7 ms·
This is 100% false. You need to have a 2FA authenticated connection or be on a 2FA authenticated device within validity period to change 2FA settings. You can e
by anon102010 6y ago
This is 100% false. You need to have a 2FA authenticated connection or be on a 2FA authenticated device within validity period to change 2FA settings. You can elect to have 2FA not remember the device you have logged into as well (ie, the remember this device for 30 days option) if you are particularly paranoid.
The headline should say - You can disable Google 2FA on 2FA authenticated connections without re-authenticating.
This is a fantastic balance in terms of security and usability. I switched iphones and google authenticator did not bring my 2FA's over, I got on my machine that had already authenticated and setup a new 2FA. Whew. Other systems were MUCH much harder to restore AND you could still get around 2FA but now with human involvement (social engineering risk). I've worked govt jobs with security so "tight" that everyone got the workarounds worked out - the social engineering would be as easy as I need reset for user X and they stopped even checking who anyone was the volumes were so high.
The loss in security is minimal here, and the loss is controllable, and it reduces pressure on other reset approaches (seriously, if you lock yourself out of google you will REALLY want to get back in).
- close04 6y agoWhile it can help you get out of a bind if you misplaced your 2FA token/app, changing any security parameters (especially when reducing security)should require entering all authentication methods enabled for the account. Imagine how changing a password requires the old password, not just the new one. At the very least they could make it configurable, let the user decide if they want to be able to turn off 2FA without being asked for a confirmation token.
- RcouF1uZ4gsC 6y ago> I switched iphones and google authenticator did not bring my 2FA's over, I have lost 2 FA's on other services via that means as well. I think it is easy if you have cloud backup on your phone that you think that you can just wipe your old phone and sync your new phone and you will be all set. Google Authenticator doesn't work like that.
- guiambros 6y agoGoogle Authenticator made it slightly easier with the "Transfer Account" functionality, but still requires access to your old device, so it doesn't help if your already wiped it. I personally would prefer backups would transfer all configuration, but understand this would be an additional risk. Of course you can just use Authy, although it does introduces the risk of an attacker compromising your phone number.
- gchamonlive 6y agoTo mitigate this, after you add browsers and phones to your Authy account, you go yo Settings, Devices and disable Multi-device.
- buran77 6y ago> This is 100% false That's a bit harsh, the actual disabling does not require a 2FA token so that part at least is true. And this is not the behavior I was expecting. On many other services I use disabling the 2FA requires 2FA confirmation and sometimes just visiting the security settings for the account requires the 2FA (if enabled). So maybe it's just "50% false"...
- m00x 6y agoThere's nothing harsh about it. It's factual. It does require 2FA, which makes the statement in the headline false. It doesn't require 2FA reauthentication, which means you already passed 2FA. You could say: "You don't need a password to log in to anyone's gmail account", while meaning that you just need to have access to their unlocked device while they're logged in.
- azinman2 6y agoThere’s a difference between logging into Google via 2FA and having subsequent interactions not require the 2nd factor, and turning off 2FA without a reconfirmation. You don’t want maximum usability in disabling your security mechanisms.
- baby 6y agoDebatable. If you lose your second device but still have access to a logged account you want to be able to disable 2FA.
- hombre_fatal 6y agoGreat counter-point, it's not as black and white as it seems. Google's own 2FA app (Google Authenticator) doesn't even let you export your keys.
- mathisonturing 6y agoIf you're talking about importing/exporting your list of 2FA codes, I think they've added it
- wnevets 6y ago> I got on my machine that had already authenticated and setup a new 2FA. I've had this happen to me a few times and I was so glad this is how it was done with google.
- koffiezet 6y ago> You need to have a 2FA authenticated connection or be on a 2FA authenticated device within validity period to change 2FA settings. You can elect to have 2FA not remember the device you have logged into as well (ie, the remember this device for 30 days option) if you are particularly paranoid. To change security-related settings, it's default practice to double-check even the user's password without 2fa. > This is a fantastic balance in terms of security and usability. Sorry, that's plain apologetic bullshit. How often do you enable and disable 2fa? This has nothing to do with usability.
- anon102010 6y agoThis is not "apologetic BS" Your comment illustrates a DEEP misunderstanding of dealing with users at scale. You have millions and millions of users. You are proposing that the threat / benefit model is such that if they lose their 2FA device (very easy via upgrades to phones, lost phones broken phones) EVEN though they have their password and and have access to a trusted device within the validity window for device trust they will be locked out, potentially forever from their account? Do you a) realize how common this situation is? b) realize how angry users will be to lose access to all their google services with basically no support route to recover that? c) what pressure there will be to allow for other recovery methods THAT ARE EVEN WEAKER? I've gone through 2FA reset procedures over the phone with a few companies, and in EACH case it struck me how easy it would be to socially engineer or use very minimal info to get a new 2FA when they allow these methods (ie, last 4 digits of CC was one reset piece of info). So you need to allow workable 2FA update methods so that your fallback can be pretty tight if allowed at all. Finally, consumer accounts have basically NO recovery option if you are locked out. I had a relative get locked out, nothing to be done (they had a landline that couldn't accept text messages and the system won't do voice calls). There is NO human backup - all emails, google photos, google drive etc GONE.
- rdiddly 6y agoThis is the "It's because of our amazing success that we totally fail at things" argument. If you can't do things right "at scale," that's fine, but everyone should know you suck at servicing that level of load, for example the fact that you don't require 2FA to change my 2FA settings, and there's no support path or even a support department for when my phone falls into a port-a-potty.
- deleted 6y ago[deleted]
- alpb 6y agoAnother story by @fasterthanlime comes with a sensational title. I should keep track of these :) https://news.ycombinator.com/item?id=23729126 https://news.ycombinator.com/item?id=23729126 Last week he also didn't understand Google Password Manager's security model and wrote an article on it. https://news.ycombinator.com/item?id=23728390 https://news.ycombinator.com/item?id=23728390
- ThePowerOfFuet 6y ago> I switched iphones and google authenticator did not bring my 2FA's over I recommend using an encrypted local backup created with a Mac (or iMazing), as _everything_ comes over except Secure Element-based info (Apple Pay cards, Touch/Face ID enrollment). Also, a better TOTP manager app; I use OTP Auth.