5 ms·
I'm so fucking pissed about this. I signed up for AWS with a personal Amazon.com shopping account. Enabled 2FA, lost the token. I can care less about the AWS ac
by throwaway324343 6y ago
I'm so fucking pissed about this. I signed up for AWS with a personal Amazon.com shopping account. Enabled 2FA, lost the token. I can care less about the AWS account but no longer can I change my password on the shopping account I've had for 10 years.
- thisisnico 6y agoAnd there is zero support to help you fix the problem.
- throwaway324343 6y agoThere is a MFA reset process that requires a notary and what not. Wouldn't be an issue for the average Joe but since I've moved 3 times since signing up for AWS, I'm not sure which address they need and not even sure I can procure sufficient documents with those addresses on them.
- seniorgarcia 6y agoI don't get this. You lost your MFA backup and you can not proof who you are and somehow this is amazons fault. What are you complaining about exactly?
- amingilani 6y agoI don't think he can't prove who he is. He is, after all, the same person. Rather, he can't verify to the service provider that he's the same individual that they have on file, despite being the same bag of flesh and bones he always was. And that is absolutely the service provider's fault.
- irishsultan 6y agoBlaming him instead of Amazon would make sense if Amazon allowed you to have an MFA backup, or recovery codes.
- seniorgarcia 6y agoI use Authy to backup my MFA codes, this works fine for amazon. When I switched providers and phone at the same time I used my billing address as well as my CC to confirm my change in billing address. Ensuring I can proof who I am is my responsibility.
- seniorgarcia 6y agoYou are responsible to ensure your identity. Make sure you backup your 2FA codes. You can try and shift the responsibility but why would they be responsible for your shit?
- staticassertion 6y agoFWIW this is why it's a good idea to have two MFA mechanisms. If you can afford it I recommend getting 2 hardware tokens, and storing them separately (you can leave one in your computer, hard to lose).
- x0x0 6y agoThat's a great plan, but AWS notably doesn't support multiple hardware u2f devices. They've been sitting on the ask for about 7 years https://forums.aws.amazon.com/thread.jspa?threadID=137055 https://forums.aws.amazon.com/thread.jspa?threadID=137055
- staticassertion 6y agoDamn, that sucks. I use GSuite to SSO to AWS though.
- mrguyorama 6y agoCan you not manually set the two tokens to the same "seed"?
- chipsa 6y agoThat works for TOTP 2FA on your phone. But most hardware tokens have an internal seed that's immutable.
- mimimi31 6y agoIsn't that just the enterprise ones? I've been using personal hardware TOTP tokens[1][2] like this for years, where you can set the seed yourself using NFC. [1] https://www.token2.com/shop/category/programmable-tokens https://www.token2.com/shop/category/programmable-tokens [2] https://www.protectimus.com/protectimus-slim-mini https://www.protectimus.com/protectimus-slim-mini
- antoinealb 6y ago
- zorked 6y agoI bet that more accounts and data have been lost to 2FA than have ever been saved by 2FA.
- ta17711771 6y agoFollow proper practice. Always register two keys.