6 ms·
Use authenticator app for 2FA, not your phone number. But be really sure you want to do this. The main reason I would not recommend ordinary consumers do this,
by ridaj 5y ago
Use authenticator app for 2FA, not your phone number.
But be really sure you want to do this. The main reason I would not recommend ordinary consumers do this, is that if you lose your SIM (eg, stolen or lost phone), you can go to a mobile phone shop and get a new SIM card issued to you after verifying your identity. With other forms of 2FA, you do not have access to the same real-life-based identity verification service, and it is also essentially the source of SIM-swap risk.
- embeng4096 5y agoYes, ordinary consumers are starting to use TOTP more but still may not be aware of what you pointed out. To mitigate the risk of losing my 2FA credentials I use the FOSS app andOTP (Aegis is similar, but better UI, from what I hear). It can export your data as both cleartext and encrypted JSON so you can import into a new phone as desired.
- ridaj 5y agoI'm aware of solutions that can help prepare for a backup. I don't think most people should trust themselves to handle backup responsibilities. Speaking as someone locked out of an encrypted disk full of old photos that I carefully wrote down the passphrase to on a piece of paper for safekeeping... Since then lost.
- pkrotich 5y agoAuthenticator app can also stop working when you migrate to a new phone - a friend got locked out recently after migration. Apparently you need to follow some steps [0] [0] https://www.alphr.com/transfer-google-authenticator-codes-new-phone/ https://www.alphr.com/transfer-google-authenticator-codes-ne...
- yumraj 5y agoYou can use Authy and install it on multiple devices/computers
- _snrv 5y agoDoesn't allow for export though, which is a complete pain for backup.
- miohtama 5y agoAuthy on Android has backup to Google Drive.
- jamesboehmer 5y agoI used this hack to export from Authy Desktop on Mac https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93 https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...
- yumraj 5y agoMaybe I'm not understanding, but what is export and backup in the context of an OTP application. Per my understanding, if I have Authy on my Phone, the one on my PC/laptop is the backup, and vice versa - in the sense that if one dies I can use another. Could you elaborate on the use case.
- stonewareslord 5y agoTOTP/HOTP codes are defined by an algorithm (sha1/md5/...), secret (A826EF8...), and number of digits (I usually see 6 digit codes). TOTP additionally takes time period (30 second codes) and time (current time which maps to some 30 second block) as a parameter and HOTP takes a counter as a parameter. All of these parameters go into the function to generate the numbers as a result. If you have ever set one of these up with a QR code, that QR scans to something like: otpauth://totp/ACME%20Co:john.doe@email.com?secret=HXDMVJECJJWSRB3HWIZR4IFUGFTMXBOZ&issuer=ACME%20Co&algorithm=SHA1&digits=6&period=30 (From: https://github.com/google/google-authenticator/wiki/Key-Uri-Format https://github.com/google/google-authenticator/wiki/Key-Uri-...). Notice all parameters I mentioned above are present, as well as a user friendly account name. So to directly answer your question: a backup would in some way contain all the parameters above, possibly in that otpauth:// format, but could be json or something else. I would not consider Authy to be a trustworthy backup. I assume they are storing these secrets for you and transferring them to other computers at your request. If you can't see the secret, you can't switch to a different app. (Take this last paragraph with a grain of salt, I don't know much about authy but it sounds like trouble. I use FreeOTP and other open source OTP apps).
- Zizizizz 5y agoAndotp or aegis authenticator are both great open source 2fa apps that let you export and backup your 2fa to cold storage somewhere incase of these situations
- jopsen 5y agoWhen you add accounts to your authenticator app, you can just print out the QR code (take screenshot). Then you have a physical offline backup of the TOTP secret in a QR code with error correction. Store those sheets of paper in a folder somewhere safe. Also consider using a yubikey for TOTP -- but do a paper backup regardless.