarily used it when I migrated phones for the upteenth time, but were I to lose my phone, I could also restore the database on my tablet in the meantime and use that instead. The prospect of doing so does leave me a little concerned, however, because my phone has full-disk encryption enabled while my tablet does not.
- toomuchtodo 10y agoPut your recovery codes on an offline SD card somewhere safe in your house. I keep mine in a literal safe.
- BinaryIdiot 10y agoSD cards don't last forever. I've had 3 different cards seemingly randomly corrupt in different devices on me. I don't trust them to hold anything important for long.
- toomuchtodo 10y agoPrint them out on paper then. Paper stored properly will outlive you and any services you need recovery codes for.
- kej 10y agoI find it far simpler to make a secure backup of the authenticator QR code than it is to save all of the one-time backup codes.
- krrrh 10y agoI wish it were possible to print a sheet of QR codes for all your 2FA accounts in Authy. The in-app backup seems to work well, but an easy offline backup would make me a lot more comfortable.
- CobrastanJorji 10y agoI keep them in LastPass, along with the passwords themselves. That does make LastPass a single point of failure for me, but I know myself and know that I'm not gonna remember where I put all of my one time recovery codes.
- vijayp 10y agoYeah, I'm also scared of LastPass being a SPOF. While LastPass does do a good job, no one is perfect, and the cost of having my account compromised is really high I'm now leaning towards encrypting backup codes with a passphrase and putting the encrypted blobs in LastPass. I haven't actually done this but as long as I don't forget the second passphrase, that might work…
- ProblemFactory 10y ago> If I actually printed them out and kept them in my wallet, my wallet would be overflowing by now. It seems unnecessary (and easy to lose) to carry them around in your wallet. I print them out, and leave them in an envelope at my parents' house.
- dnr 10y agoI recently turned on 2FA on a bunch of accounts (nine total) and ran into the same problem. My solution was to save the initialization QR codes and print them on a piece of paper (actually three copies, stored in separate locations). This involved a bunch of screenshotting and messing around in gimp and was in general a big pain. But if my phone dies, restoring my 2FA setup will be much simpler than using backup codes: I just have to scan codes; the account providers aren't involved at all. (I do also keep a few backup codes for the most important accounts in my wallet.) I know Authy can back up 2FA state to their own cloud, but it's unclear how secure this is: they let you restore codes onto a new phone with the same number, and apparently even to a brand new phone (https://www.authy.com/phones/change/ https://www.authy.com/phones/change/). So it seems like stealing a phone number would allow an attacker to steal 2FA codes stored in Authy. (What I'd really like is a TOTP app that let me back up its state into a single giant QR code or a small file that I could print out in hex and scan+ocr later.)
- AdmiralAsshat 10y ago>So it seems like stealing a phone number would allow an attacker to steal 2FA codes stored in Authy. You're required to set a password on your Authy database before you can start adding tokens to it. So when I transferred my Authy database to a new phone (had to send in the old one for a replacement), I had to confirm the password before it would sync to the new device. Authy also bugs you about once a month to confirm your password phrase to make sure you don't forget it. Additionally, you can set a PIN that Authy will prompt you for any time you try to open the app. I have that set, as well, so that even if someone should get past my lockscreen, they can't reach my 2FA tokens without another PIN.
- twr 10y ago> You're required to set a password on your Authy database before you can start adding tokens to it. That's not true. Passwords in Authy are for backup, which is optional. Backup synchronizes offline TOTP secrets between paired devices. Only the offline TOTP secret is encrypted; the token name is not. "Authy Account" secrets, the ones created by the Authy API, used by Coinbase, Cloudflare, et cetera, are always stored remotely, and can be restored without-password to anyone with possession of your phone number and email account. I wrote about this a little over here: https://news.ycombinator.com/item?id=12603380 https://news.ycombinator.com/item?id=12603380
- RubyPinch 10y ago2FA requires a phone number (for google accounts)
- aianus 10y agoIt does not. I had TOTP 2FA only on my last work account and it was company policy not to add phone numbers for security reasons.
- RubyPinch 10y agohttps://i.imgur.com/SCxAk0V.png https://i.imgur.com/SCxAk0V.png is what I get if I try to add two fac to my account, doesn't seem to be any way around it
- aianus 10y agoThis is what I see on my personal GApps account: http://i.imgur.com/YHAOFlZ.png http://i.imgur.com/YHAOFlZ.png TOTP 2FA with no recovery options. Maybe they changed their policies since 2014 :/