5 ms·
How to Enable Two-Factor Authentication on Amazon
- stuff4ben 10y agoAnyone know if you can use the authenticator app on more than one device? My wife and I share the same Amazon account and it would suck if I had to generate a token for her whenever she wanted to buy something. I don't want to have separate accounts because I don't want to pay for Prime more than once.
- fooey 10y agoPrime lets you share with members of your family https://www.amazon.com/gp/help/customer/display.html?nodeId=200444180 https://www.amazon.com/gp/help/customer/display.html?nodeId=... https://www.amazon.com/myh/households https://www.amazon.com/myh/households
- stuff4ben 10y agoThanks for that!
- taylorwc 10y agoThe simple way to do this is to use the authenticator app on each of your phones and scan the QR code at the same time, when you setup 2FA. Since it's time-based, your apps will always be in sync and showing the same code.
- michaelt 10y agoAnyone know if you can use the authenticator app on more than one device? Not only can you do that, you can scan the QR code in the image in the article and get the author's TOTP credentials in 'Google Authenticator'. The normal way to do phone-based 2FA is a QR code with data of the format "otpauth://totp/yourusername?secret=1F56D7AFLONGBASE64&issuer=Amazon" where the secret is the secret needed for TOTP [2] one-time code generation. As such, you can write down the secret (or print out the QR code) and scan it into other phones (or use it with tools like oathtool on linux) and they'll then generate identical codes to your main phone. Obviously, if you store your TOTP secret alongside your password or keep a copy somewhere that isn't safe, there's no point in using 2FA. And if people fuck this up too often 2FA users will start insisting we install twenty shit proprietary apps (one for steam, one for salesforce, one for symantec vip access....) and nobody wants that. So use your new powers with care! [1] https://www.eff.org/files/styles/large/public/2016/12/19/amazon_6.png?itok=vlg3tjCh https://www.eff.org/files/styles/large/public/2016/12/19/ama... [2] https://en.wikipedia.org/wiki/Time-based_One-time_Password_Algorithm https://en.wikipedia.org/wiki/Time-based_One-time_Password_A...
- ckcheng 10y agoPrinting out or otherwise saving the QR code (somewhere safe) is also the only way to have a backup code in case the device is lost or broken, because they don't provide one-time backup codes (unlike pretty much everyone else). Then again, it sounds like it's really easy to disable 2FA with just a simple phone call, so...
- rahimnathwani 10y agoI thought that only worked if the two devices scanned the code at the samw time.
- avens19 10y agoUse Authy instead of Google Authenticator. It allows multiple devices and backups
- bks 10y ago+1000 for authy.
- tedd4u 10y ago1Password [0] can store and share one-time passwords as well. [0] https://1password.com/ https://1password.com/
- OrwellianChild 10y agoDid not know this! A little cumbersome, but it works!
- ust 10y agoYes, there is oathtool that you can use on Linux (well, that's how it's called in Debian). I use the same, just type: oathtool --totp -b "key value" where your "key value" is your secret (same thing you would get if you scan QR code). And then you just need to keep the secret safe, and you can run it on as many devices you need. EDIT: just realized that michaelt had much more substantial comment.
- jjnoakes 10y agoDid Amazon recently merge the retail 2FA TOTP setup and the AWS 2FA TOTP setup? My normal retail 2FA TOTP code failed, but my AWS code worked for getting me into the retail 2FA settings (and also into the AWS settings). Which seems really odd to me. Because I know I had two separate 2FA TOTP seeds, one for AWS, one for retail. Anyone else notice anything like this?
- grapehut 10y agoThat's odd indeed. I have a different 2FA seed for my retail and AWS account, but I've never tried using the wrong one but it's conceivably they allow you to use either
- dazc 10y agoWell what's even more odd is that sometimes they do and sometimes they don't.
- jjnoakes 10y agoI wasn't able to use either though, as I said above. My retail 2FA TOTP failed for my retail account, but my AWS 2FA TOTP worked for my retail account (and for my AWS account). So something shady is going on.
- koolba 10y agoI've read horror stories about people who's personal and seller Amazon accounts were conflated. As such, I recommend keeping AWS and retail usage completely separate. Different email, different card, different name too if possible.
- dazc 10y agoI have had to log in on a different machine twice recently because of this.
- taylorwc 10y agoYes! I had 2FA set up on AWS when they announced it for retail, and after I set that up, my retail one was required to log into AWS.
- azinman2 10y agoI had MFA in my AWAS account using a hardware device. Just last night he battery finally wore out and I wasn't able to login. So I clicked the link saying I'm not able to login... and within 15 minutes amazon called me back to remove the MFA on the account. They asked for the email on the account, and to repeat back a code they emailed me. So in the end, after thinking I was all secure with this special hardware one time token generating device, it falls back to email + phone, both of which can get taken over easily.
- vollmond 10y ago> it falls back to email + phone, both of which can get taken over easily. How easy is it really for someone to intercept a phone call Amazon makes to your number? (edit: I'm not arguing, I really don't know)
- ohyeshedid 10y agoAttackers can social engineer the carrier to provision service onto a new sim card, which means they then have access to calling and sms.
- Ajedi32 10y agoSpecific example of this, for reference: https://medium.com/internet-creators-guild/getting-hacked-as-an-internet-creator-982d03637e86 https://medium.com/internet-creators-guild/getting-hacked-as...
- riffraff 10y agoin fairness, this is still much better than just needing access to your email to gain access.
- azinman2 10y agoBut this $40 device is a mirage.
- 10y ago
- dbg31415 10y agoAnd for Gmail * Google 2-Step Verification || https://www.google.com/landing/2step/ https://www.google.com/landing/2step/ And for everything else... * Turn On 2FA | Turn It On || https://www.turnon2fa.com/ https://www.turnon2fa.com/