14 ms·
Disabling Google 2FA doesn't need 2FA if you're already logged in
- verandaguy 6y agoI'm not defending this, but this could be seen as a way to increase usability — if you lose your 2FA token but you're still logged into a session, you can still disable 2FA and potentially re-add the token. Obviously though, that excuse becomes an exploit the moment you change your tone of voice, so there's that.
- ocdtrekkie 6y agoThat's what backup codes are for, or backing up your 2FA app. Enabling 2FA is an acknowledgement that you expect to be responsible for maintaining access to your second factor: It's reasonable to require you still have it when you shut that off. That being said, Google is far from being unique in this issue.
- Wowfunhappy 6y ago> Enabling 2FA is an acknowledgement that you expect to be responsible for maintaining access to your second factor. On the other hand, articles all over the place increasingly recommend it to everyone.
- loktarogar 6y ago> Enabling 2FA is an acknowledgement that you expect to be responsible for maintaining access to your second factor Maybe to you and me, but to everyone else it's just a recommended (and in many cases forced) method to gain access to your own account. My mum isn't making a pledge to always have her phone with her, she just doesn't want her email stolen
- Koenvh 6y agoIn theory, yes, and I think most people here would store their backup codes properly. However, there are many people who don't store them properly, and don't think about it until it's too late. They lose their token, break their phone, or lose access in one of the many other ways. Sure, you can say "tough luck", but then people will complain, reasonable or not, and Google probably doesn't want that to happen. I think this is a reasonable compromise when it comes to security and usability.
- sceutre 6y agoIf I have 15 sites in google authenticator is it such a win that 1/15th of them will allow me to reset without needing the second factor? Backing up the app or backup codes seems needed to scale to widespread 2FA use.
- kkarakk 6y agoi know my life was flashing before my eyes when i logged out of my old phone and then my new phone asked for 2FA coz like a dumbo i stored the 8 codes in google drive...
- mtgx 6y agoThen why even bother with 2FA? Just for the "safety feels"? The point of 2FA is that someone that gets access to your account, such as by saying "they broke their phone and need access again", shouldn't be able to do it without the 2FA code. I'm not sure if it's still the case now, but it must have been like at least a 4-5 years period in which auth codes/tokens were basically useless because Google would automatically fallback to SMS codes. Same issue - why offer with other "stronger" 2FA methods, if all of them will fallback to SMS?
- Wowfunhappy 6y agoDisabling Google 2FA doesn't need 2FA if you're already logged in. The author's core issue is that once a machine has logged in, it is considered trusted for a period of time. Google should probably make this configurable for particularly security-conscious users (assuming it isn't already), but it strikes me as a perfectly reasonable default.
- pat2man 6y agoAlso Google requires you to re-enter your password. The fact that his browser was set up to auto enter passwords without any prompt (not the default) and the fact that his machine was open to the internet means that Google probably had enough security here.
- ryanianian 6y ago> Google requires you to re-enter your password And it does it at unpredictable and often inconvenient times. The periodic check is undeniably good for security. But google's impl doesn't give the user any indication of when it will happen, and it doesn't allow the user to preemptively re-auth to restart the clock. This means that I always end up having to re-auth right in the middle of sharing my screen or right when I'm trying to quickly find a thing and in a state of flow. On good days 1pw is already unlocked and can autofill the login. On bad days I have to manually unlock 1pw and/or hunt for the pw and hope my colleagues don't see my other saved sites and then hope that I don't accidentally paste my password in a doc or something - let alone worry about destroying what was on the clipboard before google decides to do this. Security and convenience are always at odds, but that doesn't mean you need to give a middle finger to basic UX in the name of security.
- andrewxdiamond 6y agoWhy cant you just log out and back in to preemptively trigger the login?
- ryanianian 6y ago
- pat2man 6y agoThis is the same issue that plagues SMS 2FA. Services constantly treat SMS as 1FA so by sim swapping someone you can get access to their account. If SMS is truly used as 2FA, and is part of MFA, it is a much more reasonable solution. These days most services should probably gather three forms of authentication and require at least two to do anything. Username/password, email, and SMS at a very minimum, with the ability for users to opt in to QR codes or FIDO devices. It is a good thing that most devices will be shipping with platform FIDO support soon, will make some of this a lot more bearable.
- CodesInChaos 6y agoIf the compromise of the machine could be turned into a permanent compromise) with the ability to manipulate the UI (which seems likely on mainstream Desktop OSs, you could use that to intercept the 2FA token on the next login, and use it to turn off 2FA. The only way to prevent that would be making the token purpose bound, and displaying that purpose on the trusted 2FA device.
- coder543 6y agoOr by using a U2F device, which is designed to prevent spoofing.
- frei 6y agoU2F doesn't protect you from an untrusted machine, it protects you from untrusted websites. https://security.stackexchange.com/questions/157756/mitm-attacks-on-fido-uaf-and-u2f https://security.stackexchange.com/questions/157756/mitm-att... The security model relies on the browser validating the origin.
- CodesInChaos 6y agoI don't think there is a way around "displaying that purpose on the trusted 2FA device." if you want to protect against a compromised computer. Domain binding protects you from fishing, but still relies on the user's computer, including the browser, being secure. So it doesn't help here.
- anon102010 6y agoThis is 100% false. You need to have a 2FA authenticated connection or be on a 2FA authenticated device within validity period to change 2FA settings. You can elect to have 2FA not remember the device you have logged into as well (ie, the remember this device for 30 days option) if you are particularly paranoid. The headline should say - You can disable Google 2FA on 2FA authenticated connections without re-authenticating. This is a fantastic balance in terms of security and usability. I switched iphones and google authenticator did not bring my 2FA's over, I got on my machine that had already authenticated and setup a new 2FA. Whew. Other systems were MUCH much harder to restore AND you could still get around 2FA but now with human involvement (social engineering risk). I've worked govt jobs with security so "tight" that everyone got the workarounds worked out - the social engineering would be as easy as I need reset for user X and they stopped even checking who anyone was the volumes were so high. The loss in security is minimal here, and the loss is controllable, and it reduces pressure on other reset approaches (seriously, if you lock yourself out of google you will REALLY want to get back in).
- close04 6y agoWhile it can help you get out of a bind if you misplaced your 2FA token/app, changing any security parameters (especially when reducing security)should require entering all authentication methods enabled for the account. Imagine how changing a password requires the old password, not just the new one. At the very least they could make it configurable, let the user decide if they want to be able to turn off 2FA without being asked for a confirmation token.
- RcouF1uZ4gsC 6y ago> I switched iphones and google authenticator did not bring my 2FA's over, I have lost 2 FA's on other services via that means as well. I think it is easy if you have cloud backup on your phone that you think that you can just wipe your old phone and sync your new phone and you will be all set. Google Authenticator doesn't work like that.
- guiambros 6y agoGoogle Authenticator made it slightly easier with the "Transfer Account" functionality, but still requires access to your old device, so it doesn't help if your already wiped it. I personally would prefer backups would transfer all configuration, but understand this would be an additional risk. Of course you can just use Authy, although it does introduces the risk of an attacker compromising your phone number.
- RcouF1uZ4gsC 6y ago>This would seem security 101, but apparently in order to make it easier for users, and to avoid them having to type their 2FA token in frequently, it is sufficent to have logged in recently to a machine to satisfy to Google that you can make security level changes, if you know the password. In other words, it's 2FA, unless you're logged on, in which case it's 1FA. The author is wrong. It is still 2 Factor. The two factors are the password (something you know) and something you have (the session token on the machine). If your logged-in machine is compromised as was the case here, you are already in a world of hurt. Your bookmarks are visible. You could likely get the passwords by going to a bookmark site, allowing the password manager to autofill, and looking at the password fields using the browser developer tools. There are security vs ease of use tradeoffs. Making everything harder by assuming that even a trusted machine is compromised would result in much more of a painful user experience and would lead people to abandon password managers and 2 Factor. See for example UAC and Windows Vista.
- kogir 6y agoTo be fair, remote access to the user’s account on the machine is game over, regardless. Knowing the password and having access to a trusted (don’t ask again for 30 days checkbox) device is possession of two factors. Google offers stricter validation in the form of advanced protection, which isn’t so easily disabled. https://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/
- frei 6y agoI just enrolled in advanced protection, and was then able to unenroll without 2FA re-auth.... I agree that requiring 2FA re-auth on trusted devices to disable 2FA would be a terrible default for users with only one method, but Advanced Protection should do more.
- ec109685 6y agoYeah, why wouldn’t the hacker wait until the user logged into their 1Password manager start stealing passwords that way?
- lordlimecat 6y agoIt is easier to trick the user into starting a remote session Than it is to convince them to unlock their vault. It's somewhat like getting someone to invite you into their home VS convincing them to open their fire safe in front of you. One of those sets off alarm bells.
- lordlimecat 6y agoRemote, unprivileged access is not game over and its ridiculous to make that claim in the world of cloud tenants.
- siraben 6y agoAs many comments have pointed out, this is only when one is already logged in. Personally, I set Firefox to clear persistence of any kind when the browser is closed so that I always will need 2FA to log in my Google account.
- tumetab1 6y agoSo a session token can downgrade an account from 2FA to 1FA. I'm pretty sure Google forgot to inform users about this new feature.
- eldridgea 6y agoA session token is "something you have" and paired with the password being "something you know" it's still 2fa. Whether making that conversion or allowing disabling of 2fa without requiring the user to do a full authentication with both their password and a code is debatable. But 2fa is two of something you "know", "have", or "are" which password + session token meets.
- Andrew_nenakhov 6y agoIt actually drives me mad when services turn on 2FA when I absolutely don't want them to. I had a Google account with 2FA disabled, because I planned to go abroad where it would be impossible or very costly to receive SMS. And you guess what? When I tried to log in there, Google demanded that I send in code! I was able to circumvent it only by VPNing to my office and logging in from there.
- deleted 6y ago[deleted]
- yuliyp 6y agoThose situations are tricky: that type of login looks very much like a compromised account.
- Andrew_nenakhov 6y agoIf a user, in clear and sober mind, disables 2FA, he accepts the risk of his account being compromised.
- jsnell 6y agoIt's not just the user's choice to make. They are not risking just themselves, they're risking all the other users that could be harmed by the compromise of their account. The bitcoin scam videos posted on YouTube, the fake Facebook likes, the spam sent to random Xbox accounts, the fraudulent credit card charges done on in-app purchases in an attacker-controlled app that get charged back, the Mugged in London scams sent to their email contacts, etc. What you're saying is basically "if I don't wear a mask during a pandemic, I accept the risks of catching the virus". No. You are opting an indefinite number of other people into transitively catching the virus despite not accepting that risk.
- Andrew_nenakhov 6y ago> if I don't wear a mask during a pandemic, I accept the risks of catching the virus No, your metaphor is rather flawed. Better one would be "if I don't see anyone during a pandemic, I do not need to wear a mask." If anyone hacked my email account, I would certainly be harmed, with a very low probability. However, Google made sure that I was _certainly_ harmed by it: for quite some time I could not access a vitally important information, which caused me significant stress. Apologists such as you miss the point: I specifically foresaw the situation, and disabled 2FA to avoid it. And still, Google decided that it knows better. Well, that was before I decided that I know better and deGooglified my life. Chrome->Firefox, Google.com->DDG, you know the drill.
- googlepathetic 6y agoGoogle use Bluetooth to track your Android phone even when Bluetooth is turned off... so what do you expect from this company? Google only want to extract money from your pocket.
- tengbretson 6y agoGood! I walked into a lake with my phone and Google Fi couldn't send me a new one for a week. Luckily I had a valid session that I could still use to disable 2fa, otherwise I wouldn't have been able to work for a week.
- gundmc 6y agoDiscussed previously: https://news.ycombinator.com/item?id=23728390 https://news.ycombinator.com/item?id=23728390
- jeffbee 6y agoAnother thing you can do without 2FA on a device that is already authenticated is generate an app-specific password which is like a persistent backdoor to your account that degrades your security until you either revoke the ASP or change your main password (which automatically revokes all ASPs).
- fortran77 6y agoMany, many sites have an option like "don't ask for 2FA on this machine for 30 days" or something like that. If someone's on your machine, of course, then you don't need 2FA. It would probably be a good idea to ask for password and 2fa anyway if the person wants to change any account details. But if it's a machine that can be remotely accessed, it's probably not a good idea to enable "remember me" on that machine.
- usr1106 6y agoThis reminds me of their security checkup. I logged in to my gmail today from an somewhat unusual IP address. I immediately got an email that unusual activity has been detected and a link to security checkup. There I can click whether it's me or unrecognized activity. So what would the attacker click if they managed to get into my gmail?
- graton 6y agoSince I'm seeing all these comments about people who were happy that Google does this as they lost/damaged their phone which had the only copy of their 2FA codes. I would recommend buying a couple U2F tokens which support NFC and/or Bluetooth. 1) U2F almost impossible to phish, unlike TOTP codes. 2) You can have multiple U2F keys enabled on Google, so if one fails you have others to use. I like Yubikeys, though they are more expensive. Yubico makes a "Security Key" which is only U2F. I like the Yubikeys as can also use them to backup TOTP codes and support PGP keys. But realistically a couple U2F tokens is all you need.
- stormdennis 6y agoOn a tangent, I set up 2FA recently for my Amazon account and deliberatelychose to use Authenticator and avoid SMS based 2FA. However when you are asked for your code on logging in they allow you to chose to receive an SMS as an alternative and there appears to be no way to turn that off.
- selykg 6y agoMost average users are the reason for this. HN is not average, lets just get that out of the way right now. But it's not uncommon at all for someone to hear "I need to setup 2FA" so they go do so and then not understand how it works or why they're doing it. Or have some misunderstanding such that they might know what it does but not how it functions enough to properly backup their 2FA secrets or backup codes. This then results in a massive amount of customer support. It's also really time consuming to verify the identity of your customers and there's no really good way to do that to then disable 2FA reliably knowing you're talking to the actual account owner. This is at least a potential way for support to assist someone that messed up and disable their 2FA without having to verify their identity with some cumbersome/unreliable method.
- deleted 6y ago[deleted]
- NewEntryHN 6y agoIn order to disable 2FA, Google requires an authentication cookie (something you possess) as well as the password (something you know). This is 2FA.
- AgentK20 6y agoThe cookie is not something that is "possessed". This is a case of two separate things you "know", such as a username and a password. If they added a second password, it would still only be 1FA. For it to be considered a "second factor" it should either be "something you have" e.g. a physical hardware token (or to a lesser extent a phone who has a saved shared secret, although it's arguable whether that counts), or "something you are" like a biometric verification (fingerprint, retina scan, etc)
- qwertox 6y ago> The other aspect that came out of Amos' investigation was that passwords.google.com seems to store your passwords in an encrypted from that uses your google login password. This allows anyone who knows your password – say, because Safari auto-filled it for you – to be able to decrypt your cloud passwords. This up to the user, he has a choice. Google gives you the ability to use a separate password, one which Google will not remember for you, to encrypt all your Chrome-Sync data. This is your sync password. You can choose to let Google manage this for you, in which case it explicitly uses your Google password and Google could read all your sync data, or you can manage it by yourself ("Sync Passphrase"). If you switch between methods, all Sync-data (Bookmarks, Passwords, AutoFill, ...) is deleted.
- bob1029 6y agoRegardless of what any company/product doing specifically, I do not think it is unreasonable to require a fresh token out of an authenticator if you wish to remove said authenticator from your account. Hypothetically, what if you had 2 forms of 2nd factor to access your account? One is a passphrase you receive via SMS and another is a hardware token you possess. Should you be able to remove the hardware token based on an SMS authenticator response? Should you be able to remove both factors if you have a current session that was authorized at some prior time via one of the factors? I think the answers boil down to just how secure the application needs to be. If you have 2FA protection, but any authorized session is valid for a year, is this actually providing any protection? I have zero problems with the idea of being required to 2FA into my brokerage app every time I want to use it. I feel like the equation can be partially reduced to: "If your app is not so security critical that any prior-authorized session up to 30+ days can arbitrarily remove 2FA tokens, then why have 2FA in the first place?" The amount of time a 2FA-authorized session is valid for seems to be the hangup for me. If its really short (<24 hours), then I would say don't require a reauth to remove a token. But, if a session can be valid for months, then it is much more likely that a bad person has your laptop and wants to maliciously remove your token. The longer the session can be valid for, the more a 2FA re-auth seems to be necessary to ensure a bad actor is not involved. But, I recognize that there are so many UX considerations when talking about massive scale products that Google puts out. Supporting mandatory 2FA re-auth for token removal would probably be an extremely expensive process, as manual verification with live persons would be required to recover accounts with lost tokens.
- deleted 6y ago[deleted]
- miguelmota 6y agoSeems like weird UX to re-authenticate if the user is already authenticated, but I also see the security side of things were requiring authentication for configuring authentication preferences should be required.
- cpcallen 6y agoThis article twice references password.google.com, but AFAICT no such site exists. What are they actually talking about?
- close04 6y agoIt's Google's password manager with a typo. https://passwords.google.com/ https://passwords.google.com/
- cheerlessbog 6y agoOn the topic of Google 2FA, why does it to confirm a number on my phone when I use it to authenticate? I have to pick one of three numbers. That's only a 1/3 chance of detecting that it went to the wrong phone somehow.
- dathinab 6y agoAlso if you explicitly log out but don't clear the cookies and then log in again no 2FA is required. Combined with the problem of 2FA not needing 2FA to be disabled logging in at a compromised computer can totally steal your account, even through 2FA is meant to prevent this. This mean never ever login to google on a hotel computer, library or any other computer you don't trust. Google 2FA has gaps. Other problems with 2FA include: - To enable 2FA with authentication app you need to first enable 2FA with SMS (but SMS 2FA is known to not be secure). - It will also implicitly enable all your android devices to be able to provide the second factor by unlocking the device and pressing ok on some google dialog. EDIT: Or at least it was the case for me. Due to e.g. A/B testing or regional differences it might differ. You might want to disable both. Through I can somewhat understand why they do it as if you then lose access to you 2FA app you are also locked out of google, or at least should be if there are not other "gaps" in the account recovery process. Note that recovery keys are still another thing you can enable, print and put in a save (or whatever way you want to keep them save). And tbh. auth app + offline securely stored recovery keys seem to me the best option.
- tomc1985 6y agoIf my phone gets stolen I need to be able to disable 2FA without having to pass 2FA
- aahhahahaaa 6y agoSame for Twitter. You can disable the account and when you re-enable it 2FA is disabled.
- Waterluvian 6y agoI’m pretty sure this saved my bacon big time when I lost my 2FA phone and backup codes. I found that I was logged in on a home machine and could disable it all and set it up with my new phone.
- dazc 6y ago2fa will authenticate from your phone number, so you only need a replacement sim card from your telco.
- Waterluvian 6y agoLike with the app? I can install the authentication app on any phone with the same number?
- enkrs 6y agoI noticed the same thing last week on AWS - no requirement for 2FA when disabling 2FA on root account. Seemed strange, but I guess they figure requiring 2FA once more doesn’t add enough security..