3 ms·
Thanks for the question, I have similar concerns. If you enable 2FA on a website it mainly asks you to scan a QR code and confirm it with a OTP value. This work
by moasda 5y ago
Thanks for the question, I have similar concerns. If you enable 2FA on a website it mainly asks you to scan a QR code and confirm it with a OTP value. This works fine until you lose you phone and have no full backup accessible without 2FA. This could be a time bomb for security oriented users.
I know, when activating 2FA the website also shows some recovery codes etc. But I can imagine that most non-tech users don't know what to do with them and ignore them.
I fully agree that you should understand how 2FA basically works and how you can recover. For me it works like this:
- KeePassXC / KeePassDX file synced on several devices + backup
- andOPT App with an encrypted backup of the exported JSON data, accessible without 2FA
This setup is easy to understand for me und I know how to recover if I lose my phone or my PC SSD gets damaged. I do not trust Google or other cloud services with fancy sync features.
- 1MachineElf 5y agoYou mentioned not trusting Google, but FWIW, Google Authenticator added support within the past year for multiple devices: https://www.theverge.com/21410260/google-authenticator-2fa-how-to-phone-security-iphone-android https://www.theverge.com/21410260/google-authenticator-2fa-h...