3 ms·
Be careful using 2FA on CF. I got locked out of my account because I reformatted my phone and hadn't kept backup codes. That's my fault, not CF's. They wouldn't
by kolp 9y ago
Be careful using 2FA on CF. I got locked out of my account because I reformatted my phone and hadn't kept backup codes. That's my fault, not CF's. They wouldn't accept email verification or uploading a html file to the root of my domains to grant access.
But here's the kicker: Cloudflare were happy to grant access if I could recall some previous name server history for some of my domains. Information that is in the public domain and can be purchased as a report.
- woogley 9y agoCustomer Support (well, humans in general) is the biggest threat to security, unfortunately .. :( This one comes to mind, I think I remember an Amazon-related story along the same lines .. https://www.macrumors.com/2012/08/05/apple-support-allowed-hacker-access-to-reporters-icloud-account/ https://www.macrumors.com/2012/08/05/apple-support-allowed-h...
- ce4 9y agoYou may not even need backup codes. Just save a copy of the google authenticator setup QR code. It's just email/key, when decoded.
- deleted 9y ago[deleted]
- jgrahamc 9y agoThanks for writing this. I will talk to the support team about it.