5 ms·
I’m not going to say whether this is good or bad for security, but it did save me a few years ago when I accidentally dropped my phone and broke it.
by quicklime 6y ago
I’m not going to say whether this is good or bad for security, but it did save me a few years ago when I accidentally dropped my phone and broke it.
- cavanasm 6y agoYeah, I lost my phone for the first time last year, and was very very glad for this default, because I was able to remove 2FA on my now lost phone from my computer that remained logged into google services, and log into google on the replacement phone, and reset 2FA to that new device.
- SketchySeaBeast 6y agoMy paranoia about my devices stability and its 2FA software (LG G4 bootloop victim) means that I keep two phones with 2FA verification and applications enabled - one stays safe at all times so that in case I lose or drop my new one I can use the backup.
- Klathmon 6y agoMost services that use standard TOTP codes have backup codes that you can print out and store in a safe, and the ones that don't you can save the QR code that enrolls the 2FA app and use it again to re-enroll a new device if needed. Obviously the backup codes are preferred as you're not storing a master key to all future codes, but it's a lot easier to manage than a second device (at least for me).
- jacobsenscott 6y agoI've lost my phone and been able to re-connect to every 2FA service I use without any need for human interaction. For google I was saved because my laptop was still logged in and I could turn google's 2fa off. Basically everyone else has an "I lost my device" thing and a fallback to SMS codes or email links. This certainly weakens 2FA in general, but strict 2FA is unusable in practice.
- lordlimecat 6y agoJust store your 2fa totp key or qr code or backup somewhere that is either protected by 2fa (password manager, online storage) , or is available offline (file cabinet). Some online storage services have secure areas requiring 2fa to open which would be suitable.
- rabuse 6y agoI don't understand why these large companies don't incorporate some type of printable backup code that can be used if your 2FA device is lost/broken. I've incorporated this type of system multiple times in the past, and it works wonderfully.
- Nrbelex 6y agoIn fact, Google does: https://support.google.com/accounts/answer/1187538?co=GENIE.Platform%3DAndroid&hl=en https://support.google.com/accounts/answer/1187538?co=GENIE....
- saagarjha 6y agoYeah, pretty much every 2FA I have set up has done this.
- greenshackle2 6y agoEvery 2FA I have setup has this. Kudos to GitHub in particular for strongly insisting that you save the backup codes somewhere.
- bcrosby95 6y agoThey do. But now that I think about it, I don't remember where any of mine are, because I haven't had to use them in over 5 years.
- Wowfunhappy 6y agoOh, it's clearly bad for security! Lots of things that are bad for security. For the best security, Google would require all users to sign in with dedicated hardware authentication tokens every time, and also present themselves for in-person interviews in Mountain View where Google employees would personally confirm each user's identity before letting them log in. That would be really good security! It would also be really bad for usability. Just like it would be bad for usability if you lost access to your Google account forever because you broke your phone.
- Macha 6y agoAs an example, my employer requires 2FA on pretty much everything, so the start of my day looks like: * Power on laptop, log in using laptop password * Log in to LastPass, use lastpass password, verify with 2FA. * Connect to VPN, log in using SSO (Okta) password from LastPass, verify with 2FA. * Open github tab, log in using the Okta password again, verify again with 2FA. * Open JIRA ticket, get sent to Okta, skips password prompt since already logged in, verify again with 2FA. * Open email, get sent to Okta, skips password prompt, verify again with 2FA. * Oh, my calendar tab was already open so Google didn't know I authenticated in another tab so sends me to Okta which now expects another 2FA there once I interact with it. Also the policy is that the lastpass password, SSO password and laptop password should be different. So that's 3 passwords and 5 2FA pushes in about 5 minutes (and again after lunch as all those sessions expire during it). My understanding is you can configure Okta to remember 2FA on a device for a while, but our security department has chosen to disable that. This is a lot of security overhead, but in this case I'm being paid for it rather than paying for it so whatever. Can you imagine getting a paying customer to agree to this level of 2FA double checking?
- tialaramex 6y agoAnd the annoyance makes people want to turn it off. Typical solution: Make the timeout much longer so you don't need to keep doing the work Correct solution: Deploy a second factor that isn't annoying If your second factor is a FIDO Security Key then you just touch the key. Doing this a dozen times per day feels about as much trouble as how you have to hit the spacebar to make spaces when typing, ie you aren't even aware of it. The VPN couldn't easily do this out of the box today (as OpenSSH demonstrates, where there is a will there is a way but I wouldn't trust a typical proprietary VPN client to not open massive security holes this way) but all the web stuff you mentioned could use WebAuthn, and Okta supports that if your employer deployed it as I understand it.
- ehsankia 6y agoIsn't that what backup codes are for? Does no one use backup codes anymore?
- usr1106 6y agoI hardly ever use my phone for 2FA. I have a 5 line Python script using pyotp to create my codes on all my computers. Admittedly if a skilled hacker breaks in into my computer they could recognize what the script does and misuse it. But at least no scripted attack should ever look for it. It's not on github because my seeds are hard-coded and there is not much to generalize.
- graton 6y agoYou could also use a Yubikey to store up to 32 TOTP codes on it. One benefit is that you can set it up to require a touch to generate the code.
- usr1106 6y agoAgain, like with the phone, I would always need to take it out the pocket. Which is inconvenient if the pants are in the bedroom but I am not. Or I have a different pair of pants and the contents of the pockets hasn't got swapped.
- graton 6y agoAh. I actually leave my Yubikeys plugged into my computers. I use the Yubikey Nano. I have a USB-C version in my laptop and a standard USB version in my desktop PC.
- scottmcdot 6y agoMe too. Cracked, unusable phone screen. Fortunately was still logged into Google on my desktop otherwise I wouldn't be able to change 2fa before fixing the screen.